Loading prices…
🩸BEARISH

Haruko Cyberattack Hits 15 Clients and Steals Funds

The breach exposed read-only exchange APIs and trading data, underscoring how infrastructure and operational weaknesses are driving a disproportionate share of crypto losses.

Haruko Cyberattack Hits 15 Clients and Steals Funds
Haruko Cyberattack Hits 15 Clients and Steals Funds
Haruko Cyberattack Hits 15 Clients and Steals Funds
Haruko Cyberattack Hits 15 Clients and Steals Funds

Haruko, a provider of portfolio and trading infrastructure for digital-asset institutions, was targeted in a cyberattack that affected 15 clients. The breach exposed read-only exchange API details and trading data, while a small amount of client funds was stolen, according to people familiar with the incident. Smaller hedge funds with weaker security controls may have been particularly exposed.

Haruko co-founder and CTO Adam Carlile told clients that an attacker extracted a user access token through a vulnerability in one of the firm's processes and used it to capture data held in memory. Client login credentials on their own systems were not compromised, according to messages sent by the company.

Why it matters

The incident illustrates the custody risk created when institutional trading platforms connect exchanges, custodians, blockchains and DeFi protocols through shared credentials and access systems. Haruko said it fixed the vulnerability and refreshed its server-side secrets. It also urged clients to configure inbound IP whitelists and said it plans to publish a technical post-mortem.

Haruko says it serves more than 80 clients and connects with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols. The affected customers were described as Haruko's non-whitelisted clients. GSR said it was not impacted by the reported breach.

Market impact

The attack adds to a worsening security backdrop for crypto infrastructure. TRM Labs recorded 207 attacks in the first half of 2026, more than double the 83 attacks recorded a year earlier, with $972 million in losses. Infrastructure and operational compromises accounted for about 76% of stolen funds while representing 15% of incidents.

For institutional firms, the immediate focus will be credential rotation, IP restrictions and the technical post-mortem. The episode also reinforces that access controls at service providers can become a material risk across multiple trading and custody relationships.

Frequently asked questions

  1. How many Haruko clients were affected by the cyberattack?

    The attack affected 15 Haruko clients. They were described as the provider’s non-whitelisted clients.

  2. What information did the Haruko breach expose?

    The breach exposed read-only exchange API details and trading data. An access token was extracted from a vulnerable process and used to capture data held in memory.

  3. Were client login credentials compromised?

    No. Messages sent by Haruko said client login credentials on their own systems were not compromised.

  4. What steps did Haruko take after the attack?

    Haruko said it fixed the vulnerability and refreshed its server-side secrets. It also advised clients to configure inbound IP whitelists and plans to publish a technical post-mortem.

  5. How significant is the wider crypto security problem?

    TRM Labs recorded 207 attacks in the first half of 2026, resulting in $972 million in losses. Infrastructure and operational compromises accounted for about 76% of stolen funds.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →