Invest1 publisher3 min readPublished
Israel's first licensed crypto broker becomes its most valuable identity target
A reported breach of roughly 200,000 customer records at Bits of Gold shows what a KYC mandate actually builds: one file worth more than the coins it sits beside.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A hacker has stolen the personal data of roughly 200,000 customers from Bits of Gold, Israel's largest regulated cryptocurrency broker, as reported by Crypto Briefing via Calcalist.
- Bits of Gold serves over 200,000 clients in Israel, meaning the breach could affect essentially every user on the platform.
- The specific types of personal information compromised have not been publicly detailed.
- Crypto brokers typically collect extensive identity documents under know-your-customer regulations, which can include government-issued IDs, proof of address, and financial information.
- Bits of Gold received Israel's first virtual asset service provider (VASP) licence from the Capital Market Authority in September 2022.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
A hacker has stolen the personal data of roughly 200,000 customers of Bits of Gold, Israel's largest regulated cryptocurrency broker, according to Crypto Briefing citing Calcalist [1]. Because the company serves more than 200,000 clients in Israel, the reported haul is arithmetically indistinguishable from its entire book [2][12].
The uncomfortable part is the causal chain. Bits of Gold received Israel's first virtual asset service provider licence, from the Capital Market Authority, in September 2022, and built its reputation on regulatory compliance and security [5][14]. Licensing is not a coat of paint. It obliges a broker to hold what other market participants can decline to collect: crypto brokers typically gather extensive identity documents under know-your-customer rules, which can include government-issued IDs, proof of address, and financial information [4]. Do that for a decade and you have not reduced identity risk in the market, you have relocated and concentrated it into a single corporate database. The most compliant broker in the country ends up holding the most complete identity file in the country.
The specific categories of information compromised have not been publicly detailed [3], and that gap matters more than any statement the company might issue about controls. Bits of Gold has promoted two-factor authentication and cold storage for digital assets [6]. Cold wallets protect coins on a chain; they do nothing for passport scans and utility bills sitting on company servers [7]. The marketing and the exposure were never describing the same asset.
There is a precedent operators should already know. Ledger's 2020 breach exposed customer names, email addresses, and physical addresses, and produced targeted phishing campaigns and physical threats against affected users [10]. Data taken from a crypto broker can be turned into phishing, SIM-swap schemes, and social engineering built specifically to move digital assets [11]. Identity data does not expire the way a password does. A customer can rotate credentials; nobody reissues an address history.
The timing sharpens the consequence. Bits of Gold offers shekel and dollar-denominated trading, over-the-counter services, and API products for businesses [8], and in April 2026 it received approval to issue BILS, a stablecoin backed 1:1 by the Israeli shekel, developed with Solana and Fireblocks and audited by EY [9]. That approval came roughly three and a half years after the VASP licence [13]. The same institutional standing that justified a shekel-backed issuance is what made the customer file large, verified, and worth stealing.
Three things to watch. First, disclosure of what was actually taken: if identity documents rather than contact details are involved, the remediation cost is not a year of credit monitoring, and the source has not yet specified the categories [3][4]. Second, whether the Capital Market Authority, which granted the first licence in the market, treats data custody as a licence condition with teeth or as a matter separate from asset custody [5]. Third, the BILS rollout, since the entity now cleared to issue a shekel-pegged token with EY as auditor is the same entity whose client base was reportedly exposed in full [9][12]. Compliance regimes that mandate collection without mandating minimisation are, in effect, target-building programmes.