Bitcoin purchases paused after Bits of Gold data breach
Bits of Gold confirmed unauthorized access that may have exposed personal and banking data for up to 250,000 customers; Paz paused Bitcoin purchases on Yellow.
On Aug. 16, Bits of Gold confirmed unauthorized access to a supporting data-analysis system that may have exposed personal information for as many as 250,000 customers. The company said customer funds and crypto assets remain secure, and that account passwords and identification-document images were not exposed. Potentially exposed data include names, national identity numbers, phone numbers, email and IP addresses, bank-account details and public crypto wallet addresses. Bits of Gold noted it does not hold customers’ private keys, full card numbers or CVV codes.
Following the disclosure, retail group Paz temporarily halted Bitcoin purchases and suspended the Bits of Gold integration on its Yellow convenience app while investigators probe the issue. Paz said the Yellow app does not share a direct interface with Bits of Gold and that it did not believe Yellow customer information was leaked. The commercial agreement between the companies remains in effect and Bits of Gold’s main services continue to operate.
Security researchers have linked the incident to an active exploit, CVE-2026-72898, affecting self-hosted releases of Metabase, an analytics and data-visualization platform. In response, Bits of Gold blocked access to the affected system, disconnected it from its data sources, engaged a cybersecurity incident-response firm and notified regulators, including the Capital Market Authority and the National Cyber Directorate.
Customers were told no technical action, such as moving funds or crypto assets, was required. The company advised users to remain alert for phishing attempts, refuse unsolicited transfer requests and never share verification codes, one-time passwords or private keys.
Security specialists warn that exposed contact and financial information can be used in phishing, impersonation and social-engineering attacks that target users outside the affected platform. Such data can be combined to create convincing scams that try to get customers to reveal credentials or approve transfers.
Investigations are ongoing to determine the exact attack path and the full scope of the compromise. Bits of Gold will provide further updates as forensic work and regulatory notifications proceed.








