Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost

Some smaller hedge funds with weaker security controls may have lost funds in the targeted attack, sources said.

  • A targeted cyberattack on Haruko affected 15 clients, exposing read-only exchange API details and trading data.
  • Some smaller hedge-fund clients with weaker security controls may have lost a small amount of funds, sources said.
  • Haruko said it fixed the vulnerability and refreshed its server-side secrets.

Some of Haruko’s smaller hedge-fund clients may have lost assets after the provider of crypto technology to institutions was targeted in a cyberattack earlier this week that affected 15 customers, according to three people with knowledge of the matter.

The breach exposed clients’ read-only exchange application programming interface (API) details and trading data, according to messages reviewed by CoinDesk and people familiar with the incident. APIs allow clients’ and Haruko’s computers to communicate and exchange information.

The affected parties were all of Haruko’s non-whitelisted clients, according to messages from the company’s co-founder and chief technology officer, Adam Carlile, to a client and seen by CoinDesk. A whitelist allows communication only with approved computers or websites.

Haruko did not respond to repeated requests for comment.

The breach was possible because Haruko uses bare-metal servers, or physical computers used exclusively by itself, rather than cloud services such as Amazon Web Services, which offer additional security controls, according to one of the people.

Haruko does not disclose its full customer roster, though its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now operating as Monarq Asset Management) and Trovio Asset Management as clients.

The London-based firm provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of their positions, transactions and risk exposure.

“GSR has not been impacted by any rumored breach,” a company spokesperson said.

“3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment,” a representative for the firm said in emailed comments.

Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication time.

A small amount of client funds was stolen, the people said, who spoke on condition of anonymity because the matter is private. Smaller hedge funds with weaker security controls may have been particularly exposed, the people said. Trading data was also taken.

Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory, Carlile told clients. That memory could have included read-only exchange API details and other data.

Clients’ login credentials were not compromised on their own systems, according to the messages. Instead, the access token was extracted through a vulnerability in Haruko’s infrastructure.

“This was a targeted attack by a group on us,” the CTO said in the messages, describing Haruko itself, rather than any particular customer, as the target. “It was 15 clients impacted.”

Haruko said it had fixed the vulnerability and refreshed its server-side secrets. The company told clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide “maximum protection.” It also plans to publish a full technical post-mortem.

The company says it serves more than 80 clients globally and connects with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols, according to the website.

The breach comes as attacks on crypto companies are increasing in frequency. Hackers carried out a record 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier, according to TRM Labs. The incidents resulted in $972 million in losses.

Infrastructure and operational compromises accounted for about 76% of the money stolen despite representing only 15% of incidents, TRM said. Security firm CertiK, which uses a broader definition, estimated first-half losses at $1.32 billion across 344 incidents.

UPDATE (Sept. 18 18.42 UTC): Updates story with 3iQ comments.

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.