London-based digital asset infrastructure provider Haruko was hit by a targeted cyberattack that compromised read-only exchange API details and trading data belonging to 15 institutional clients, according to three sources familiar with the matter. Beyond the individual alert, the incident exposes a structural blind spot in the crypto industry: the concentration of risk on third-party technology providers.
🔑 Key Takeaways
- 15 institutional crypto clients affected by a targeted attack on Haruko
- An access token was extracted through a vulnerability in an internal platform process
- A small amount of client funds was stolen, mainly at smaller hedge funds with weaker security controls
- The use of bare-metal servers — without the added protections of cloud infrastructure — has been flagged as a contributing factor
- Haruko has promised a full technical post-mortem and is recommending IP allowlists for all clients
Origin of the breach: an access token exfiltrated from memory
According to internal communications reviewed by CoinDesk, the attack did not target a specific client but Haruko itself, which was singled out by an organized threat group. Adam Carlile, co-founder and CTO of the firm, confirmed this directly to customers in a written message.
The breach mechanism relied on exploiting a vulnerability in one of Haruko’s internal processes. The attacker managed to extract a user access token — a technical credential used to authenticate requests — and then used it to capture data held in the process memory during execution. That memory could contain read-only exchange API credentials and other sensitive information.
« This was a targeted attack by a group against us. Fifteen clients were impacted. »
Adam Carlile, Co-founder and CTO of Haruko
An important clarification: customer login credentials were not compromised on their own systems, according to the internal messages. The flaw lies entirely within Haruko’s infrastructure, distinguishing this incident from a classic wallet or account compromise.
Scope of the attack: 15 clients, with smaller hedge funds hardest hit
All clients not included in Haruko’s allowlist were affected, as clarified by the CTO. An allowlist is a filtering mechanism that only permits communications with pre-approved IP addresses or services. This configuration, which could have blocked the exfiltration, was clearly absent at multiple clients.
Smaller hedge funds with less robust security controls were particularly exposed. A small amount of client funds was stolen, the sources said. Notable customers include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management.
| Haruko client | Reported status |
|---|---|
| GSR | Not impacted |
| 3iQ Digital Assets | Not affected (IP allowlist active) |
| Bitcoin Suisse | No response before publication |
| Flowdesk | No response before publication |
| M2 | No response before publication |
| Ampersan | No response before publication |
| MNNC / Monarq | No response before publication |
| Trovio | No response before publication |

3iQ’s case is telling: the asset manager notes its funds remain fully secure precisely because it had restricted API access via IP allowlisting, a measure Haruko is now recommending across its entire client base.
Infrastructure choices: the risky bet on bare metal
According to one of the sources, Haruko runs on bare-metal servers — dedicated physical machines operated exclusively by the company — rather than cloud services such as Amazon Web Services, which provide additional security controls (encryption at rest, granular IAM, native auditing, network segmentation). This architectural choice, sometimes motivated by performance or cost considerations, removes several standard protection layers.
Haruko has stated that it has patched the vulnerability and rotated its server-side secrets (cryptographic keys and tokens). The company has advised clients to configure an inbound IP allowlist restricting access to specified internet addresses, which would provide « maximum protection ». A full technical post-mortem is planned.
A broader context of accelerating crypto hacks
The incident fits into a strong sector trend. According to TRM Labs data, hackers carried out 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier. These incidents resulted in $972 million in losses. The share of infrastructure compromises is particularly striking: they account for roughly 76% of stolen funds while representing only 15% of incidents.
| H1 2026 indicator | Value | Source |
|---|---|---|
| Number of attacks | 207 | TRM Labs |
| Total losses (strict definition) | $972M | TRM Labs |
| Total losses (broad definition) | $1.32B | CertiK |
| H1 2025 incidents | 83 | TRM Labs |
| Share of infrastructure incidents | 15% | TRM Labs |
| Share of funds stolen via infrastructure | 76% | TRM Labs |
| Incidents (CertiK definition) | 344 | CertiK |
Security firm CertiK, which uses a broader definition that includes rug pulls and flash loan attacks, puts H1 losses at $1.32 billion across 344 incidents. Regardless of methodology, the message is identical: attacks are less frequent in terms of infrastructure incidents but far more devastating in absolute value.
Hacks remain a persistent problem for the crypto industry because blockchain transactions are generally irreversible and platforms rely on digital credentials and signature systems that can give attackers direct access to assets, with no recourse.
Conclusion: the concentration risk on third-party providers
Founded in March 2021, Haruko provides wallet, risk management and trading data infrastructure to more than 80 clients globally. Its platform connects to over 100 centralized trading venues, 30 blockchains and 250 on-chain protocols. The company has raised roughly $16 million in total funding, including a $6 million Series A in July 2024 co-led by White Star Capital and MMC Ventures.
The incident is a reminder that an infrastructure provider becomes a single point of failure for all of its clients. As institutional players outsource API management and market data to third parties, security due diligence on those providers — independent audits, penetration testing, network segmentation, systematic allowlisting — becomes as critical as the security of the wallets themselves. European MiCA regulators and US supervisors are now scrutinizing these architectures closely, where the compromise of a single intermediary can cascade across dozens of regulated funds.
Sources
- CoinDesk — Crypto Tech Provider Haruko Hit by Cyberattack Affecting 15 Clients
- Ground News — Haruko hack hits 15 crypto clients
- CryptoNews — Haruko cyberattack coverage
- Crypto Briefing — Haruko Cyberattack: Client Data and Funds Lost
- Startup Fortune — A Hacked Read-Only API at Haruko
- The420 — Haruko cyberattack and crypto theft
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

