What to Know
- Haruko, a London-based crypto technology provider serving institutional digital-asset firms, was targeted in a cyberattack.
- The incident affected 15 clients and exposed read-only exchange API details and trading data.
- Some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds.
- Haruko said the attacker exploited a vulnerability in one of its processes, extracted a user-access token and captured data held in process memory.
- Client login credentials on client systems were not compromised, based on messages shared with clients.
- Haruko said it fixed the vulnerability and refreshed its server-side secrets.
- The company told clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide maximum protection.
- Haruko says it serves more than 80 clients globally and connects with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols.
- The incident comes as crypto cyberattacks remain a major industry risk, with TRM Labs citing a record 207 attacks in the first half of 2026 and $972 million in losses.
Haruko Breach Raises Fresh Concerns Over Institutional Crypto Infrastructure
Haruko, a provider of portfolio, risk-management and trade-data infrastructure for institutional crypto firms, has been hit by a targeted cyberattack that affected 15 clients and exposed read-only exchange API details and trading data. The incident underscores a persistent vulnerability across the digital-asset industry: critical infrastructure providers sit at the center of complex networks connecting exchanges, custodians, blockchains and decentralized-finance protocols, creating an attractive target for attackers seeking sensitive operational data or pathways toward assets.
The London-based company serves institutional digital-asset firms that need consolidated oversight of positions, transactions and risk exposure. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance protocols, helping clients monitor activity across fragmented crypto markets. That role makes the security of API connections and platform-level secrets especially important, even where credentials are designed to be read-only or limited in scope.
The cyberattack affected all of Haruko’s non-whitelisted clients, based on client communications. A whitelist is a security measure that allows communication only with approved computers or websites. In practical terms, inbound IP whitelisting can restrict access to known internet addresses and help limit the ability of unauthorized systems to interact with sensitive services. Haruko told clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide maximum protection.
What Was Exposed in the Haruko Attack?
The exposed information included read-only exchange application programming interface details and trading data. APIs allow client systems, exchange platforms and service providers such as Haruko to communicate and exchange information. In institutional trading environments, APIs can be used for tasks such as retrieving account balances, collecting trade data, monitoring risk, and in some cases placing or managing orders, depending on permission settings.
In this incident, the exposed exchange API details were described as read-only. That distinction matters because read-only API keys generally do not grant permission to move funds or execute trades. However, read-only access can still reveal sensitive information about positions, trading patterns, venue exposure, portfolio structure and operational habits. For hedge funds and trading firms, that type of data can be commercially sensitive even if it does not directly authorize withdrawals.
Some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds. The exact mechanism by which funds may have been taken was not publicly detailed. The available information indicates that clients’ login credentials were not compromised on their own systems. Instead, the attacker extracted a user-access token through a vulnerability in Haruko’s infrastructure and used it to capture data held in the process’s memory. That memory could have included read-only exchange API details and other data.
Haruko Says Vulnerability Was Fixed
Haruko said it fixed the vulnerability and refreshed its server-side secrets. In cybersecurity terms, refreshing secrets can involve replacing sensitive tokens, keys or credentials used by servers and applications to authenticate, communicate or access protected systems. The step is typically intended to reduce the risk that any previously exposed secret can continue to be used by an attacker.
The company also plans to publish a full technical post-mortem. For institutional clients, a post-mortem can be an important document because it may clarify the vulnerability, timeline, affected systems, remediation steps and any recommended actions. Technical traders and operational teams often use such disclosures to evaluate whether additional controls are needed around API permissions, IP restrictions, exchange-side settings and monitoring systems.
Haruko characterized the incident as a targeted attack against the company rather than a strike aimed at a particular customer. The distinction is important for institutional risk teams because vendor-side compromise can create downstream exposure even when a client’s own internal systems remain intact. A client can maintain strong workstation security and internal access controls, yet still face risk if a third-party platform handling sensitive connectivity suffers a breach.
Why API Security Is Critical in Crypto Markets
API credentials are a core part of crypto market infrastructure. Digital-asset firms often trade across multiple venues and maintain relationships with exchanges, custodians, blockchains and onchain protocols. To manage that complexity, they rely on automated systems that collect balances, positions and trading data. Those systems require credentials, tokens and permissions to operate efficiently.
That convenience creates a security challenge. If credentials are too broad, a breach can lead directly to unauthorized activity. If credentials are read-only, the direct asset risk may be lower, but the exposure of trading data can still be damaging. In fast-moving crypto markets, knowledge of a fund’s positions, execution patterns or exchange relationships can be valuable intelligence. For smaller hedge funds, weaker operational controls may heighten the potential impact of a third-party incident.
