Haruko cyberattack hits 15 crypto clients, exposing exchange API data

Haruko cyberattack hits 15 crypto clients, exposing exchange API data

Haruko cyberattack hits 15 institutional clients

Crypto technology provider Haruko was targeted in a cyberattack earlier this week that affected 15 of its clients, exposing their read-only exchange API details and trading data, according to three people with knowledge of the matter and company messages reviewed by CoinDesk. APIs are connections that let computers talk to each other and share information.

Some of the firm's smaller hedge-fund clients may have lost a small amount of funds in the attack, the people said, speaking anonymously because the matter is private. London-based Haruko builds portfolio, risk-management and trade-data systems for institutional digital-asset firms.

Haruko did not respond to repeated requests for comment.

Key facts about the breach

  • Fifteen clients were affected, and they were all of Haruko's non-whitelisted clients, according to messages from co-founder and chief technology officer Adam Carlile to a client. A whitelist is a setting that allows communication only with approved computers or websites.
  • The attacker exploited a vulnerability in one of Haruko's processes, extracted a user-access token, and used it to capture data held in that process's memory, Carlile told clients.
  • A small amount of client funds was stolen and trading data was taken, the people said.
  • Haruko said it fixed the vulnerability and refreshed its server-side secrets.
  • Clients' login credentials were not compromised on their own systems, the messages said.

What the company's messages say

Carlile told clients the attacker used the stolen token to reach data stored in the process's memory, which could have included read-only exchange API details and other data. He said clients' own login details were not taken from their systems.

The breach was possible because Haruko uses bare-metal servers, which are physical computers used exclusively by the company, rather than cloud services such as Amazon Web Services that offer additional security controls, according to one of the people. This explanation is a claim from a single source and has not been confirmed by Haruko.

According to the summary of the messages, Haruko said it patched the vulnerability and refreshed its server-side secrets, which are sensitive keys used to protect access.

How clients responded

Haruko does not publish its full customer list, though its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now operating as Monarq Asset Management) and Trovio Asset Management as clients.

"GSR has not been impacted by any rumored breach," a GSR spokesperson said.

"3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment," a 3iQ representative said in emailed comments.

Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication.

What is confirmed

The details of the attack come from three people with knowledge of the incident and from internal Haruko messages seen by CoinDesk. Haruko itself has not publicly confirmed the breach and did not reply to requests for comment.

On the record, GSR and 3iQ both stated they were not affected. The other named clients neither confirmed nor denied involvement before publication.

What is still unclear

The exact amount of stolen funds is not stated, and the sources described it only as "small." Which specific clients lost money, and how much, also remains unclear.

Whether any stolen funds can be recovered is not addressed in the source material. The full explanation of how the access token was extracted is also incomplete in the supplied report, which cuts off mid-sentence.

Why this matters

Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

Haruko's role as an infrastructure provider means a single breach at the company reached 15 clients at once, rather than just one firm.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!