7OrStone

Market Prices

BTC Bitcoin
$68,035.9 +5.08%
ETH Ethereum
$2,079.06 +8.64%
SOL Solana
$81.2 +5.56%
BNB BNB Chain
$615.2 +2.06%
XRP XRP Ledger
$1.06 +5.41%
DOGE Dogecoin
$0.0721 +2.63%
ADA Cardano
$0.1786 +2.47%
AVAX Avalanche
$6.54 +2.99%
DOT Polkadot
$0.7718 +3.26%
LINK Chainlink
$9.89 +4.38%

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$68,035.9
1
Ethereum ETH
$2,079.06
1
Solana SOL
$81.2
1
BNB Chain BNB
$615.2
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0721
1
Cardano ADA
$0.1786
1
Avalanche AVAX
$6.54
1
Polkadot DOT
$0.7718
1
Chainlink LINK
$9.89

🐋 Whale Tracker

🔴
0xd673...756a
2m ago
Out
2,336,257 USDT
🔴
0x178f...908f
3h ago
Out
36,191 BNB
🔵
0xd4c1...9f8d
12m ago
Stake
31,760 SOL

The Metabase Breach: When the Backend Analytics Tool Becomes the Front Door to Crypto User Data

Special | CryptoPomp |

Often, we overlook the quiet backends—the internal dashboards, the analytics servers, the data pipelines that are not part of the blockchain's consensus layer. But a recent incident at Israel's first licensed crypto broker, Bits of Gold, forces us to look there. A single vulnerability in a self-hosted Metabase instance, cataloged as CVE-2026-72898, has exposed the personal and financial details of approximately 250,000 customers. No smart contract was exploited, no private key was stolen, yet the event has already triggered a pause in Bitcoin purchases through the retail-focused Yellow app, integrated by Paz, Israel's energy and retail giant. Tracing the hidden vulnerabilities in the code, this is a story about the infrastructure we forget to secure.

Bits of Gold, operating under the supervision of the Israel Securities Authority (ISA) as a licensed Virtual Asset Service Provider (VASP), has long been considered a pillar of regulatory compliance in the Israeli crypto ecosystem. It serves as a fiat-to-crypto on-ramp, holding accounts with major banks and enabling customers to buy and sell Bitcoin. The company's integration with Paz's Yellow app was a landmark moment—bringing crypto purchases to millions of households through convenience stores. The breach, which occurred days before the public disclosure on August 16, 2026, involved an unauthorized access to an 'auxiliary data analysis system'—a self-hosted instance of the open-source business intelligence tool Metabase. Redefining what ownership means in the digital age, the incident reminds us that owning a license does not automatically mean owning a secure perimeter.

Core Analysis: The Anatomy of a Data Layer Breach

The technical architecture of Bits of Gold reveals a critical design choice: customer funds are isolated from customer data. The company does not hold private keys, full card details, or CVV numbers. This separation is commendable and likely prevented direct asset theft. However, the 'auxiliary data analysis system'—a Metabase instance used for internal reporting and analytics—contained a goldmine of personally identifiable information (PII): names, addresses, phone numbers, national ID numbers, and even bank account details. The vulnerability, CVE-2026-72898, is categorized as a critical flaw in the self-hosted version of Metabase, likely involving authentication bypass or arbitrary file read. Based on my experience auditing DeFi protocols during the DeFi Summer of 2020, I have seen firsthand how internal tools are often the weakest link. They are deployed with minimal security configurations, relying on network isolation rather than robust access controls. The attack surface here is not the blockchain but the software stack that supports the business. Bits of Gold's response—blocking the affected system, disconnecting data sources, and engaging third-party incident response experts—is textbook. But the damage is done. The attackers likely had access for days or weeks, enough to exfiltrate a comprehensive database. The company stated that funds are safe, and no customer had to take technical action. But this is a half-truth. The data is now in the hands of malicious actors, and the long-term consequences—phishing, identity theft, financial fraud—cannot be patched.

The Metabase Breach: When the Backend Analytics Tool Becomes the Front Door to Crypto User Data

Contrarian Angle: The False Security of Compliance

The market's initial reaction is muted. Crypto veterans dismiss it as 'just another data breach,' pointing out that no on-chain assets were lost. But this overlooks a deeper blind spot. The incident challenges the narrative that regulated, licensed entities are inherently safer than unregulated ones. Bits of Gold was the most compliant broker in Israel, audited by the ISA, yet its auxiliary systems were vulnerable. Quietly securing the layers beneath the hype, we must ask: if the regulated gateway can be breached, what does that say about the countless unregulated services? Furthermore, the breach exposes the fragility of the retail-crypto integration model. Paz's decision to pause Bitcoin purchases on Yellow is not just a precaution; it is a reputation-driven move. A traditional retail giant like Paz cannot afford to be associated with a data leak that exposes its customers' bank details. The fact that the broader commercial agreement remains intact is a sign of resilience, but the suspension of the most visible crypto feature sends a clear signal to other potential partners: due diligence on a crypto partner must now include deep security audits of every internal system, not just the smart contracts. The contrarian insight is that the real damage is not the data loss itself, but the chilling effect on future partnerships between traditional enterprises and crypto service providers. The 'safety of the regulated' narrative is now damaged, and the cost of rebuilding that trust will be measured in months, not days.

Takeaway: A Vulnerability Forecast for the Industry

This event is not an anomaly; it is a template. The use of open-source analytics tools like Metabase, Grafana, and Superset is widespread across crypto companies. Most of these tools are self-hosted and receive far less security attention than the primary trading or custody platforms. We should expect a wave of similar attacks targeting auxiliary systems. The crypto industry must extend its security audits beyond the blockchain layer to include every internal data pipeline. Building trust through rigorous, unseen diligence is the only way to prevent the next breach. For Bits of Gold, the road ahead involves not just technical remediation but also a prolonged effort to reassure customers, regulators, and partners. The next time a startup boasts about its regulatory license, ask about its Metabase version.


This article is based on publicly available information and analysis of the Bits of Gold data breach incident. The author's views are derived from technical and market analysis, not from any insider knowledge.

Fear & Greed

46

Fear

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0xe131...2065
Early Investor
+$0.6M
70%
0x08fa...e672
Arbitrage Bot
+$1.3M
89%
0x87df...e1be
Market Maker
+$5.0M
84%