Bitcoin purchases were halted after a data breach at Israeli crypto broker Bits of Gold, with fuel and retail group Paz temporarily freezing the option to buy Bitcoin through its Yellow app while an investigation into the security incident continues.
Why Bitcoin purchases were halted after the data breach
Bits of Gold said it identified unusual access to its data analysis system and disconnected the affected system from its data sources as part of its response to a large-scale cyber incident, according to the company’s incident update. For related coverage, see Jane Street Reports Over $1 Billion in U.S. Spot Bitcoin ETF Shares.
In response, Paz froze the option to buy Bitcoin through the Yellow app until the investigation concludes, CTech reported. Paz said there is no direct interface between the Yellow and Bits of Gold apps. For related coverage, see Bitcoin Futures Open Interest Tops Daily Volume as Liquidation Risk Builds.
The pause is a precautionary operational step tied directly to the breach response rather than a market-driven decision. Buying activity was suspended so the platforms could contain the incident before restoring access. For related coverage, see Coinbase Noble USDC Cutoff Passed, but Circle Guide Still Points Users to Coinbase.
What the breach means for users trying to buy Bitcoin
For customers, the immediate effect is that planned or pending Bitcoin purchases through Yellow cannot go through until the freeze lifts. The disruption affects buying access, not existing holdings.
Bits of Gold said passwords, verification codes, private keys, ID photos, full credit-card details, CVV codes, customer funds, accounts, wallets, and digital assets were not exposed in the incident. The company said digital assets and funds were not involved.
However, the company said names, IP addresses, emails, phone numbers, bank account details, Israeli ID numbers, and some public wallet addresses may have been exposed. That gap between protected credentials and exposed personal data is why account-safety and identity concerns persist even though funds appear secure. The scope of that exposure is detailed in reporting that Bits of Gold’s breach may have affected a large customer base.
External reporting put the incident at roughly 200,000 affected customers, according to CoinDesk, though Bits of Gold’s public notice does not publish a confirmed total affected-user count. That figure remains externally attributed rather than company-confirmed.
The distinction matters: the transaction disruption is temporary and reversible, while the potential exposure of personal data is a longer-running trust question that outlasts the buying freeze itself. The freeze also lands as Bitcoin trades near the levels that have drawn renewed debate over a sell-off around $65,000, keeping broader sentiment cautious.
What needs to happen before Bitcoin purchases resume
Reporting has tied the incident to a critical flaw in Metabase, the data-analytics software, specifically CVE-2026-72898, though Bits of Gold’s customer notice does not name Metabase or the CVE. That attribution comes from direct reporting rather than company confirmation.
The National Vulnerability Database lists CVE-2026-72898 at the maximum CNA severity of 10.0 CRITICAL, describing a flaw that lets a remote unauthenticated attacker inject arbitrary SQL through the reset-password endpoint.
Metabase said it confirmed active exploitation, blocked the attack endpoints, and published minimum safe releases including 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5, in its security update. Patching to those versions is the remediation step that underpins any safe resumption of service.
Bits of Gold said it notified the relevant authorities, which CTech identified as Israel’s Capital Market Authority and the National Cyber Directorate. Bits of Gold was the first company in Israel’s market to receive a Capital Market Authority license to provide digital-asset financial services.
Before purchases resume, users will be looking for clear status updates confirming the affected system is secured, the vulnerability is patched, and the investigation with regulators has concluded. No public timeline for restoring Bitcoin buying through Yellow has been set.
The episode is the third crypto-industry data exposure disclosed within roughly a week, following incidents involving SafePal and Trezor vendors, per CoinDesk’s reporting. That clustering has kept the security posture of consumer-facing crypto platforms under fresh scrutiny.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.