A Haruko cyberattack has put a piece of crypto’s institutional plumbing under scrutiny after the technology provider was targeted earlier this week. The incident affected 15 clients and exposed read-only exchange API details and trading data, according to people familiar with the matter and messages reviewed by CoinDesk.
A small amount of client funds was also stolen, the people said, with smaller hedge funds potentially more exposed because of weaker security controls. They spoke anonymously because the incident remains private.
London-based Haruko provides infrastructure for digital-asset firms, connecting their systems to centralized exchanges, custodians, blockchains and decentralized-finance protocols. Its software gives institutional clients a consolidated view of positions, transactions and risk.
That connectivity is useful precisely because it sits in the middle of so many systems. It also means a vulnerability inside the provider can create consequences beyond a single company’s own network.
What the Haruko cyberattack exposed
The affected customers were all Haruko clients that had not been whitelisted, according to messages from co-founder and chief technology officer Adam Carlile. IP whitelisting restricts access to approved internet addresses, creating another barrier between an external system and sensitive infrastructure.
Carlile told clients that an attacker exploited a vulnerability in one of Haruko’s processes, extracted a user access token and used it to capture information stored in the process’s memory.
That information could have included read-only exchange API credentials and other data. Client login credentials on their own systems, however, were not compromised, according to messages sent by the company.
“This was a targeted attack by a group on us,” Carlile wrote, describing Haruko itself as the target. “It was 15 clients impacted.”
Haruko said it has since patched the vulnerability and refreshed its server-side secrets. The company also advised customers to configure inbound IP whitelisting for what it described as “maximum protection” and said it plans to release a full technical post-mortem.
The company did not respond to repeated requests for comment.
Why the infrastructure matters
One person familiar with the incident attributed the exposure to Haruko’s use of bare-metal servers — physical machines dedicated to the company — rather than cloud platforms such as Amazon Web Services, which offer additional security controls.
Haruko says it serves more than 80 clients worldwide and connects to more than 100 centralized trading venues, 30 blockchains and 250 onchain protocols.
Its publicly named customers include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group, now operating as Monarq Asset Management, and Trovio Asset Management.
Not all of those firms were affected. GSR said it had not been impacted by the reported breach, while 3iQ said it was unaffected and that its funds remained secure because its API access is restricted through IP whitelisting.
Other named clients did not respond to requests for comment before publication.
The Haruko cyberattack lands in a bigger security problem
The incident arrives as attacks targeting crypto companies continue to rise. TRM Labs recorded 207 attacks during the first half of 2026, more than twice the 83 incidents reported during the same period a year earlier.
Those attacks produced $972 million in losses, according to the security firm. Infrastructure and operational compromises accounted for roughly 76% of the money stolen while representing only 15% of the incidents.
CertiK, using a broader definition of crypto security incidents, estimated first-half losses at $1.32 billion across 344 events.
Crypto has always had an uncomfortable relationship with stolen credentials. Transactions are generally irreversible, while digital assets can be controlled through credentials and signing systems that may give an attacker a direct path to funds.
The Haruko case adds another layer to that problem: sometimes the point of entry is not an exchange or a wallet, but the infrastructure connecting institutions to both.
