How Did the Haruko Attack Reach Client Data?
Institutional crypto technology provider Haruko was targeted in a cyberattack that affected 15 clients, exposing read-only exchange API details and trading information while reportedly leading to a small amount of client funds being stolen.
The London-based company provides portfolio management, risk monitoring and trade-data infrastructure to digital-asset firms, connecting institutional customers with centralized exchanges, custodians, blockchains and decentralized-finance protocols.
Attackers exploited a vulnerability in one of Haruko’s processes and extracted a user-access token, according to messages from co-founder and chief technology officer Adam Carlile. The token was then used to capture information held in the process’s memory, which could include read-only exchange API details and other trading data.
Client login credentials were not compromised on customers’ own systems. Instead, the attacker gained access through Haruko’s infrastructure.
“This was a targeted attack by a group on us,” Carlile told clients. “It was 15 clients impacted.”
Haruko said it has patched the vulnerability and refreshed its server-side secrets. The company also plans to publish a technical post-mortem explaining the incident in more detail.
Why Did Whitelisting Matter?
One of the clearest distinctions between affected and unaffected customers appears to have been whitelisting. The 15 affected customers were Haruko clients that had not configured whitelisting, according to messages sent by the company.
IP whitelisting restricts API access to specified internet addresses, reducing the ability of stolen credentials or tokens to be used from an unauthorized system. Haruko told customers after the attack that configuring an inbound IP whitelist would provide “maximum protection.”
GSR said it was not affected by the incident. 3iQ Digital Assets also said its funds remained secure and specifically cited IP whitelisting as preventing its API access from being exposed to the compromised environment.
That distinction makes the breach particularly relevant for smaller hedge funds and trading firms that depend on third-party infrastructure but may not maintain the same security controls as larger institutions. A read-only API key normally cannot directly authorize withdrawals, but exposed trading data, account information and interconnected infrastructure can still create additional attack surfaces.
Investor Takeaway
The Haruko incident shows that institutional crypto risk does not end with exchanges and private keys. Trading firms increasingly depend on third-party systems that aggregate positions and connect multiple venues, meaning one infrastructure compromise can expose several clients at the same time. The apparent protection provided by IP whitelisting also shows how basic access controls can materially change the outcome of the same breach.
Why Is Haruko an Important Part of Institutional Crypto Infrastructure?
Haruko says it serves more than 80 clients globally and integrates with more than 100 centralized trading venues, over 30 blockchains and 250 onchain protocols. Its website lists clients including Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan and Trovio Asset Management.
The platform effectively sits between institutional trading firms and many of the exchanges and protocols they use, consolidating positions, transactions and risk information into a single system.
That makes infrastructure providers attractive targets even when they do not directly custody customer assets. An attacker who compromises one service provider may gain information about multiple funds, their exchange relationships and potentially their trading activity.
The attack fits a pattern already visible across major crypto exploits in 2026, where compromised infrastructure, credentials and operational systems have become increasingly important attack vectors alongside traditional smart-contract vulnerabilities.
Are Crypto Attackers Moving Toward Infrastructure?
The Haruko breach arrives during an unusually active year for crypto security incidents. More than 200 attacks were recorded during the first half of 2026, with losses approaching $1 billion under some industry estimates.
CertiK’s broader H1 2026 dataset estimated losses of approximately $1.32 billion across 344 security incidents. Wallet compromise alone accounted for hundreds of millions of dollars in losses, while other attacks increasingly targeted systems surrounding blockchain applications rather than vulnerabilities in smart contracts themselves.
Security researchers had already warned that supply-chain, phishing and infrastructure attacks were becoming a larger part of the crypto threat model as institutional adoption increased.
Haruko’s promised post-mortem will therefore matter beyond its own customers. The key questions are how the access token was extracted, exactly what information was available in process memory, whether stolen read-only credentials were used in subsequent attacks and why reported fund losses occurred despite the exposed APIs being described as read-only.
For institutional crypto firms, the incident turns API security, token handling and mandatory whitelisting from technical configuration choices into counterparty-risk questions.
