CoinWorld reports:
Israeli crypto broker Bits of Gold has disclosed that personal information of approximately 200,000 customers was accessed without authorization during a security incident involving a third-party service provider. The company stated that the affected data pertains to an external data analytics network, and customer funds and digital assets remain untouched.
Leaked Information Includes Banking Details
The company stated that the accessed information includes names, national ID numbers, email addresses, phone numbers, IP addresses, bank account information, and public wallet addresses. This indicates that the incident primarily affected identity and contact information rather than credentials that directly control account assets.
Bits of Gold confirmed that passwords, private keys, CVV codes, and ID scans were not leaked, thus the incident did not directly impact the security of user funds.
Intrusion Originated from Third-Party Service Provider
The Tel Aviv-based company reported that hackers gained access through the network of a third-party data analytics service provider. The company stated that after detecting the anomaly, it blocked the related access and disconnected the systems from the information source.
The company also mentioned that preliminary investigations suggest this incident may be part of a larger global attack, with other companies affected at the same time. Its security team has launched a comprehensive investigation and engaged a cybersecurity incident response agency to assist in handling the situation.
Three Similar Incidents in a Week
This is the third data breach incident disclosed in the crypto industry within the past week. Previously, SafePal reported that nearly 40,000 user order details were stolen due to a third-party vendor breach; hardware wallet manufacturer Trezor also stated on August 13 that its fulfillment partner ShipMonk was attacked, leading to the leakage of information from nearly 14,000 customers.
Bits of Gold also reminds customers that the company will never ask users for passwords, verification codes, or private keys, nor will it request fund transfers. The series of incidents points to external vendors, exposing the security risks of the third-party service chain again.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























