London-based digital asset technology provider Haruko suffered a targeted cyberattack that affected 15 institutional clients. Attackers exploited a vulnerability in Haruko's processes to extract an access token, exposing read-only exchange API credentials and trading data. Sources report that a small, undisclosed amount of funds was stolen, particularly affecting smaller hedge-fund clients with weaker security controls. Haruko has since fixed the vulnerability and rotated its server-side secrets.
Haruko access token exploit
- ▪A targeted cyberattack on London-based digital asset technology provider Haruko affected 15 clients, exposing exchange API details and trading data.
- ▪A source stated that the cyberattack on Haruko reported in September 2026 was possible because Haruko uses bare-metal physical servers rather than cloud services like Amazon Web Services
- ▪Attackers exploited a vulnerability in one of Haruko's processes to extract a user-access token and capture data held in the process's memory.
Exposed API credentials
- ▪The cyberattack on Haruko reported in September 2026 exposed read-only exchange API credentials and trading data belonging to the 15 Haruko clients affected by that cyberattack
- ▪The affected parties in the cyberattack on Haruko reported in September 2026 were all of Haruko's non-whitelisted clients, according to messages from co-founder Adam Carlile
Client fund theft
- ▪Sources indicated that some of Haruko's smaller hedge-fund clients with weaker security controls may have lost assets in the cyberattack on Haruko reported in September 2026
- ▪People familiar with the matter stated that a small, undisclosed amount of client funds was stolen during the Haruko cyberattack.
Haruko security remediation
- ▪Haruko told clients that it plans to publish a technical post-mortem covering the cyberattack on Haruko reported in September 2026, its response, and the scope of data exposure
- ▪Haruko fixed the vulnerability exploited in the cyberattack on Haruko reported in September 2026, rotated its server-side secrets, and advised affected customers to enable inbound IP whitelisting
Affected institutional clients
- ▪A representative for 3iQ Digital Assets stated that 3iQ was not affected by the Haruko breach and its API access is restricted through IP whitelisting.
- ▪A GSR spokesperson stated that GSR has not been impacted by any rumored breach at Haruko reported in September 2026
- ▪Haruko's website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group, and Trovio Asset Management as customers.
Crypto industry security trends
- ▪CertiK estimated first-half 2026 crypto losses at approximately $1.32 billion across 344 security incidents.
- ▪TRM Labs reported 207 crypto attacks in the first half of 2026, resulting in approximately $972 million in losses.
Story comments
Loading comments…