Bits of Gold Halts Bitcoin Sales After Breach Exposes 250,000 User Records

Key Takeaways

Bits of Gold suspended Bitcoin purchases following a data breach affecting 250,000 users. While private keys and passwords remain secure, the incident highlights risks of phishing and social engineering attacks targeting exposed personal information.

Woofun AI reports that Bits of Gold has halted Bitcoin purchases in response to a data breach compromising the records of 250,000 crypto users. The immediate suspension of trading services underscores the severity of the security incident, even as the company works to contain the exposure.

Account passwords and identification-document images were confirmed not to be exposed by the breach. Bits of Gold also stated it does not hold customers' private keys, full card details or CVV codes. This distinction limits the immediate risk of on-platform asset theft but creates longer-lasting security concerns. The exposed data includes names, email addresses, phone numbers, physical addresses and other identifying details. Such information can be leveraged in phishing campaigns, impersonation attempts, and social-engineering attacks designed to convince users to reveal credentials, approve transfers, or surrender access to self-custodied crypto.

Paz stated it was not concerned that Yellow customer information had leaked because the two applications lack a direct interface. The broader commercial agreement between the firms remains in effect, while Bits of Gold's primary services continue to operate normally. Per Woofun AI, CTech attributed the Bits of Gold's data breach to an active exploit, CVE-2026-72898, affecting self-hosted releases of Metabase, an analytics software provider. The crypto-focused company has since blocked access to the affected system, disconnected it from its data sources, and retained a cybersecurity incident-response firm. Bits of Gold also notified relevant regulatory bodies, identified by Israeli media as the Capital Market Authority and the National Cyber Directorate.

Customers were advised that no technical action, such as moving funds or crypto assets, was required. The incident highlights the persistent vulnerability of customer data in digital asset platforms, even when direct asset custody is not compromised. This marks another significant security challenge for the sector as regulatory scrutiny intensifies.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions