Haruko Hack Exposes 15 Crypto Clients, Drains Funds via API Breach

Share

London-based digital asset infrastructure provider Haruko was hit by a targeted cyberattack that compromised read-only exchange API details and trading data belonging to 15 institutional clients, according to three sources familiar with the matter. Beyond the individual alert, the incident exposes a structural blind spot in the crypto industry: the concentration of risk on third-party technology providers.

🔑 Key Takeaways

  • 15 institutional crypto clients affected by a targeted attack on Haruko
  • An access token was extracted through a vulnerability in an internal platform process
  • A small amount of client funds was stolen, mainly at smaller hedge funds with weaker security controls
  • The use of bare-metal servers — without the added protections of cloud infrastructure — has been flagged as a contributing factor
  • Haruko has promised a full technical post-mortem and is recommending IP allowlists for all clients

Origin of the breach: an access token exfiltrated from memory

According to internal communications reviewed by CoinDesk, the attack did not target a specific client but Haruko itself, which was singled out by an organized threat group. Adam Carlile, co-founder and CTO of the firm, confirmed this directly to customers in a written message.

The breach mechanism relied on exploiting a vulnerability in one of Haruko’s internal processes. The attacker managed to extract a user access token — a technical credential used to authenticate requests — and then used it to capture data held in the process memory during execution. That memory could contain read-only exchange API credentials and other sensitive information.

« This was a targeted attack by a group against us. Fifteen clients were impacted. »

Adam Carlile, Co-founder and CTO of Haruko

An important clarification: customer login credentials were not compromised on their own systems, according to the internal messages. The flaw lies entirely within Haruko’s infrastructure, distinguishing this incident from a classic wallet or account compromise.

Scope of the attack: 15 clients, with smaller hedge funds hardest hit

All clients not included in Haruko’s allowlist were affected, as clarified by the CTO. An allowlist is a filtering mechanism that only permits communications with pre-approved IP addresses or services. This configuration, which could have blocked the exfiltration, was clearly absent at multiple clients.

Smaller hedge funds with less robust security controls were particularly exposed. A small amount of client funds was stolen, the sources said. Notable customers include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management.

Haruko clientReported status
GSRNot impacted
3iQ Digital AssetsNot affected (IP allowlist active)
Bitcoin SuisseNo response before publication
FlowdeskNo response before publication
M2No response before publication
AmpersanNo response before publication
MNNC / MonarqNo response before publication
TrovioNo response before publication

3iQ’s case is telling: the asset manager notes its funds remain fully secure precisely because it had restricted API access via IP allowlisting, a measure Haruko is now recommending across its entire client base.

Infrastructure choices: the risky bet on bare metal

According to one of the sources, Haruko runs on bare-metal servers — dedicated physical machines operated exclusively by the company — rather than cloud services such as Amazon Web Services, which provide additional security controls (encryption at rest, granular IAM, native auditing, network segmentation). This architectural choice, sometimes motivated by performance or cost considerations, removes several standard protection layers.

Haruko has stated that it has patched the vulnerability and rotated its server-side secrets (cryptographic keys and tokens). The company has advised clients to configure an inbound IP allowlist restricting access to specified internet addresses, which would provide « maximum protection ». A full technical post-mortem is planned.

A broader context of accelerating crypto hacks

The incident fits into a strong sector trend. According to TRM Labs data, hackers carried out 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier. These incidents resulted in $972 million in losses. The share of infrastructure compromises is particularly striking: they account for roughly 76% of stolen funds while representing only 15% of incidents.

H1 2026 indicatorValueSource
Number of attacks207TRM Labs
Total losses (strict definition)$972MTRM Labs
Total losses (broad definition)$1.32BCertiK
H1 2025 incidents83TRM Labs
Share of infrastructure incidents15%TRM Labs
Share of funds stolen via infrastructure76%TRM Labs
Incidents (CertiK definition)344CertiK

Security firm CertiK, which uses a broader definition that includes rug pulls and flash loan attacks, puts H1 losses at $1.32 billion across 344 incidents. Regardless of methodology, the message is identical: attacks are less frequent in terms of infrastructure incidents but far more devastating in absolute value.

Hacks remain a persistent problem for the crypto industry because blockchain transactions are generally irreversible and platforms rely on digital credentials and signature systems that can give attackers direct access to assets, with no recourse.


Conclusion: the concentration risk on third-party providers

Founded in March 2021, Haruko provides wallet, risk management and trading data infrastructure to more than 80 clients globally. Its platform connects to over 100 centralized trading venues, 30 blockchains and 250 on-chain protocols. The company has raised roughly $16 million in total funding, including a $6 million Series A in July 2024 co-led by White Star Capital and MMC Ventures.

The incident is a reminder that an infrastructure provider becomes a single point of failure for all of its clients. As institutional players outsource API management and market data to third parties, security due diligence on those providers — independent audits, penetration testing, network segmentation, systematic allowlisting — becomes as critical as the security of the wallets themselves. European MiCA regulators and US supervisors are now scrutinizing these architectures closely, where the compromise of a single intermediary can cascade across dozens of regulated funds.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles