Bitcoin purchases halted after data breach puts 250,000 crypto users at risk

Bits of Gold, Israel’s largest regulated cryptocurrency broker, is currently investigating a potential data breach that may have compromised the personal information of approximately 250,000 customers. While customer funds and digital assets are safe, the incident has led to a temporary suspension of Bitcoin purchases on the Yellow convenience store app by Israeli retail and energy giant Paz.

According to a notice released on Aug. 16 by Bits of Gold, an unauthorized party gained access to a supporting data-analysis system a few days prior. The firm, which is Israel’s first licensed virtual asset service provider, confirmed that names, national identity numbers, phone numbers, email and IP addresses, bank-account details, and public crypto wallet addresses were potentially exposed. However, account passwords, identification-document images, private keys, full card details, and CVV codes were not compromised.

This breach is part of a series of recent incidents in the crypto sector where customer information has been accessed without directly affecting digital assets. While on-platform asset theft is not an immediate risk, the exposed data, including names, email addresses, phone numbers, and physical addresses, can be used in phishing campaigns and social-engineering attacks outside the affected platform.

In response to the breach, Paz has temporarily suspended the integration of Bits of Gold on its Yellow app. Despite this, Paz assured that customer information from Yellow had not been leaked as the two applications do not directly interface. Bits of Gold has taken steps to address the breach, including blocking access to the affected system, disconnecting it from data sources, and engaging a cybersecurity incident-response firm. Regulatory bodies have been notified, and customers have been advised that no technical actions are required.

As a precaution, users are encouraged to remain vigilant for phishing attempts, avoid unsolicited transfer requests, and refrain from sharing verification codes, one-time passwords, or private keys.