Haruko cyberattack hit 15 clients, with some smaller hedge funds reportedly losing funds
Crypto technology provider Haruko was hit by a targeted cyberattack earlier this week, affecting 15 clients and exposing read-only exchange API details and trading data, according to messages reviewed by CoinDesk and people familiar with the matter. Three people with knowledge of the incident said some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds. Haruko said it has fixed the vulnerability, refreshed its server-side secrets, and told clients that an inbound IP whitelist would offer maximum protection. The London-based firm, which provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset companies, said the attacker exploited a vulnerability in one of its processes to extract a user access token and capture data held in memory. Haruko’s CTO Adam Carlile told clients the company itself, rather than any individual customer, was the target. The incident comes as attacks on crypto firms continue to rise, with TRM Labs reporting 207 attacks in the first half of 2026 and $972 million in losses.








