Skip to main content
Sign in
Bits of Gold1 decision on this page

Audit log

Every state-changing event for Bits of Gold: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-17 23:40:26Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5kaNNMHNmMog…sLJ1HBnjsha256 → base58
    verifying row…
    canonical bytes (20446 B) ▸
    {"actor":"system:backfill","investigation_id":"f6ef462c-3310-40dd-b49b-601f0a2b73b4","kind":"publish","page_slug":"bits-of-gold","published_at":"2026-08-17T23:40:26.605Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Bits of Gold","sections":[{"content":"Bits of Gold was founded in 2013 and is headquartered in Tel Aviv, Israel. The company operates as Israel's largest regulated cryptocurrency broker, offering retail and institutional crypto trading services denominated in Israeli shekels. Co-founders include Youval Rouach (CEO) and Jonathan Rouach (Director). The company reports a customer base exceeding 300,000 and holds SOC 2 Type 2 certification. In April 2026, Israeli regulators approved the company's BILS stablecoin — pegged one-to-one with the Israeli shekel — following approximately two years in a regulatory sandbox. Bits of Gold operates under financial-services license number 56716.","heading":"Company Overview","severity":"low","sources":[{"credibility":2,"name":"Bits of Gold CEO: B2B Demand Increased Despite Falling BTC Price (Bitcoinist)","type":"news_article","url":"https://bitcoinist.com/bits-of-gold-interview-israel-bitcoin/"},{"credibility":2,"name":"Bits of Gold — Startup Nation Finder","type":"other","url":"https://finder.startupnationcentral.org/company_page/bits-of-gold"},{"credibility":2,"name":"Israel crypto broker Bits of Gold probes customer data breach (crypto.news)","type":"news_article","url":"https://crypto.news/bits-of-gold-probes-customer-data-breach/"}]},{"content":"Bits of Gold was the first active Israeli cryptocurrency company to receive a permanent financial-services license from Israel's Capital Market, Insurance and Savings Authority. The license (number 56716) was granted on September 23, 2022. The company's path to licensing was contested: in 2017, Israel's Supreme Court ruled that Bank Leumi could legally refuse service to Bits of Gold on anti-money-laundering grounds. By 2019, the Supreme Court reversed course, ruling that Leumi could not block the company's bank account — a decision that set a regulatory precedent for the Israeli crypto sector and paved the way for eventual licensing. The company notified Israel's Capital Market Authority and National Cyber Directorate following the August 2026 breach.","heading":"Regulatory History and Licensing","severity":"low","sources":[{"credibility":2,"name":"Crypto Exchange Bits of Gold Secures Capital Markets License From Israeli Regulator (crypto.news)","type":"regulatory","url":"https://crypto.news/crypto-exchange-bits-of-gold-secures-capital-markets-license-from-israeli-regulator/"},{"credibility":2,"name":"Israel Grants Its First Bitcoin, Crypto Trading License To Local Exchange Bits Of Gold (Bitcoin Magazine)","type":"news_article","url":"https://bitcoinmagazine.com/business/bits-of-gold-becomes-first-active-crypto-exchange-in-israel"},{"credibility":2,"name":"Israel's Supreme Court Lifts Banking Restrictions on Crypto Exchange Bits of Gold (CTech / Calcalist)","type":"news_article","url":"https://www.calcalistech.com/ctech/articles/0,7340,L-3732871,00.html"}]},{"content":"On August 16, 2026, Bits of Gold detected unauthorized access to a third-party data analytics system connected to its platform. The company disclosed the incident publicly on August 16-17, 2026. According to Bits of Gold's statement, an unauthorized party accessed a supporting data-analysis system several days prior to discovery. The breach is attributed to CVE-2026-72898, a CVSS 10.0-rated unauthenticated SQL injection zero-day in self-hosted releases of Metabase analytics software (versions 0.58 through 0.63.4). The vulnerability exists in Metabase's password-reset endpoint and requires no authentication to exploit. CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog. Bits of Gold characterizes the incident as part of a broader global supply-chain attack that simultaneously affected other companies. Confirmed separate victims of the same CVE include Framework, Anaconda, and n8n. The data exposed reportedly includes customer names, national ID numbers, email addresses, phone numbers, IP addresses, bank account details, and public cryptocurrency wallet addresses. Bits of Gold stated that no funds, private keys, account passwords, CVV codes, or scanned identification documents were exposed. The company has not publicly confirmed the exact number of affected customers; approximately 200,000 is the figure reported by multiple news outlets, while CryptoSlate reported up to 250,000 users at risk. Upon detection, Bits of Gold blocked access to the affected system