Haruko, a London-based technology provider that connects hedge funds and other institutional traders to crypto exchanges and blockchains, was hit by a cyberattack this week that exposed read-only exchange API details and trading data for 15 of its clients. Some smaller hedge-fund clients reportedly lost a small amount of funds, according to the company’s CTO and co-founder, Adam Carlile. The incident matters because it strikes at infrastructure sitting behind dozens of institutional trading desks rather than at a single exchange or wallet, illustrating how attackers are increasingly targeting the plumbing of the crypto market rather than its front doors.
Haruko describes itself as a portfolio, risk-management and trade-data infrastructure provider serving more than 80 clients globally. Its systems connect to over 100 centralized trading venues, 30 blockchains and 250 onchain protocols, giving institutional clients a single point of access to a fragmented market. That kind of aggregation is exactly what makes such providers attractive both to institutions seeking efficiency and to attackers seeking maximum leverage from a single intrusion.
How the breach happened
According to Carlile, the attacker did not compromise client login credentials directly. Instead, they exploited a vulnerability in one of Haruko’s internal processes to extract a user-access token and read data from process memory. That token effectively let the intruder view read-only API details and trading data belonging to clients who had not enabled IP whitelisting, a security setting that restricts account access to pre-approved network addresses. Haruko says it has since patched the flaw and refreshed server-side secrets, and plans to publish a technical post-mortem detailing what went wrong.
Notably, the source reporting on the breach pointed to Haruko’s choice of infrastructure as a contributing factor: the firm runs on bare-metal servers rather than cloud platforms such as AWS. Bare-metal setups can offer performance and control advantages prized by trading firms, but they also place more of the security burden — patching, monitoring, memory protection — directly on the operator rather than on a cloud provider’s managed security layers.
Haruko’s client roster, as listed on its own website, includes names such as Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, Monarq Asset Management (formerly MNNC Group) and Trovio Asset Management. Two of those, GSR and 3iQ, said publicly they were not affected by the breach, with 3iQ specifically crediting its use of IP whitelisting for shielding it. Other named clients did not respond to requests for comment, leaving open questions about the full scope of exposure across Haruko’s client base.
What it means for institutional crypto security
The episode underscores a structural risk in how institutional crypto trading has matured. As hedge funds and asset managers have moved from manual, exchange-by-exchange trading toward consolidated infrastructure providers, they have also concentrated risk. A single vulnerability in a shared process can, in principle, expose data across many otherwise unrelated clients simultaneously — a dynamic very different from a hack of one exchange’s hot wallet.
The fact that whitelisting protected at least some clients (per 3iQ’s own account) suggests that basic configuration choices, not just the vendor’s core code, made a meaningful difference in outcomes here. That is a useful data point for institutions evaluating their own risk controls when they plug into third-party trading infrastructure, regardless of how reputable the provider is.
Industry data cited alongside the Haruko incident reinforces the broader pattern. TRM Labs recorded 207 attacks on crypto companies in the first half of 2026, up sharply from 83 in the same period a year earlier, with losses totaling $972 million. Strikingly, 76% of stolen funds came from infrastructure or operational compromises, even though such incidents made up only 15% of the total attack count — meaning attacks on backend systems, access controls and operational processes tend to be far more costly per incident than more common attack types. CertiK, using a broader definition of incidents, put total losses at $1.32 billion across 344 events in the same period. Separately, the sector has also seen North Korean hackers moving funds on the Hyperliquid platform, part of a wider wave of state-linked and criminal activity targeting crypto operations.
What to watch next
Several concrete developments will show how seriously the incident is being addressed. Haruko’s promised technical post-mortem should clarify exactly how the token was extracted from process memory and why non-whitelisted clients were more exposed. Affected hedge funds may disclose whether recovered or lost funds are made whole, and whether any regulatory bodies take interest given Haruko’s institutional client base. More broadly, expect institutional trading firms to scrutinize vendor security architecture — cloud versus bare-metal, whitelisting defaults, and token-handling practices — as a standard part of onboarding, rather than treating infrastructure providers as a black box. This unfolds against a backdrop where US regulators have been easing pathways for crypto market structure, from the CFTC’s stance on crypto wallets and broker registration to the SEC’s moves on onchain trading of US stocks, even as security incidents like this one remind institutions that regulatory clarity does not eliminate operational risk. It also comes as flows into products like Bitcoin ETFs show investors remain sensitive to headline risk across the sector.
Source: CoinDesk
This content is for informational purposes only and does not constitute financial or investment advice.




Create a free account to comment and earn rewards.
Create account Log in