Threat Intelligence Brief
Curated summary with source attribution
Source: kucoin.com
Threat Risk: Medium
Victim: Bits of Gold
Incident: Data breach resulting in the theft of approximately 200,000 customer records.
Impact: Potential exposure of sensitive personal information for a large number of crypto brokerage clients.
Attacker: Unidentified threat actors
Analysis: The breach targeting Bits of Gold underscores the persistent risk facing Virtual Asset Service Providers (VASPs) that manage high-value customer data. Although the specific data categories have not been disclosed, the scale of the incident suggests a significant compromise of user privacy.
Recommendations: Enable multi-factor authentication (MFA) on all cryptocurrency and financial accounts; Stay vigilant against targeted phishing campaigns leveraging stolen personal data; Rotate passwords for any accounts sharing credentials with the breached platform
Source: KuCoin
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source
Latest Developments
Update — 2026-08-16 18:15 UTC
Data breach involving the exposure of customer personal information. Personal data of 200,000 users has been compromised. The breach involves the unauthorized leak of personal data for approximately 200,000 customers. This type of exposure typically increases the risk of targeted phishing and credential stuffing attacks against the affected users.
Corroborating source: binance.com
Update — 2026-08-16 20:19 UTC
Data breach of a cryptocurrency broker’s customer database. Exposure of personal identity information for 200,000 users. The breach targeted server-side personal identity documents rather than digital asset wallets. Because the company is a regulated broker, the stolen data likely includes sensitive KYC information such as government IDs. This creates a significant secondary risk of highly targeted phishing and identity theft for the entire user base.
Corroborating source: cryptobriefing.com
Update — 2026-08-17 10:01 UTC
Data breach of an external analytics provider exposing PII of 250,000 customers. Exposure of personal identification and contact details increasing the risk of targeted phishing and fraud. The breach originated at an external analytics provider, highlighting a critical supply chain vulnerability where third-party access becomes a primary attack vector. While core assets and passwords remain secure, the leakage of PII combined with known cryptocurrency usage allows attackers to craft highly convincing social engineering lures. This incident underscores the risk of data sprawl across external service providers.
Corroborating source: calcalistech.com
Update — 2026-08-17 14:09 UTC
Data breach resulting in the exposure of personal customer information. Personal data of 200,000 users is exposed, increasing risks of fraud and identity theft. The incident involved the unauthorized exposure of personal data belonging to approximately 200,000 customers. This breach increases the risk of targeted phishing and identity theft for the affected user base. The scale suggests a compromise of a centralized customer database.
Corroborating source: binance.com
Update — 2026-08-17 17:06 UTC
A third-party data analytics network compromise led to a massive customer data leak. Personal and financial information of approximately 200,000 customers was exposed. The breach occurred via unauthorized access to a third-party data analytics network rather than the broker’s core systems. While digital assets and private keys remained secure, the exposure of national IDs and bank details creates a high risk for identity theft and targeted phishing. This incident is reportedly part of a wider global campaign targeting similar service providers.
Corroborating source: bitcoinke.io
Update — 2026-08-17 18:07 UTC
Unauthorized access to customer PII via a third-party support and analysis system. Potential exposure of names, IDs, and bank details for up to 200,000 customers. The breach occurred through a third-party support and analysis platform, highlighting a significant supply chain vulnerability. While financial assets and passwords remain secure, the exposure of PII and bank details increases the risk of targeted phishing. This incident is reportedly linked to a broader campaign affecting multiple organizations using the same software.
Corroborating source: grafa.com
Update — 2026-08-17 18:59 UTC
Unauthorized access to a data-analysis system resulting in a mass PII leak. Exposure of personal, banking, and wallet information for 250,000 customers. The breach occurred through unauthorized access to a supporting data-analysis system, likely leveraging a vulnerability in self-hosted Metabase software. While digital assets remain secure, the exposure of national IDs and banking details significantly increases the risk of identity theft and targeted social engineering. This incident highlights the danger of tertiary analysis tools becoming the primary entry point for attackers in financial environments.
Corroborating source: cryptoslate.com
Update — 2026-08-19 11:23 UTC
Data breach via a support analysis system. Exfiltration of PII for approximately 200,000 customers. Threat actors gained unauthorized access through a support analysis system to exfiltrate extensive customer PII. While core financial assets and private keys remain secure, the breadth of leaked data significantly increases the risk of targeted phishing and identity theft. This incident aligns with a recent trend of supply-chain and third-party vulnerabilities targeting cryptocurrency service providers.
Corroborating source: cybernews.com