Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost

Haruko, a London-based provider of trading and risk infrastructure for institutional crypto firms, was the target of a targeted cyberattack that affected 15 non-whitelisted clients and exposed read-only exchange API details and trading data. Sources said some smaller hedge-fund customers with weaker security controls may have lost a small amount of assets; Haruko says it has fixed the vulnerability and refreshed server-side secrets.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished about 1 hour agoUpdated about 1 hour ago0 views
Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost

Why It Matters

The incident highlights persistent security risks in crypto infrastructure providers, where breaches of centralized systems can expose multiple institutional clients and lead to irreversible asset losses. It also underscores industry-wide trends of rising attacks and losses concentrated in operational and infrastructure compromises, as reported by security firms.

Key Facts

  • Company: Haruko (London-based crypto infrastructure provider)
  • Affected clients: 15 non-whitelisted clients
  • Type of data exposed: Read-only exchange API details and trading data
  • Reported losses: A small amount of client funds potentially lost (sources)
  • Vulnerability exploited: Process memory extraction via a user-access token obtained through a Haruko infrastructure flaw},{

Haruko, which supplies portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms, was targeted in a cyberattack earlier this week that exposed exchange API details and trading data for 15 of its customers. The firm’s co-founder and chief technology officer, Adam Carlile, told clients the impacted parties were Haruko’s non-whitelisted customers; the company counts more than 80 clients globally and lists firms such as Bitcoin Suisse, GSR and Flowdesk on its website.

According to people briefed on the matter and messages reviewed by CoinDesk, the attacker exploited a vulnerability in one of Haruko’s processes to extract a user-access token and then read data from that process’s memory. That memory could have contained read-only API credentials and other trading information. Haruko told clients it has patched the vulnerability and rotated server-side secrets, and it plans to publish a full technical post-mortem.

Sources said a small amount of client funds may have been stolen in the breach, with smaller hedge funds that have weaker security controls particularly at risk. Haruko’s messages advised clients that configuring an inbound IP whitelist to restrict access to specific addresses would provide “maximum protection.” The company also emphasized the attack was targeted at Haruko rather than any single customer.

The incident comes amid a broader rise in attacks on crypto firms. Security firms reported a sharp increase in hacks and losses in recent reporting periods: TRM Labs recorded 207 attacks in the first half of 2026, more than double the year-earlier figure, resulting in $972 million in losses, while CertiK — using a broader incident definition — estimated $1.32 billion lost across 344 incidents in the same period. Industry observers note that infrastructure and operational compromises account for a disproportionate share of stolen funds.

Keep Reading