and disconnected it from its data sources. An external cybersecurity incident-response firm was engaged. At the time of initial disclosure, the company stated it had no indication the exposed information had been misused. Bits of Gold warned customers to remain alert for phishing and social-engineering attempts, as the combination of personal identity, contact, banking, and wallet data creates conditions for highly targeted fraud.","heading":"August 2026 Data Breach — Third-Party Vendor via CVE-2026-72898","severity":"high","sources":[{"credibility":1,"name":"Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"credibility":2,"name":"Bitcoin purchases halted after data breach puts 250,000 crypto users at risk (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/bitcoin-purchases-halted-after-data-breach-puts-250000-crypto-users-at-risk/"},{"credibility":2,"name":"Israel's Largest Regulated Crypto Broker Bits of Gold Probes Data Leak (FinanceFeeds)","type":"news_article","url":"https://financefeeds.com/israels-largest-regulated-crypto-broker-bits-of-gold-probes-data-leak-potentially-affecting-200000-customers/"},{"credibility":2,"name":"Bits of Gold Reports Cyber Incident, Says Crypto Funds Are Safe (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/17/bits-of-gold-reports-cyber-incident-says-crypto-funds-are-safe/"},{"credibility":2,"name":"Israel crypto broker Bits of Gold probes customer data breach (crypto.news)","type":"news_article","url":"https://crypto.news/bits-of-gold-probes-customer-data-breach/"},{"credibility":2,"name":"Israel's Largest Crypto Broker Reports Data Breach (Yahoo Finance)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/israel-largest-crypto-broker-reports-141000691.html"}]},{"content":"CVE-2026-72898 is a critical unauthenticated SQL injection vulnerability in Metabase, an open-source business intelligence and analytics platform commonly used by organizations for internal data dashboards. The vulnerability carries a CVSS 3.1 base score of 10.0, the maximum possible rating, reflecting its network-accessible, no-authentication, no-user-interaction attack vector. The flaw resides in the POST /api/session/reset_password endpoint. A remote attacker can inject arbitrary SQL through this endpoint and obtain administrator access to the Metabase instance, from which all connected downstream databases and credentials become accessible. Affected versions span 0.58.0 through 0.63.4 across multiple release branches; Metabase released patches in versions 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5. Internet-wide scanning identified approximately 11,000 probable self-hosted Metabase instances, of which roughly 4,309 were potentially vulnerable, with over 97% of fingerprinted hosts on affected branches appearing unpatched at the time of reporting. Metabase disclosed an active exploitation incident on August 6, 2026, and CISA subsequently added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog. The Bits of Gold incident is consistent with organizations that had self-hosted Metabase deployments through third-party vendors operating on unpatched versions.","heading":"CVE-2026-72898: Metabase Zero-Day Technical Context","severity":"high","sources":[{"credibility":2,"name":"CVE-2026-72898 — Unauthenticated SQL Injection / Admin Takeover — Metabase (IONIX Threat Center)","type":"research","url":"https://www.ionix.io/threat-center/cve-2026-72898/"},{"credibility":2,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (The Hacker News)","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":2,"name":"Metabase vulnerability CVE-2026-72898: Find impacted assets (runZero)","type":"research","url":"https://www.runzero.com/blog/metabase/"},{"credibility":2,"name":"Metabase SQL Injection Breached Five Companies, Exposed All Connected Database Credentials (TechTimes)","type":"news_article","url":"https://www.techtimes.com/articles/324060/20260812/metabase-sql-injection-breached-five-companies-exposed-all-connected-database-credentials.htm"}]},{"content":"The data categories exposed in the August 2026 breach create a heightened risk of identity theft and targeted fraud for affected customers. Israeli national ID numbers, combined with full names, phone numbers, bank account details, and public wallet addresses, provide sufficient material to craft convincing impersonation attempts or fraudulent transactions. Public wallet addresses, while not sensitive in isolation, allow bad actors to identify high-value crypto holders and tailor attacks accordingly. Bits of Gold advised customers to avoid clicking suspicious links, not to share passwords or one-time verification codes, and not to transfer digital assets in response to unsolicited contact. The company stated at time of disclosure that it had no indication the exposed data had been misused. Paz, a commercial partner operating Yellow convenience store Bitcoin purchasing