Flash News

Israel's Largest Compliant Crypto Broker Bits of Gold Suffers Data Breach

Israel's largest compliant crypto broker Bits of Gold has experienced a data breach, with approximately 200,000 customers' personal information stolen by hackers, putting all users at risk.

The company obtained Israel's first virtual asset service provider license in September 2022 and was approved to issue the BILS stablecoin, pegged 1:1 to the shekel, in April 2026.

The types of stolen data have not been fully disclosed, but crypto brokers typically collect sensitive information such as identification documents, proof of address, and financial information in accordance with KYC regulations, potentially including names, ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public crypto wallet addresses.

While cold wallets can protect digital assets, they cannot safeguard customer identity documents stored on servers. The company confirmed that funds, private keys, passwords, ID scans, and credit card details were not affected.

Historical cases show that similar data breaches are often used for phishing, SIM swapping, and targeted social engineering attacks, with security risks extending beyond the platform itself.

From a market mechanism perspective, data breaches at compliant brokers undermine user trust and increase security review costs, potentially directing funds towards data minimization or self-custody solutions. This incident may drive the industry to strengthen third-party software supply chain security, putting pressure on affected platforms while benefiting privacy-enhancing services.

Supplementary data indicates that this incident stemmed from unauthorized access to a third-party data analysis support system, part of a large-scale cyber attack affecting hundreds of companies worldwide. The company has blocked access and notified authorities.

Source: Public Information

ABAB AI Insight

As the first crypto broker in Israel to obtain a VASP license, Bits of Gold has established its market position through compliance and localized services, and has advanced the implementation of the BILS stablecoin. Historical behavior shows its priority in meeting regulatory requirements while relying on third-party systems to handle customer data.

In terms of capital pathways, the company immediately blocked access, initiated an investigation, and notified users and authorities after the breach, motivated by the need to control reputational damage and prevent secondary attacks, strategically emphasizing that asset security was unaffected to stabilize customer retention.

Similar cases have been observed where other licensed exchanges or brokers faced KYC data breaches due to third-party vendors. Currently, compliant crypto platforms are transitioning from asset custody security to comprehensive data protection.

Structurally, this indicates regulatory changes: the mandatory collection of sensitive information for KYC creates a centralized data target, making third-party software an attack entry point, forcing licensed institutions to reassess vendor risks and data minimization, shifting pricing power from mere compliance licensing to data security capabilities.

ABAB News · Cognitive Law

  1. Compliant data collection also becomes an attack surface
  2. Cold wallets protect assets but not identities
  3. Third-party vulnerabilities can breach licensed defenses.

Source

·ABAB News
·
4 min read
·1d ago
分享: