Haruko, a crypto infrastructure provider serving institutional clients, suffered a cyberattack earlier this week that exposed read-only exchange API details and trading data from 15 clients. A small amount of client funds was stolen.
Sources familiar with the matter indicate that smaller hedge funds with weaker security controls were hit. Adam Carlile, Haruko's co-founder and chief technology officer, informed a client that all affected parties were non-whitelisted clients—meaning they lacked the additional security layer a whitelist provides by restricting communication to approved computers or websites.
The attacker exploited a vulnerability in one of Haruko's internal processes to extract a user-access token. That token was then used to capture data held in the process's memory, including read-only exchange API details and other sensitive information. Client login credentials on their own systems were not compromised.
The breach was possible because Haruko uses bare-metal servers—physical computers exclusively controlled by the company—rather than cloud services like Amazon Web Services, which offer additional security controls built in.
Haruko provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects centralized exchanges, custodians, blockchains and decentralized-finance protocols, offering clients consolidated visibility into positions, transactions and risk exposure.
Haruko's website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management as clients.
A GSR spokesperson stated the firm was not impacted by the breach. A 3iQ representative confirmed they were also unaffected, citing restricted API access through IP whitelisting that prevented exposure. Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio did not respond to requests for comment. Haruko did not respond to repeated requests for comment.
Haruko has fixed the vulnerability and refreshed its server-side secrets.