Crypto transactions are generally irreversible, which is one reason hacks remain such a persistent industry problem. Once assets are transferred onchain or withdrawn through compromised infrastructure, recovering them can be difficult. That reality has pushed institutional market participants to focus on defense-in-depth measures, including whitelisting, segmented permissions, separate withdrawal controls, hardware-backed signing processes and close monitoring of API use.
Client Exposure and Industry Response
Haruko does not disclose its full customer roster, though its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group, now operating as Monarq Asset Management, and Trovio Asset Management as clients. GSR said it had not been impacted by any rumored breach. Other named companies did not provide public responses before publication time.
The scope described by Haruko places the incident at 15 impacted clients. That number is significant in the context of institutional crypto operations because a single technology provider may be deeply integrated into multiple clients’ trading and risk workflows. Even when the immediate financial losses are described as small, the operational implications can be broader, including credential rotation, API audits, internal reviews and tighter access controls.
The breach was possible because Haruko uses bare-metal servers rather than cloud services such as Amazon Web Services, which offer additional security controls, according to one person familiar with the matter. Bare-metal servers are physical computers dedicated to a single user or organization. They can offer performance and control advantages, but the security model depends heavily on how the infrastructure is configured, monitored and maintained. Cloud environments, by contrast, may provide built-in security features, although they also require careful configuration.
Crypto Hacks Continue to Escalate
The Haruko incident lands against a backdrop of increasing crypto security breaches. TRM Labs cited a record 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier. Those incidents resulted in $972 million in losses. The figures point to a threat environment in which attackers continue to target the operational layers that support trading, custody and onchain activity.
TRM Labs also said infrastructure and operational compromises accounted for about 76% of the money stolen despite representing only 15% of incidents. That imbalance highlights why vendor infrastructure, credential handling and internal operational safeguards are so important. A small number of successful compromises at the infrastructure layer can produce outsized losses because such systems may touch many accounts, venues or client workflows.
Security firm CertiK, using a broader definition, estimated first-half losses at $1.32 billion across 344 incidents. While methodologies differ across security firms, the broader trend is clear: attackers continue to probe digital-asset companies for weaknesses in access control, signing systems, token handling and vendor integrations. For institutional clients, the Haruko case may sharpen attention on how third-party technology providers store secrets, protect memory, segment client access and communicate after a breach.
What Institutional Clients May Do Next
Institutional clients affected by the attack are likely to focus on containment and verification. Common responses after this type of incident can include rotating API keys, reviewing exchange permissions, checking whether IP whitelisting is enabled, investigating account activity, and comparing trading records against expected behavior. Funds may also review whether read-only keys were properly separated from keys with trading or withdrawal permissions.
Some chart watchers and market participants may treat the event as another reminder that crypto market structure is not only about price discovery, liquidity and execution quality. It is also about operational resilience. The ability to trade across venues has value, but each integration can expand the attack surface unless access is tightly managed and monitored. For funds using external technology providers, vendor due diligence remains an ongoing process rather than a one-time onboarding step.
For Haruko, the immediate focus will be on remediation, client communication and the promised technical post-mortem. The company says it serves more than 80 clients globally and connects with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols. That scale gives the platform an important role in institutional crypto operations, and it also means confidence in its controls is central to client trust.
Frequently Asked Questions (FAQs)
What happened to Haruko?
Haruko was hit by a targeted cyberattack that affected 15 clients. The incident exposed read-only exchange API details and trading data, and some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds.
What kind of company is Haruko?
Haruko is a London-based crypto technology provider that offers portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance protocols.
Were client login credentials compromised?
Client login credentials on client systems were not compromised, based on messages shared with clients. The attacker instead exploited a vulnerability in Haruko’s infrastructure, extracted a user-access token and used it to capture data held in process memory.
What are read-only exchange API details?
Read-only exchange API details generally allow systems to view information such as balances, positions or trading records without granting permission to move funds or execute transactions. Even so, this information can be sensitive for institutional traders and hedge funds.
Did clients lose funds in the Haruko attack?
Some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds. The available information does not specify a total amount of stolen assets.
How did Haruko respond to the breach?
Haruko said it fixed the vulnerability and refreshed its server-side secrets. The company also told clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide maximum protection.
What is an IP whitelist?
An IP whitelist is a security control that allows access only from approved internet addresses. In crypto operations, it can help reduce the risk that unauthorized systems interact with sensitive APIs or infrastructure.
Why are crypto infrastructure attacks so serious?
Crypto infrastructure attacks can be serious because platforms often rely on digital credentials, access tokens and signing systems. Since crypto transactions are generally irreversible, successful compromises can lead to losses that are difficult to recover.
How does this incident fit into the broader crypto security landscape?
The incident comes as crypto attacks are increasing. TRM Labs cited a record 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier, with $972 million in losses. CertiK estimated first-half losses at $1.32 billion across 344 incidents.
