According to three individuals with knowledge of the incident, a targeted cyberattack on crypto tech provider Haruko exposed API details and trading data for 15 clients, and some smaller hedge funds with weaker security controls may have lost a small amount of funds.
This week brought a breach, and Haruko’s setup played a part in it. The company relies on bare-metal servers — physical machines devoted solely to its own use — instead of cloud services such as Amazon Web Services, which come with extra security controls, according to one person. The vulnerability in question sat inside one of Haruko’s processes, and that weakness is what made the attack possible.
What Was Stolen
The breach exposed clients’ read-only exchange API details and trading data. APIs allow clients’ and Haruko’s computers to communicate and exchange information. A whitelist allows communication only with approved computers or websites, and the affected parties were all of Haruko’s non-whitelisted clients, according to messages from the company’s co-founder and chief technology officer, Adam Carlile, to a client and seen by CoinDesk.
Clients’ login credentials were not compromised on their own systems. Instead, an access token was extracted through a vulnerability in Haruko’s infrastructure. The attacker exploited that token to capture data held in the process’s memory, which could have included API details and other data.
“This was a targeted attack by a group on us,” the CTO said in the messages, describing Haruko itself as the target rather than any particular customer. “It was 15 clients impacted.”
Who Was Hit
Repeated requests for comment went unanswered from Haruko. Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC Group (now operating as Monarq Asset Management) and Trovio Asset Management appear as clients on its website. None of those firms replied to requests for comment prior to publication time.
GSR and 3iQ Digital Assets confirmed separately that they were not affected. GSR said it had not been impacted by any rumored breach. 3iQ said its funds remained fully secure, with API access restricted through IP whitelisting, preventing exposure to the compromised environment.
The speakers insisted on remaining unnamed since the issue involves personal matters. The individuals suggested that smaller hedge funds, which often have less robust security measures in place, were especially at risk.
Aftermath
The company claimed it had addressed the flaw and replaced its server-side secrets. Haruko reported that configuring an inbound IP whitelist restricting access to specified internet addresses would offer “maximum protection.” It has also announced that a full technical post-mortem will be published.
According to the website, the firm works with more than 80 customers worldwide and links up with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols. Its services include portfolio, risk-management and trade-data infrastructure for institutional digital-asset firms.
A security gap has emerged at a time when crypto companies are facing a rising number of attacks. According to TRM Labs, hackers executed a record 207 attacks in the opening half of 2026, which is more than double the 83 noted a year before. These incidents led to losses of $972 million.
TRM said infrastructure and operational compromises made up roughly 76% of the funds taken even though they were involved in just 15% of the incidents. Using a wider definition, security firm CertiK estimated that losses for the first half came to $1.32 billion across 344 incidents.
KEY FACTS
– 15 clients affected
– API details and trading data exposed
– Small amount of client funds stolen, per sources
– Vulnerability exploited via access token extraction
– Haruko uses bare-metal servers instead of cloud services
– 207 attacks in H1 2026, up from 83 in H1 2025
– $972 million in losses per TRM Labs
– $1.32 billion in losses per CertiK
Source material: “Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost,” CoinDesk.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

