TL;DR
-
A targeted cyberattack on institutional crypto technology provider Haruko affected 15 clients.
-
The breach reportedly exposed read-only exchange API details and confidential trading data.
-
Sources said a small amount of client funds was stolen, with smaller hedge funds potentially facing the greatest exposure.
-
Haruko reportedly fixed the vulnerability, rotated server-side secrets and recommended IP whitelisting to clients.
Haruko Breach Affects 15 Crypto Clients
Some hedge funds may have lost assets after institutional crypto technology provider Haruko suffered a cyberattack earlier this week, according to three people familiar with the incident.
The targeted breach affected 15 customers and reportedly exposed read-only exchange application programming interface credentials and trading data.
APIs allow Haruko’s platform to communicate with clients’ accounts on exchanges and other services. Although read-only API keys generally cannot authorize withdrawals, exposed trading information and credentials can still create security risks—particularly when clients have weaker safeguards elsewhere in their infrastructure.
Messages reportedly sent by Haruko co-founder and Chief Technology Officer Adam Carlile indicated that all affected customers were non-whitelisted clients. IP whitelisting restricts account access to approved internet addresses or systems.
Haruko did not respond to repeated requests for comment.
Sources said a small quantity of client funds was stolen during or after the breach, though they did not provide a specific figure.
Smaller hedge funds with less-developed security controls may have been particularly vulnerable, according to the people, who requested anonymity because the incident remains private. Attackers also obtained client trading data.
The precise mechanism through which read-only credentials may have contributed to asset losses remains unclear.
Cryptocurrency companies are frequent hacking targets because blockchain transactions are typically irreversible. The industry also relies heavily on digital credentials and signing systems that, if improperly secured, can provide attackers with access to sensitive data or assets.
Attacker Extracted Access Token From Haruko System
The attacker exploited a vulnerability in one of Haruko’s processes, according to messages Carlile sent to clients.
The flaw allowed the attacker to extract a user-access token and use it to capture information stored in the process’s memory. That memory may have contained read-only exchange API details and other client data.
Carlile reportedly told customers that credentials stored within their own systems were not compromised. Instead, the attacker obtained the access token through a vulnerability in Haruko’s infrastructure.
He described the incident as a targeted attack against Haruko rather than an operation directed at one specific customer.
One source attributed the exposure to Haruko’s use of bare-metal servers—physical machines operated exclusively by the company—instead of cloud platforms offering additional managed security controls. Haruko has not publicly confirmed that characterization.
Haruko Fixes Vulnerability and Rotates Secrets
Haruko reportedly told clients that it had patched the vulnerability and refreshed its server-side secrets following the attack.
The company also advised customers to implement inbound IP whitelists, describing the measure as providing the highest level of protection. A technical post-mortem is expected to provide further details about the breach.
Haruko offers portfolio management, risk monitoring and trade-data infrastructure to institutional digital-asset companies. Its platform connects to centralized exchanges, custodians, blockchains and decentralized-finance protocols, allowing customers to track their positions, transactions and risk exposures through a consolidated interface.
The London-based company says it serves more than 80 customers worldwide and integrates with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols.
GSR and 3iQ Say They Were Not Affected
Haruko does not publish a complete list of its clients, but its website names companies including Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, Monarq Asset Management and Trovio Asset Management.
GSR said it was not affected by the reported breach.
3iQ also confirmed that its funds remained secure. The asset manager said its API access was protected through IP whitelisting, preventing exposure to the compromised environment.
Bitcoin Suisse, Flowdesk, M2, Ampersan, Monarq and Trovio did not respond to requests for comment before publication.
Nikolas Sargeant