Haruko, a London-based provider of portfolio and risk-management infrastructure for institutional digital-asset firms, was hit by a targeted cyberattack affecting 15 of its clients, according to messages reviewed by CoinDesk.
The breach exposed clients' read-only exchange API details and trading data. A small amount of client funds was stolen, according to people with knowledge of the matter, with smaller hedge funds featuring weaker security controls potentially facing greater exposure.
The attacker exploited a vulnerability in one of Haruko's processes to extract a user-access token and capture data held in the process's memory, Haruko's co-founder and chief technology officer Adam Carlile told clients. The affected parties were all non-whitelisted clients, meaning those without restricted access controls.
Haruko uses bare-metal servers—physical computers used exclusively by the company—rather than cloud services such as Amazon Web Services, which offer additional security controls, according to one person familiar with the matter.
Response and Remediation
Haruko said it fixed the vulnerability and refreshed its server-side secrets. The company advised clients that configuring an inbound IP whitelist restricting access to specified internet addresses would provide maximum protection and plans to publish a full technical post-mortem.
The company serves more than 80 clients globally and connects with over 100 centralized trading venues, 30 blockchains and 250 onchain protocols, according to its website. Named clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group and Trovio Asset Management. GSR stated it was not impacted by the breach.
Broader Context
The incident reflects a growing security challenge in crypto. According to TRM Labs, hackers carried out 207 attacks in the first half of 2026, more than double the 83 recorded a year earlier, resulting in $972 million in losses. Infrastructure and operational compromises accounted for approximately 76% of stolen funds despite representing only 15% of incidents, TRM said.