services, reportedly suspended Bitcoin purchases through its app following the disclosure, though the broader commercial agreement between the companies remained active according to CryptoSlate.","heading":"Customer Risk Profile Following the Breach","severity":"high","sources":[{"credibility":2,"name":"Bitcoin purchases halted after data breach puts 250,000 crypto users at risk (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/bitcoin-purchases-halted-after-data-breach-puts-250000-crypto-users-at-risk/"},{"credibility":2,"name":"Bits of Gold Reports Cyber Incident, Says Crypto Funds Are Safe (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/17/bits-of-gold-reports-cyber-incident-says-crypto-funds-are-safe/"}]},{"content":"The Bits of Gold breach occurred alongside two other crypto-sector third-party vendor incidents within the same week. SafePal reported that data from nearly 40,000 users was stolen after a third-party vendor suffered a security breach, and personal data from approximately 14,000 Trezor wallet customers was exposed on August 13, 2026 after Trezor's fulfillment partner ShipMonk was compromised. All three incidents involved breaches of third-party service providers rather than direct attacks on the core trading or custody infrastructure of the affected companies. The pattern reflects a broader trend of attackers targeting vendor ecosystems that aggregate customer data across multiple organizations, rather than attacking well-defended primary infrastructure directly. Bits of Gold's own statement characterized its incident as part of a broader global attack affecting multiple companies simultaneously.","heading":"Broader Industry Supply-Chain Context","severity":"medium","sources":[{"credibility":1,"name":"Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"credibility":3,"name":"Hackers hit a Bits of Gold vendor and swept up 200,000 Israeli crypto customers (Startup Fortune)","type":"news_article","url":"https://startupfortune.com/hackers-hit-a-bits-of-gold-vendor-and-swept-up-200000-israeli-crypto-customers/"}]}],"sources_used":[{"credibility":1,"name":"Israel's largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"credibility":2,"name":"Bitcoin purchases halted after data breach puts 250,000 crypto users at risk (CryptoSlate)","type":"news_article","url":"https://cryptoslate.com/bitcoin-purchases-halted-after-data-breach-puts-250000-crypto-users-at-risk/"},{"credibility":2,"name":"Israel's Largest Regulated Crypto Broker Bits of Gold Probes Data Leak (FinanceFeeds)","type":"news_article","url":"https://financefeeds.com/israels-largest-regulated-crypto-broker-bits-of-gold-probes-data-leak-potentially-affecting-200000-customers/"},{"credibility":2,"name":"Bits of Gold Reports Cyber Incident, Says Crypto Funds Are Safe (CryptoTimes)","type":"news_article","url":"https://www.cryptotimes.io/2026/08/17/bits-of-gold-reports-cyber-incident-says-crypto-funds-are-safe/"},{"credibility":2,"name":"Israel crypto broker Bits of Gold probes customer data breach (crypto.news)","type":"news_article","url":"https://crypto.news/bits-of-gold-probes-customer-data-breach/"},{"credibility":2,"name":"Israel's Largest Crypto Broker Reports Data Breach (Yahoo Finance)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/israel-largest-crypto-broker-reports-141000691.html"},{"credibility":2,"name":"Crypto Exchange Bits of Gold Secures Capital Markets License From Israeli Regulator (crypto.news)","type":"regulatory","url":"https://crypto.news/crypto-exchange-bits-of-gold-secures-capital-markets-license-from-israeli-regulator/"},{"credibility":2,"name":"Israel Grants Its First Bitcoin, Crypto Trading License To Local Exchange Bits Of Gold (Bitcoin Magazine)","type":"news_article","url":"https://bitcoinmagazine.com/business/bits-of-gold-becomes-first-active-crypto-exchange-in-israel"},{"credibility":2,"name":"Israel's Supreme Court Lifts Banking Restrictions on Crypto Exchange Bits of Gold (CTech / Calcalist)","type":"news_article","url":"https://www.calcalistech.com/ctech/articles/0,7340,L-3732871,00.html"},{"credibility":2,"name":"CVE-2026-72898 — Unauthenticated SQL Injection / Admin Takeover — Metabase (IONIX Threat Center)","type":"research","url":"https://www.ionix.io/threat-center/cve-2026-72898/"},{"credibility":2,"name":"Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (The Hacker News)","type":"news_article","url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"credibility":2,"name":"Metabase vulnerability CVE-2026-72898: Find impacted assets (runZero)","type":"research","url":"https://www.runzero.com/blog/metabase/"},{"credibility":2,"name":"Metabase SQL Injection Breached Five Companies, Exposed All Connected Database Credentials (TechTimes)","type":"news_article","url":"https://www.techtimes.com/articles/324060/20260812/metabase-sql-injection-breached-five-companies-exposed-all-connected-database-credentials.htm"},{"credibility":2,"name":"Bits