← Radar

Incident case file

Sign in to watch

Bits of Gold Third-Party Analytics Breach — ~200,000 Customers Exposed

Incident date 2026-08-15Last updated Aug 26, 2026

0 views

ContainedNot applicable (CEXregulated crypto brokerIsrael; Web2 third-party analytics system)Third-party/supply chain data breach — unauthorized access to an external analytics/support system (no custody or tradCluster: BOG-DATA-2026-08

Estimated loss

$0

Victims identified

200000
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

Not publicly disclosed. Reported to be part of a broader campaign affecting multiple organizations globally through the same third-party analytics provider.

Funds moved to

Not applicable. Bits of Gold states custody and trading systems were not affected, and that funds, private keys, passwords, CVV numbers, and identity-document copies were not part of the exposed dataset.

Linked

Bits of Gold detected unauthorized access to a third-party system used for support/analytics functions. Exposed data: customer names, national ID numbers, emails, phone numbers, IP addresses, banking details, and customers' own public wallet addresses. Reported (but not officially confirmed in the primary company statement) association with CVE-2026-72898, an unauthenticated Metabase SQL injection vulnerability affecting the password-reset endpoint (CVSS 10). This link should be treated as repor

Chronology

1 beat
  1. Several days prior to disclosure (per the company's account): Unauthorized access to the third-party analytics/support system occurs; precise intrusion date not publicly disclosed. Aug 16, 2026: Bits of Gold publicly discloses the breach and blocks/disconnects the compromised system from internal data sources. The company states approximately 200,000 customers were affected (a separate, higher figure of up to 250,000 cited by some outlets likely reflects total client base or a maximum-exposure estimate rather than the confirmed-affected count). An external cybersecurity firm is engaged for investigation. Aug 17, 2026, 11:59 UTC: CoinDesk publishes coverage citing the company's own statement, describing the breach as tied to a third-party analytics system and confirming custody/trading infrastructure was unaffected. Bits of Gold is described as the first licensed Virtual Asset Service Provider (VASP) in Israel (licensed September 2022) and had separately received approval in April 2026 for BILS, a 1:1 Israeli-shekel-pegged stablecoin, in partnership with Solana and Fireblocks, audited by EY.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)