Skip to content
Back to Blog
high severity August 22, 2026 · 4 min read Unverified claim — what this is

Bits of Gold data breach August 2026: was my information exposed?

If you have an account with Bits of Gold, here’s what is being claimed, and what it would mean for you.

On 16 August 2026, Bits of Gold said someone had unauthorized access to a supporting data-analysis system. Coins, passwords and private keys were not involved. Names, ID numbers, contact details, bank account details and public wallet addresses may have been accessible; the company has not said how many people that covers.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Bits of Gold data breach August 2026: was my information exposed?

On 16 August 2026, Bits of Gold — a large Israeli cryptocurrency broker — told customers that someone had gained unauthorized access to a supporting system used for data analysis. The company said this was part of a wider cyber incident that also hit other firms around the world, not a break-in of its own trading systems. It blocked the access, disconnected that system, brought in specialists, and notified Israeli authorities. Services kept running as normal.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

A review found there may have been access to names, identifying details such as ID numbers, emails, phone numbers, IP addresses, bank account details, and public crypto wallet addresses. Bits of Gold has not said how many records that involves. Digital assets were not touched. The company does not hold private keys, account passwords, ID-document photos, or full card numbers and CVV codes, and it says those were not part of this.

The headlines say your money is fine. Here is what they skip.

Almost every report opens with the same reassurance: your coins are still there, Bits of Gold never held your private keys, passwords were not taken, and this was not an attack on the broker’s own systems. All of that is true. It is also the least useful part of the story if you are trying to work out what this means for you.

What may have been sitting in that analysis system is not a way into a wallet. It is the paperwork that lets a stranger sound like someone you already trust. A name plus an Israeli ID number plus a phone number plus an email plus a bank account plus a public wallet address is enough for someone to call you, email you, or contact your bank while reciting facts that feel like proof they are legitimate. That same wallet address can be looked up on a public blockchain, so activity there can be tied to a real person — not because the blockchain was hacked, but because the name and the address may now sit in the same file.

The company used careful language on purpose. It said there may have been access. It has not confirmed that records were copied out, and it has not published any number of people. Figures such as 200,000 that appeared in news reports are not from Bits of Gold’s own statement; they track the size of the customer base. The company also said it had no sign, at the time, that the information had been used. None of that makes the combination of fields harmless if it did leave. It does mean nobody can honestly tell you, from the outside, whether your row was among those that were reachable.

What to actually expect

  • Emails, texts or WhatsApp messages that mention this incident by name and ask you to “verify,” “secure” an account, enter a code, or move coins. The breach is the bait. Bits of Gold has said it will never ask for a password, a verification code, a private key, or a transfer of funds or assets.
  • Calls or messages from people who already know your name and that you use Bits of Gold. That knowledge is not proof they work for the company or your bank. It is exactly the sort of detail that may have been in the analysis system.
  • Someone trying your bank with account details that were on file, hoping a staff member or an automated check will treat them as you. Watch that specific account, not “your finances” in the abstract.
  • A quiet period, then a second wave weeks later. Impersonation often waits until the first headlines fade and a message about “final account review” or “compensation” looks routine.

What you can and cannot fix

If your name, national ID number, contact details, bank account details or public wallet address were in that system and were accessible, that copy cannot be pulled back. You cannot change an Israeli ID number. You cannot un-publish a wallet address, and you cannot undo a pairing of that address with your legal name if the pairing left. A bank account number that is out stays out unless you stop using that account. Nobody can remove the breached file itself.

  • Treat any inbound contact about this incident as hostile unless you started it yourself through the official website or app you already use. Do not move crypto because a message told you the coins are at risk. The company said funds were not involved.
  • Watch the bank account whose details were on file with Bits of Gold. If you want a concrete step with the bank, tell them that account number may have been exposed in a third-party incident and ask what extra monitoring they will put on it. Opening a replacement account is the only way to retire a number that may already be in someone else’s hands.
  • A leaked name, ID number and wallet address become much more dangerous when they are joined to people-search and data-broker listings that add relatives, extra phone numbers, employers and previous addresses. That join is how a dry row in a stolen file turns into a script for a phone call. Those listings, unlike the breach, can often actually be removed — and shrinking that public layer is one of the few things still under your control.
  • If you still use Bits of Gold, change nothing on the basis of a link in a message. Use only the bookmark or app you already had. Passwords were not part of this incident, so a panicked reset from a “security” email is more likely to be the scam than the fix.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Bits of Gold is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 22, 2026
Affected Unconfirmed
Data exposed Full namesNational ID numbersEmail addressesPhone numbersIP addressesBank account detailsPublic crypto wallet addresses
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email