Cryptography technology provider Haruko was attacked, affecting 15 clients, with a small amount of funds stolen
According to CoinDesk, the crypto technology provider Haruko was targeted in a cyber attack earlier this week, affecting 15 clients. The attack exposed clients' read-only exchange API details and trading data. According to insiders, some hedge fund clients with weaker security protections may have had a small amount of funds stolen.
Adam Carlile, co-founder and Chief Technology Officer of Haruko, stated in an email sent to clients that this was a targeted attack initiated by an organization, and the affected clients were all non-whitelisted clients. The attackers exploited a vulnerability in one of Haruko's processes to extract user access tokens, thereby obtaining data such as read-only exchange API information stored in process memory; clients' login credentials were not compromised. Haruko has fixed the vulnerability and refreshed the server-side keys, and plans to release a complete technical review report.
Based in London, Haruko provides portfolio, risk management, and trading data infrastructure for institutional digital asset companies. The platform connects centralized exchanges, custodians, blockchains, and DeFi protocols, currently serving over 80 clients globally and integrating with more than 100 centralized trading platforms, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, among others, with GSR stating that it was not affected by this incident.






