Bits of Gold, Israel's largest regulated cryptocurrency broker and first licensed virtual asset service provider, is investigating a breach at a supporting analytics system that may have exposed personal and financial data tied to as many as 250,000 customers. The company said customer funds and digital assets were not affected, private keys were not involved, and there was no indication at the time of its Aug. 16 notice that the information had been misused. Potentially exposed data included names, national identification numbers, email addresses, phone numbers, IP addresses, bank-account details and public wallet addresses. Bits of Gold said it blocked the access, disconnected the system from its data sources, notified authorities and hired a specialist incident-response firm, while services continued normally. The case underscores how third-party or auxiliary systems can create a separate attack surface for crypto companies: even without a custody breach, exposed wallet and identity data can fuel phishing and other social-engineering attacks. Israeli partner Paz also temporarily halted Bitcoin purchases on its Yellow app, while CTech linked the incident to an active Metabase exploit tracked as CVE-2026-72898.