Haruko cyberattack hit 15 clients, with some smaller hedge funds reportedly losing funds

Haruko cyberattack hit 15 clients, with some smaller hedge funds reportedly losing funds

N
News Editor
2026-09-18 15:11:52
Crypto technology provider Haruko was hit by a targeted cyberattack earlier this week, affecting 15 clients and exposing read-only exchange API details and trading data, according to messages reviewed by CoinDesk and people familiar with the matter. Three people with knowledge of the incident said some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds. Haruko said it has fixed the vulnerability, refreshed its server-side secrets, and told clients that an inbound IP whitelist would offer maximum protection. The London-based firm, which provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset companies, said the attacker exploited a vulnerability in one of its processes to extract a user access token and capture data held in memory. Haruko’s CTO Adam Carlile told clients the company itself, rather than any individual customer, was the target. The incident comes as attacks on crypto firms continue to rise, with TRM Labs reporting 207 attacks in the first half of 2026 and $972 million in losses.

Haruko, a crypto technology provider serving institutional clients, was targeted in a cyberattack earlier this week that affected 15 customers. Messages reviewed by CoinDesk and people familiar with the matter said the breach exposed read-only exchange application programming interface (API) details and trading data. Three people with knowledge of the incident said some smaller hedge-fund clients with weaker security controls may also have lost a small amount of funds.

Haruko did not respond to repeated requests for comment.

Non-whitelisted clients were affected

According to messages from Haruko co-founder and chief technology officer Adam Carlile to a client, seen by CoinDesk, all affected parties were among the company’s non-whitelisted clients. A whitelist allows communication only with approved computers or websites.

People familiar with the incident said a small amount of client funds was stolen and trading data was also taken. They added that smaller hedge funds with weaker security controls may have been especially exposed. The people spoke on condition of anonymity because the matter is private.

In messages to clients, Carlile said, 「This was a targeted attack by a group on us,」 describing Haruko itself, rather than any specific customer, as the target. He also said, 「It was 15 clients impacted.」

Attack exploited a vulnerability in one Haruko process

Carlile told clients that the attacker exploited a vulnerability in one of Haruko’s processes, extracted a user access token, and used it to capture data held in the process’s memory. That memory could have included read-only exchange API details and other data.

The messages said clients’ login credentials were not compromised on their own systems. Instead, the access token was extracted through a vulnerability in Haruko’s infrastructure.

Haruko said it had fixed the vulnerability and refreshed its server-side secrets. The company also told clients that configuring an inbound IP whitelist to restrict access to specified internet addresses would provide 「maximum protection.」 Haruko said it plans to publish a full technical post-mortem.

Institutional crypto infrastructure provider

Based in London, Haruko provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of positions, transactions and risk exposure.

Haruko does not publish its full customer roster. Its website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group, now operating as Monarq Asset Management, and Trovio Asset Management as clients.

A GSR spokesperson said, 「GSR has not been impacted by any rumored breach.」 Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication.

According to Haruko’s website, the company serves more than 80 clients globally and connects with more than 100 centralized trading venues, 30 blockchains and 250 onchain protocols.

Server setup and broader industry backdrop

One person familiar with the matter said the breach was possible because Haruko uses bare-metal servers, physical computers used exclusively by the company, rather than cloud services such as Amazon Web Services, which offer additional security controls.

APIs allow clients’ systems and Haruko’s computers to communicate and exchange information. In this case, the exposed data included read-only exchange API details and trading data. The available information indicates that clients’ own login credentials were not compromised on their systems.

The incident comes as attacks on crypto companies are rising in frequency. TRM Labs said hackers carried out a record 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier. Those incidents resulted in $972 million in losses.

TRM said infrastructure and operational compromises accounted for about 76% of the money stolen while representing only 15% of incidents. Security firm CertiK, using a broader definition, estimated first-half losses at $1.32 billion across 344 incidents.

Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible, and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.