Timeline
- 8.0
Israel's Largest Crypto Broker Bits of Gold Breached, 200K Customers Exposed
Bits of Gold, Israel's largest crypto broker, disclosed a data breach affecting about 200,000 customers. The breach occurred via a third-party data analytics provider, exposing names, national ID numbers, bank details, and public wallet addresses, but not funds or private keys. This incident underscores the vulnerability of crypto firms to supply-chain attacks via external vendors, and the exposure of sensitive financial and identity data could put affected users at heightened risk of fraud and phishing. It also adds to a string of recent crypto industry data breaches, potentially eroding customer trust in custodial brokers. Bits of Gold stated that no funds, passwords, private keys, CVV codes, or scanned IDs were exposed, and that it disconnected the affected system upon detection. The company believes the attack was part of a broader global incident, and it has launched an investigation with a cyber incident response firm.
- 7.5
SafePal Discloses Data Breach Affecting Nearly 40,000 Users' Order Information
SafePal disclosed an authorization flaw in a plug-in used to track customer orders, exposing personal order information of 39,798 users. The company says no seed phrases, private keys, or funds were compromised. This breach underscores the risks of third-party order-processing systems even in hardware-wallet ecosystems and could expose affected users to phishing and impersonation attacks. It also reinforces the importance of distinguishing between customer data and cryptographic key security. Exposed data included names, physical addresses, and contact details. SafePal patched the vulnerability, retained an independent security firm to audit the fix, will limit order-data retention to 90 days, and removed over 30 fraudulent websites and phishing links.