Israel’s largest regulated crypto broker discloses unauthorized access to analytics system
Bits of Gold, Israel’s largest regulated crypto broker and first licensed virtual asset service provider, disclosed unauthorized access to a supporting data-analysis system on August 16, 2026. The breach potentially exposed personal and financial information for 250,000 customers.
Exposed data includes names, national identity numbers, phone numbers, email addresses, IP addresses, bank-account details, and public crypto wallet addresses. Account passwords, identification-document images, full card details, and CVV codes were not exposed. Bits of Gold does not hold customers’ private keys.
The unauthorized access affected a system running Metabase, an analytics software platform. The breach exploited CVE-2026-72898, an active exploit affecting self-hosted releases of Metabase. Bits of Gold blocked access to the affected system, disconnected it from data sources, and retained a cybersecurity incident-response firm to investigate.
Customer funds and digital assets remained secure despite the breach. Bits of Gold’s primary services continued operating normally following the disclosure.
Paz suspends Bitcoin partnership temporarily
Paz, an Israeli retail and energy giant, suspended Bits of Gold’s integration on its Yellow convenience store app on August 17, 2026, according to CTech. Paz stated that the Yellow app and Bits of Gold lack a direct interface, so Yellow customer information was not at risk from the breach.
The broader commercial agreement between Paz and Bits of Gold remains in effect. The temporary suspension affects only Bitcoin purchases through the Yellow app partnership.
Customer notification and response
Bits of Gold advised customers that no technical action was required but urged them to remain alert for phishing attempts. The company notified the Capital Market Authority and National Cyber Directorate, Israel’s regulatory bodies overseeing financial services and cybersecurity respectively.
Bits of Gold did not name the unauthorized party or confirm the identity of the attacker. The company did not specify the exact attack path, the full extent of the compromise, or the timeline between when unauthorized access began and when the breach was discovered.