Haruko cyberattack hits 15 clients, some funds stolen
Security

Haruko cyberattack hits 15 clients, some funds stolen

September 20, 20264 min read

Haruko, a London-based infrastructure provider for institutional crypto firms, suffered a targeted cyberattack that affected 15 clients. According to CoinDesk, the attackers obtained exchange API details and trading data. Three people familiar with the matter told the outlet that a small share of client funds was stolen.

What happened at Haruko

CoinDesk reported the attack on September 18, saying it took place earlier that same week. Haruko provides portfolio accounting, risk management and trade-data analytics to companies that work with digital assets. The platform connects to more than 100 centralized exchanges, 30 blockchains and 250 onchain DeFi protocols, which include decentralized exchanges. Clients see their positions, trades and risk exposure in one place.

Co-founder and chief technology officer Adam Carlile told one client that every customer without an IP whitelist was hit. That came to 15. In total, Haruko serves more than 80 clients worldwide. A whitelist allows connections only from pre-approved computers or websites. The company did not answer CoinDesk's repeated requests for comment.

A provider like this holds the access and data of many clients in one place. A single flaw in one Haruko process exposed 15 companies at once, and the attacker did not have to break into each of them separately.

How the attackers got the data

The attackers exploited a vulnerability in one of Haruko's processes. They pulled a user-access token out of it and used it to read data held in the process's memory. That memory could have included read-only exchange API keys and other details, Carlile told clients.

The 15 clients without an IP whitelist were hit, while the login credentials on their own systems were not touched.

Read-only keys cannot withdraw funds. They do show balances, open positions and trade history, which is sensitive strategy information for a fund. How exactly the money was stolen, the sources did not explain.

An IP whitelist works as a restriction on the exchange or service side: a key is valid only when the request comes from an approved address. If a token or key ends up in the wrong hands, it cannot be used from another address. Haruko clients without a whitelist did not have that barrier.

According to one of the sources, the breach was possible because Haruko runs on its own physical servers. These lack the extra security controls that cloud services such as Amazon Web Services offer. The company closed the vulnerability and refreshed its server-side secrets. It advised clients to set up an inbound IP whitelist, which it said would give "maximum protection".

"This was a targeted attack by a group on us."

- Adam Carlile, co-founder and chief technology officer of Haruko, from a message to a client

Carlile clarified that the target was Haruko itself, not any single client. The company also promised to publish a full technical post-mortem. For now, the account of events comes only from messages and the words of sources, since Haruko has not commented on the attack publicly.

What Haruko's clients are saying

The company does not disclose its full customer list. Its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management. Two of them have already denied being affected.

  • GSR said the rumors of a breach do not concern it.
  • 3iQ said its funds are secure and its API access is restricted by IP whitelisting, so the compromised environment did not reach it.
  • Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio had not replied to requests by publication time.

Who exactly lost money, the sources did not say. They noted that smaller hedge funds with weaker security controls were the most exposed. Trading data was taken along with the funds. Nobody has published the size of the losses. The three people spoke to CoinDesk on condition of anonymity because the matter is private. The outlet also reviewed Carlile's messages to a client.

The wider the network of connections, the more data flows through a single service. Providers of this type usually receive API access from clients so they can merge balances and trades from different exchanges into one report. That is exactly the kind of data that ended up in the memory of the compromised process.

A record year for attacks on the crypto market

The Haruko incident fits the broader trend. According to TRM Labs, hackers carried out a record 207 attacks in the first half of 2026, against 83 in the same period a year earlier. Losses reached $972 million. The number of attacks more than doubled in a year.

The most money does not come from the most frequent attacks. Compromises of infrastructure and operations accounted for about 76% of stolen funds, although they made up only 15% of incidents. The share of losses was roughly five times the share of incidents. CertiK uses a broader definition of an incident, so its total is higher: $1.32 billion in losses over the half-year across 344 cases.

Industry watchers point out that transactions are generally irreversible and that platforms rely on digital credentials and signing systems that give attackers direct access to assets. The Haruko attack belongs to exactly this infrastructure type: what was breached was not a blockchain or a smart contract, but a provider's system. The amount of stolen funds has still not been disclosed.

Comments

Your email address will not be published. Required fields are marked *

or verify by email