Block number: N/A (CeFi incident). CVE: CVE-2026-72898. Affected: 250,000 users.
Bits of Gold, Israel's first licensed VASP, got pwned. Not through a smart contract bug. Not through a private key leak. Through a Metabase instance. A self-hosted BI tool. The kind of system that ops teams set up, forget to patch, and never put under the same security microscope as the hot wallet.
I've audited enough CeFi setups to know: the asset layer is a fortress. The data layer is a trailer park. This breach proves it. Again.

Here's the timeline. Bits of Gold discovered unauthorized access to its auxiliary data analysis system. The vector: CVE-2026-72898, a Metabase vulnerability for self-hosted versions. Attackers grabbed customer data—full names, email, phone, bank account details. No private keys. No CVV. No direct asset loss. But the damage is already done.
Paz, the Israeli energy giant that integrated Bitcoin purchases via the Yellow app, immediately suspended the service. That's a 2025 bull-market narrative killer: retail-crypto adoption pausing because of a data breach, not a chain failure.
Context: Why This Matters Now
Bits of Gold isn't just any broker. It's the first in Israel to get a VASP license from the Capital Market Authority. It's the poster child for 'regulated crypto is safe.' That narrative just took a bullet.
Metabase is a BI tool used by thousands of teams for internal analytics. It's often self-hosted, with minimal security hardening. The CVE number is brand new (2026 disclosure). That means the attackers likely used a zero-day or a very recent N-day. Bits of Gold didn't patch in time. Classic.
Core: The Technical Breakdown
Let me be clear: Bits of Gold's architecture separated asset custody from data systems. That's why funds are safe. But the data system was the weak link. The attackers accessed a system that aggregated customer PII and financial details. This is not a 'hack' in the crypto sense—it's a data breach with a 250,000-user blast radius.
From my forensic experience, I've seen this pattern before. The auxiliary system is where security teams spend the least. It's not a validator. It's not a node. It's just a dashboard. But it holds the keys to the kingdom: user identities, bank accounts, transaction histories.
Bits of Gold's response was textbook: lock down the system, disconnect data sources, bring in a third-party incident response firm, notify regulators. They did everything right post-breach. But pre-breach, they missed the Metabase patch. That's the gap.
Contrarian: The Unreported Angle
The media will focus on the breach itself. The real story is different.
First, the 'regulated = safe' illusion is now permanently dented. Bits of Gold was the most audited, most compliant player in Israel. If they can't secure a BI tool, what about the unlicensed ones? Expect the Israel Securities Authority to launch a sweep of all licensed VASPs. This breach will become a policy catalyst.
Second, the Paz suspension is a canary in the coal mine. Traditional brands are hypersensitive to crypto risk. One data breach, and they pull the plug. The Yellow app's Bitcoin purchase feature was a gateway for mass adoption. Now it's paused indefinitely. This will make other retailers think twice before integrating crypto services. The cost of customer data leaks is now a barrier to partnership.
Third, the leaked bank account details are a bigger deal than anyone is saying. Attackers can use those for traditional financial fraud. That means Bits of Gold's customers are now at risk of being targeted by social engineering attacks targeting their bank accounts, not just their crypto wallets. This expands the damage from 'crypto incident' to 'general fraud incident.' The regulatory overlap between ISA and the anti-money laundering authority just got complicated.
Takeaway: What to Watch Next
The next 90 days will determine the long-term impact. If Bits of Gold can produce a clean security audit and restore Paz's integration, this will be a footnote. If not, it becomes a case study in how compliance does not equal security.
I'm watching three things: 1) The ISA's enforcement action, 2) whether Paz resumes the Yellow app integration, and 3) the number of phishing attacks targeting the leaked user base. If that number spikes, expect a class-action lawsuit.
This is a wake-up call for every regulated crypto entity. Patch your BI tools. Audit your data systems. Because the next attacker won't target your hot wallet. They'll target your dashboard.
Response: 3rd-party forensics underway. Trust repair: quarterly timeline.