LIVEBTC $84,387 ↗ +5.03%ETH $2,713 ↗ +5.32%SOL $115.76 ↗ +7.06%XRP $1.49 ↗ +8.03%BNB $784.36 ↗ +4.50%HYPE $95.22 ↗ +4.76%ZEC $1,515 ↗ +5.28%STRK $0.05 ↗ +2.98%BTC $84,387 ↗ +5.03%ETH $2,713 ↗ +5.32%SOL $115.76 ↗ +7.06%XRP $1.49 ↗ +8.03%
Monday, September 21, 202610:33 UTC
Finance3 days ago

Haruko cyberattack exposed 15 institutional clients, with some funds lost

The crypto infrastructure provider said a targeted attacker pulled a user-access token from its server memory, capturing read-only exchange API credentials and trading data.

Illustration · generated, not a photograph

Why it mattersThe attack comes in a hostile year for crypto, with TRM Labs recording 207 attacks on crypto companies in the first half of 2026, causing $972 million in losses.

Haruko, a London-based provider of portfolio, risk-management and trade-data infrastructure for institutional digital-asset firms, was hit by a targeted cyberattack this week that affected 15 of its clients, according to three people briefed on the matter and messages sent by the company's chief technology officer to customers.

The attacker exploited a vulnerability in one of Haruko's internal processes, extracting a user-access token and using it to capture data held in that process's memory, CTO Adam Carlile told clients in messages seen by CoinDesk. That memory could have contained read-only exchange API keys — credentials that let a client's systems connect to a trading venue — as well as trading data. Client login credentials on their own systems were not compromised; the access came through Haruko's infrastructure instead.

A small amount of client funds was stolen, the people said, speaking anonymously because the matter is private. Smaller hedge funds with weaker security controls were thought to be particularly exposed. The affected parties were all of Haruko's clients that had not configured IP whitelisting — a setting that restricts communication to approved internet addresses.

The attack succeeded, per one of the people, partly because Haruko runs its own bare-metal servers — physical machines used exclusively by the firm — rather than cloud services such as Amazon Web Services, which carry additional built-in security controls.

Carlile said the company itself, rather than any individual customer, was the target. "This was a targeted attack by a group on us," he wrote. "It was 15 clients impacted." Haruko has since patched the vulnerability and rotated its server-side secrets, and plans to publish a full technical post-mortem. It has advised clients that configuring an inbound IP whitelist offers "maximum protection."

> [SUBHEAD: Who was affected]

Haruko does not publish a full client roster, but its website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management among its customers. The firm says it serves more than 80 clients in total, connecting to over 100 centralized trading venues, 30 blockchains and 250 onchain protocols.

Several named clients said they were unscathed. "GSR has not been impacted by any rumored breach," a spokesperson said. "3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment," a representative said in emailed comments. Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio did not respond to requests for comment.

The incident lands in a hostile year for the industry. TRM Labs recorded 207 attacks on crypto companies in the first half of 2026, more than double the 83 in the same period a year earlier, with $972 million in losses. Infrastructure and operational compromises accounted for roughly 76% of the money stolen despite representing just 15% of incidents, TRM said. CertiK, using a broader definition, put first-half losses at $1.32 billion across 344 incidents.

Crypto platforms remain attractive targets in part because transactions are generally irreversible and access often depends on digital credentials that, once stolen, can give attackers a direct route to assets.

What happens nextHaruko plans to publish a full technical post-mortem and has advised clients to configure an inbound IP whitelist for maximum protection.

Source reporting

The outlets whose reporting this account was written from.

Written from the reporting and primary documents credited at the foot of this story. Facts are credited to the outlet or document that established them. How Chainpress works

Emailhttps://www.chainpress.co/article/haruko-cyberattack-exposed-15-institutional-clients-with-some-fu-cp
Report a correction →
Harukocybersecurityhacksinstitutional crypto

Related coverage

View all →