Haruko, a crypto technology provider serving institutional clients, was targeted in a cyberattack earlier this week that affected 15 customers. Messages reviewed by CoinDesk and people familiar with the matter said the breach exposed read-only exchange application programming interface (API) details and trading data. Three people with knowledge of the incident said some smaller hedge-fund clients with weaker security controls may also have lost a small amount of funds.
Haruko did not respond to repeated requests for comment.
Non-whitelisted clients were affected
According to messages from Haruko co-founder and chief technology officer Adam Carlile to a client, seen by CoinDesk, all affected parties were among the company’s non-whitelisted clients. A whitelist allows communication only with approved computers or websites.
People familiar with the incident said a small amount of client funds was stolen and trading data was also taken. They added that smaller hedge funds with weaker security controls may have been especially exposed. The people spoke on condition of anonymity because the matter is private.
In messages to clients, Carlile said, 「This was a targeted attack by a group on us,」 describing Haruko itself, rather than any specific customer, as the target. He also said, 「It was 15 clients impacted.」
Attack exploited a vulnerability in one Haruko process
Carlile told clients that the attacker exploited a vulnerability in one of Haruko’s processes, extracted a user access token, and used it to capture data held in the process’s memory. That memory could have included read-only exchange API details and other data.
The messages said clients’ login credentials were not compromised on their own systems. Instead, the access token was extracted through a vulnerability in Haruko’s infrastructure.
Haruko said it had fixed the vulnerability and refreshed its server-side secrets. The company also told clients that configuring an inbound IP whitelist to restrict access to specified internet addresses would provide 「maximum protection.」 Haruko said it plans to publish a full technical post-mortem.
Institutional crypto infrastructure provider
Based in London, Haruko provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of positions, transactions and risk exposure.
Haruko does not publish its full customer roster. Its website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group, now operating as Monarq Asset Management, and Trovio Asset Management as clients.
A GSR spokesperson said, 「GSR has not been impacted by any rumored breach.」 Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication.
According to Haruko’s website, the company serves more than 80 clients globally and connects with more than 100 centralized trading venues, 30 blockchains and 250 onchain protocols.
Server setup and broader industry backdrop
One person familiar with the matter said the breach was possible because Haruko uses bare-metal servers, physical computers used exclusively by the company, rather than cloud services such as Amazon Web Services, which offer additional security controls.
APIs allow clients’ systems and Haruko’s computers to communicate and exchange information. In this case, the exposed data included read-only exchange API details and trading data. The available information indicates that clients’ own login credentials were not compromised on their systems.
The incident comes as attacks on crypto companies are rising in frequency. TRM Labs said hackers carried out a record 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier. Those incidents resulted in $972 million in losses.
TRM said infrastructure and operational compromises accounted for about 76% of the money stolen while representing only 15% of incidents. Security firm CertiK, using a broader definition, estimated first-half losses at $1.32 billion across 344 incidents.
Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible, and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

