Bitcoin purchases halted after data breach puts 250,000 crypto users at risk

Israel’s largest regulated cryptocurrency dealer, Bits of Gold, is investigating a knowledge breach that doubtlessly uncovered the non-public data of as much as 250,000 prospects.
Whereas buyer funds and digital property stay safe, the incident prompted Israeli retail and power big Paz to quickly halt Bitcoin purchases on its Yellow comfort retailer app.
In an Aug. 16 notice, Bits of Gold confirmed that an unauthorized celebration accessed a supporting data-analysis system a number of days earlier. The agency is Israel’s first licensed digital asset service supplier.
The possibly uncovered knowledge consists of names, nationwide id numbers, telephone numbers, electronic mail and IP addresses, bank-account particulars and public crypto pockets addresses.
Account passwords and identification-document photos weren’t uncovered. Bits of Gold additionally mentioned it doesn’t maintain prospects’ personal keys, full card particulars or CVV codes.


This incident provides to a rising variety of crypto-sector breaches by which attackers have gained entry to buyer data with out straight compromising digital property.
In a number of current circumstances, the uncovered knowledge has included names, electronic mail addresses, telephone numbers, bodily addresses and different figuring out particulars that can be utilized to focus on prospects exterior the affected platform.
That distinction limits the quick threat of on-platform asset theft however can create longer-lasting safety considerations.
It’s because private and monetary data can be utilized in phishing campaigns, impersonation makes an attempt, and social-engineering assaults designed to persuade customers to disclose credentials, approve transfers, or give up entry to self-custodied crypto.
Paz partnership paused amid vulnerability probe
Following the disclosure, Paz suspended the Bits of Gold integration on its Yellow app, in line with an Aug. 17 report by CTech.
Paz mentioned it was not involved that Yellow buyer data had leaked as a result of the 2 functions lack a direct interface. The broader industrial settlement between the corporations stays in impact, whereas Bits of Gold’s main providers proceed to function usually.
CTech attributed the Bits of Gold’s knowledge breach to an lively exploit, CVE-2026-72898, affecting self-hosted releases of Metabase, an analytics software program supplier. Bits of Gold has since blocked entry to the affected system, disconnected it from its knowledge sources, and retained a cybersecurity incident-response agency.
The crypto-focused firm additionally mentioned it has notified related regulatory our bodies, recognized by Israeli media because the Capital Market Authority and the Nationwide Cyber Directorate.
Clients had been suggested that no technical motion, corresponding to transferring funds or crypto property, was required.
Nonetheless, as a result of contact and monetary data could have been uncovered, customers had been urged to stay alert for phishing makes an attempt, refuse unsolicited switch requests, and by no means share verification codes, one-time passwords, or personal keys.