of Gold — Startup Nation Finder","type":"other","url":"https://finder.startupnationcentral.org/company_page/bits-of-gold"},{"credibility":3,"name":"Hackers hit a Bits of Gold vendor and swept up 200,000 Israeli crypto customers (Startup Fortune)","type":"news_article","url":"https://startupfortune.com/hackers-hit-a-bits-of-gold-vendor-and-swept-up-200000-israeli-crypto-customers/"},{"credibility":2,"name":"Bits of Gold Confirms Major Data Breach Affecting 200,000 Crypto Customers (Crypto Economy)","type":"news_article","url":"https://crypto-economy.com/bits-of-gold-data-breach-200000-customers/"}],"summary":"Bits of Gold is Israel's largest regulated cryptocurrency broker, founded in 2013 and licensed by the Israeli Capital Market, Insurance and Savings Authority since 2022. On August 16-17, 2026, the company disclosed that a third-party analytics vendor breach exposed personal data on approximately 200,000 customers — including national ID numbers, bank account details, and public wallet addresses — stemming from CVE-2026-72898, an actively exploited zero-day in self-hosted Metabase software. Customer crypto funds and private keys were not compromised, and the company has engaged a cybersecurity incident-response firm while notifying Israeli regulators.","timeline":[{"date":"2013-01-01","event":"Bits of Gold founded in Tel Aviv, Israel.","source":"Startup Nation Finder / Bitcoinist","source_url":"https://finder.startupnationcentral.org/company_page/bits-of-gold"},{"date":"2017-01-01","event":"Israeli Supreme Court rules Bank Leumi may legally refuse banking service to Bits of Gold on anti-money-laundering grounds.","source":"CTech / Calcalist","source_url":"https://www.calcalistech.com/ctech/articles/0,7340,L-3732871,00.html"},{"date":"2019-01-01","event":"Israeli Supreme Court reverses earlier ruling, prohibiting Bank Leumi from blocking Bits of Gold's account — setting a precedent for Israeli crypto banking access.","source":"CTech / Calcalist","source_url":"https://www.calcalistech.com/ctech/articles/0,7340,L-3732871,00.html"},{"date":"2022-09-23","event":"Bits of Gold becomes the first active Israeli crypto company to receive a permanent financial-services license (no. 56716) from Israel's Capital Market, Insurance and Savings Authority.","source":"crypto.news","source_url":"https://crypto.news/crypto-exchange-bits-of-gold-secures-capital-markets-license-from-israeli-regulator/"},{"date":"2026-04-27","event":"Israeli regulators approve Bits of Gold's BILS stablecoin, pegged one-to-one to the Israeli shekel, following approximately two years in a regulatory sandbox.","source":"crypto.news / Analytics Insight","source_url":"https://crypto.news/bits-of-gold-probes-customer-data-breach/"},{"date":"2026-08-06","event":"Metabase discloses active exploitation of CVE-2026-72898, a CVSS 10.0 unauthenticated SQL injection zero-day; CISA adds the flaw to its Known Exploited Vulnerabilities catalog.","source":"The Hacker News / IONIX","source_url":"https://thehackernews.com/2026/08/metabase-zero-day-exploited-in-wild.html"},{"date":"2026-08-13","event":"Trezor reports approximately 14,000 customers' personal data exposed after fulfillment partner ShipMonk is compromised.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"date":"2026-08-16","event":"Bits of Gold detects unauthorized access to a third-party data analytics system. The company blocks access and disconnects the affected system. Israeli Capital Market Authority and National Cyber Directorate are notified. An external cybersecurity incident-response firm is engaged.","source":"crypto.news / CryptoTimes","source_url":"https://crypto.news/bits-of-gold-probes-customer-data-breach/"},{"date":"2026-08-16","event":"SafePal reports data from nearly 40,000 users stolen after a third-party vendor breach.","source":"CoinDesk","source_url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"date":"2026-08-17","event":"Bits of Gold publicly discloses the breach. Approximately 200,000 customers' personal data reported as exposed, including names, national ID numbers, emails, phone numbers, IP addresses, bank account details, and public wallet addresses. Company states no funds, private keys, passwords, CVV codes, or scanned ID documents were compromised.","source":"CoinDesk / CryptoSlate / FinanceFeeds","source_url":"https://www.coindesk.com/tech/2026/08/17/israel-s-largest-crypto-broker-bits-of-gold-hit-by-data-breach-affecting-200-000-customers"},{"date":"2026-08-17","event":"Paz reportedly suspends Bitcoin purchases through its Yellow convenience store app following the Bits of Gold breach disclosure.","source":"CryptoSlate","source_url":"https://cryptoslate.com/bitcoin-purchases-halted-after-data-breach-puts-250000-crypto-users-at-risk/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision ecce6ca4-eb48-498e-a54b-a0f0287c1868
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.