Sources indicate that smaller hedge funds lacking robust security may have experienced financial losses due to the breach.
By Will Canny|Edited by Sheldon RebackUpdated 51 min agoPublished 53 min ago3 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on Haruko hack affected 15 crypto clients, exposing exchange API details and trading data. (Max Bender/Unsplash)SummaryShow- A cyberattack specifically targeting Haruko has impacted 15 clients, revealing read-only exchange API information and trading data.
- Smaller hedge funds with less robust security measures may have incurred financial losses, according to sources.
- Haruko has stated that it has addressed the security vulnerability and updated its server-side credentials.
In a recent cyberattack directed at Haruko, a provider of technology solutions for the crypto sector, 15 clients were affected, with some potentially losing funds, as reported by three sources familiar with the situation.
The breach compromised clients' read-only exchange application programming interface (API) details and trading data, as indicated by communications reviewed by CoinDesk and insights from individuals knowledgeable about the incident. APIs facilitate the exchange of information between clients’ systems and Haruko's infrastructure.
The clients impacted were all those not included on Haruko's whitelist, which restricts communication to authorized computers or websites, according to messages from Adam Carlile, the company's co-founder and CTO, to a client, which were reviewed by CoinDesk.
Despite multiple attempts for comment, Haruko has not responded.
The breach occurred due to Haruko's reliance on bare-metal servers—dedicated physical computers—rather than utilizing cloud services like Amazon Web Services that offer enhanced security features, according to one insider.
While Haruko does not publicly share its complete list of clients, its website lists clients such as Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management), and Trovio Asset Management.
Based in London, Haruko provides essential portfolio, risk management, and trading data infrastructure to institutional digital asset firms, allowing them to connect with centralized exchanges, custodians, blockchains, and decentralized finance (DeFi) protocols for a comprehensive view of their positions, transactions, and risks.
A spokesperson for GSR confirmed that the firm was not affected by the alleged breach. Meanwhile, Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC, and Trovio did not respond to inquiries before publication.
According to sources, a limited amount of client funds was stolen during the incident, particularly from smaller hedge funds with less effective security measures. Additionally, trading data was compromised.
The crypto sector continues to face significant security challenges, as transactions are typically irreversible, and platforms depend on digital credentials and signing systems that can provide hackers direct access to assets.
The attacker exploited a vulnerability in Haruko's processes, capturing a user-access token and using it to retrieve data from the process's memory, Carlile informed clients. This memory may have contained read-only exchange API details and other sensitive information.
Clients' login credentials on their respective systems were not compromised. The access token was extracted due to a flaw in Haruko's infrastructure.
“This was a targeted attack by a group on us,” the CTO stated in the messages, clarifying that Haruko itself was the intended target, affecting 15 clients in total.
Haruko reported that it has rectified the vulnerability and renewed its server-side credentials. The company advised clients that implementing an inbound IP whitelist to limit access to specific internet addresses would ensure “maximum protection.” Additionally, Haruko is planning to release a comprehensive technical analysis of the incident.
The firm claims to serve over 80 clients worldwide and connects with more than 100 centralized trading venues, 30 blockchains, and 250 on-chain protocols, as stated on its website.
This breach occurs amid a growing trend of cyberattacks on cryptocurrency firms. According to TRM Labs, there were 207 attacks recorded in the first half of 2026, significantly exceeding the 83 incidents reported in the same period the previous year, leading to losses of $972 million.
TRM noted that infrastructure and operational breaches accounted for approximately 76% of the stolen funds, despite representing only 15% of the total incidents. In contrast, security firm CertiK, using a broader definition, estimated first-half losses at $1.32 billion across 344 incidents.
hackingExclusiveCrypto TradingBreaking NewsLatest Crypto News- 1CFTC sends crypto rules to White House to review as Congress stalls on Clarity Act43 min ago
- 2DHS’s predictive policing is unconstitutional, un-American and should be stopped3 hrs ago
- 3ECB President Christine Lagarde intervened to block Binance’s EU MiCA license: WSJ3 hrs ago
- 4Zcash targets November upgrade to make private payments up to three times faster3 hrs ago
- 5XRP on the brink of a golden cross as focus switches to altcoins4 hrs ago
- 6Layer-2 and DeFi tokens lead broad crypto advance as post-Fed hike nerves fade5 hrs ago
- 7Bitcoin weathers September storm as rate hikes and Clarity act setback test bulls5 hrs ago
- 8Live updates: Bitcoin climbs over $80,000 as rally accelerates at U.S. market open6 hrs ago
- 9SBI Group backs payments firm dtcpay in $25 million funding round8 hrs ago
- 10Iran’s Strait of Hormuz toll booth ran through a bitcoin exchange, U.S. says9 hrs ago
The Definitive Stablecoin Landscape Series: Asia Pacific
The Definitive Stablecoin Landscape Series: Asia Pacific
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
By CoinDesk ResearchSep 15, 2026Commissioned byRippleAs stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Why it matters:
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
View Full ReportMore From Finance