Haruko, a London-based provider of portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms, was hit by a targeted cyberattack this week that affected 15 clients, exposed their read-only exchange API details and trading data — and, according to people familiar with the matter, led to a small amount of stolen client funds.
The details come primarily from CoinDesk's reporting, which reviewed messages from co-founder and CTO Adam Carlile to a client, corroborated by Grafa and Crypto Briefing. Haruko did not respond to repeated requests for comment; no attribution for the attack has been publicly reported.
What the Attacker Reached
According to the CTO's messages, the attacker exploited a vulnerability in one of Haruko's processes, extracted a user-access token, and used it to capture data held in that process's memory — which could have included clients' read-only exchange API details and trading data. Clients' own login credentials were not compromised on their systems, the company told clients.
The affected parties were all of Haruko's non-whitelisted clients — 15 in total. A whitelist restricts communication to approved internet addresses, and the affected customers lacked that protection. One person familiar with the incident tied the exposure to Haruko's use of bare-metal servers — physical machines the firm operates exclusively — rather than cloud services that layer additional security controls on top.
A small amount of client funds was stolen, three people with knowledge of the matter said, speaking anonymously because the matter is private. Smaller hedge funds with weaker security controls may have been particularly exposed, they said.
The Response
Carlile described the incident to clients as targeted at Haruko itself rather than any single customer: "This was a targeted attack by a group on us. It was 15 clients impacted." The company says it has fixed the vulnerability and refreshed its server-side secrets, told clients that configuring an inbound IP whitelist would provide "maximum protection," and plans to publish a full technical post-mortem.
The client list is relevant context: Haruko does not disclose its full roster, but its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management as clients. GSR said it was not impacted; 3iQ said its funds remain secure and that its API access is restricted through IP whitelisting. The others did not reply to requests for comment before publication.
Why a Vendor Breach Multiplies
Haruko's platform connects with over 100 centralized trading venues, 30 blockchains and 250 on-chain protocols across more than 80 clients, per its website. That consolidation is precisely what made the incident's blast radius what it was: one compromised process on the vendor side surfaced API material belonging to every client that had not locked access down to approved addresses.
The incident fits the pattern quantified in TRM Labs' first-half 2026 data: of 207 recorded crypto attacks — a record semi-annual count — infrastructure and operational compromises accounted for about 76% of the money stolen despite representing only 15% of incidents. The cheapest defense in this case was also the oldest: allow-list who can use a credential, not just who holds it.
Read-only API keys limit direct withdrawal risk, but trading data and account visibility carry their own exposure — from front-running insight to targeted phishing of the firms whose connectivity was visible in the compromised process.
TrustGrade tracks the security posture of infrastructure providers, protocols and exchanges. Verified trust data: trustgrade.ai.