Haruko Cyberattack Exposes API Data for 15 Clients, Some Funds Lost

2 hour ago 2 sources negative

Key takeaways:

  • Haruko breach exposes middleware as a critical weak point in institutional crypto trading infrastructure.
  • Institutional crypto security gaps may slow institutional BTC/ETH allocations, making IP whitelisting a due-diligence priority.
  • Watch for regulatory scrutiny on API security standards as 2026 infrastructure losses mount.

London-based institutional crypto technology provider Haruko suffered a targeted cyberattack affecting 15 clients, exposing read-only exchange API details and trading data, with some smaller hedge-fund clients reporting small undisclosed losses, according to CoinDesk, The Crypto Times and people familiar with the incident.

Haruko said on Sept. 18 that it had fixed the exploited vulnerability and rotated server-side secrets. The company plans to publish a technical post-mortem. In messages to clients, co-founder and CTO Adam Carlile said attackers extracted a user-access token by exploiting a vulnerability in one of Haruko's processes, then used it to capture information held in process memory. Client login credentials were not compromised on customers' own systems. "This was a targeted attack by a group on us," Carlile told clients. "It was 15 clients impacted."

The 15 affected customers had not configured IP whitelisting, according to company messages. Haruko told customers that configuring an inbound IP whitelist would provide maximum protection. GSR said it was not affected, and 3iQ Digital Assets said its funds remained secure and cited IP whitelisting as preventing API access exposure.

The platform sits between institutional trading firms and exchanges, consolidating positions, transactions and risk information. Haruko says it serves more than 80 clients globally and integrates with more than 100 centralized trading venues, over 30 blockchains and 250 onchain protocols. The breach fits a wider 2026 pattern: CertiK's H1 2026 dataset estimated losses of about $1.32 billion across 344 security incidents, with infrastructure, credential and supply-chain attacks becoming more prominent alongside smart-contract vulnerabilities.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.