Bits of Gold data breach August 2026: was my information exposed?
If you have an account with Bits of Gold, here’s what is being claimed, and what it would mean for you.
On 16 August 2026, Bits of Gold said someone had unauthorized access to a supporting data-analysis system. Coins, passwords and private keys were not involved. Names, ID numbers, contact details, bank account details and public wallet addresses may have been accessible; the company has not said how many people that covers.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Bits of Gold customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
On 16 August 2026, Bits of Gold — a large Israeli cryptocurrency broker — told customers that someone had gained unauthorized access to a supporting system used for data analysis. The company said this was part of a wider cyber incident that also hit other firms around the world, not a break-in of its own trading systems. It blocked the access, disconnected that system, brought in specialists, and notified Israeli authorities. Services kept running as normal.
A review found there may have been access to names, identifying details such as ID numbers, emails, phone numbers, IP addresses, bank account details, and public crypto wallet addresses. Bits of Gold has not said how many records that involves. Digital assets were not touched. The company does not hold private keys, account passwords, ID-document photos, or full card numbers and CVV codes, and it says those were not part of this.
The headlines say your money is fine. Here is what they skip.
Almost every report opens with the same reassurance: your coins are still there, Bits of Gold never held your private keys, passwords were not taken, and this was not an attack on the broker’s own systems. All of that is true. It is also the least useful part of the story if you are trying to work out what this means for you.
What may have been sitting in that analysis system is not a way into a wallet. It is the paperwork that lets a stranger sound like someone you already trust. A name plus an Israeli ID number plus a phone number plus an email plus a bank account plus a public wallet address is enough for someone to call you, email you, or contact your bank while reciting facts that feel like proof they are legitimate. That same wallet address can be looked up on a public blockchain, so activity there can be tied to a real person — not because the blockchain was hacked, but because the name and the address may now sit in the same file.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
The company used careful language on purpose. It said there may have been access. It has not confirmed that records were copied out, and it has not published any number of people. Figures such as 200,000 that appeared in news reports are not from Bits of Gold’s own statement; they track the size of the customer base. The company also said it had no sign, at the time, that the information had been used. None of that makes the combination of fields harmless if it did leave. It does mean nobody can honestly tell you, from the outside, whether your row was among those that were reachable.
What to actually expect
- Emails, texts or WhatsApp messages that mention this incident by name and ask you to “verify,” “secure” an account, enter a code, or move coins. The breach is the bait. Bits of Gold has said it will never ask for a password, a verification code, a private key, or a transfer of funds or assets.
- Calls or messages from people who already know your name and that you use Bits of Gold. That knowledge is not proof they work for the company or your bank. It is exactly the sort of detail that may have been in the analysis system.
- Someone trying your bank with account details that were on file, hoping a staff member or an automated check will treat them as you. Watch that specific account, not “your finances” in the abstract.
- A quiet period, then a second wave weeks later. Impersonation often waits until the first headlines fade and a message about “final account review” or “compensation” looks routine.
What you can and cannot fix
If your name, national ID number, contact details, bank account details or public wallet address were in that system and were accessible, that copy cannot be pulled back. You cannot change an Israeli ID number. You cannot un-publish a wallet address, and you cannot undo a pairing of that address with your legal name if the pairing left. A bank account number that is out stays out unless you stop using that account. Nobody can remove the breached file itself.
- Treat any inbound contact about this incident as hostile unless you started it yourself through the official website or app you already use. Do not move crypto because a message told you the coins are at risk. The company said funds were not involved.
- Watch the bank account whose details were on file with Bits of Gold. If you want a concrete step with the bank, tell them that account number may have been exposed in a third-party incident and ask what extra monitoring they will put on it. Opening a replacement account is the only way to retire a number that may already be in someone else’s hands.
- A leaked name, ID number and wallet address become much more dangerous when they are joined to people-search and data-broker listings that add relatives, extra phone numbers, employers and previous addresses. That join is how a dry row in a stolen file turns into a script for a phone call. Those listings, unlike the breach, can often actually be removed — and shrinking that public layer is one of the few things still under your control.
- If you still use Bits of Gold, change nothing on the basis of a link in a message. Use only the bookmark or app you already had. Passwords were not part of this incident, so a panicked reset from a “security” email is more likely to be the scam than the fix.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Betterment Robo-Advisor 1.4M Customers — January 2026
Robo-advisor Betterment disclosed a breach affecting ~1.4 million customers in January 2026 via a fa…
Harvard University Alumni & Donor Data Breach — November 2025
ShinyHunters (Scattered Lapsus$ Hunters) dumped ~115,000 sensitive records from Harvard's Alumni Aff…