Haruko confirms cyberattack affecting 15 clients with reported fund losses.
Security & Exploits ·
Haruko, a crypto technology provider serving institutional clients, disclosed a cyberattack that compromised 15 customers earlier this week, with some funds reported stolen. The breach exposed read-only exchange API credentials and trading data belonging to non-whitelisted clients. Company co-founder and chief technology officer Adam Carlile characterized the incident as a targeted attack on Haruko's infrastructure rather than individual customers, stating the vulnerability allowed attackers to extract a user-access token and access data in system memory.
The security lapse stemmed from Haruko's use of bare-metal servers instead of cloud platforms offering enhanced protective measures, according to people familiar with the matter. Attackers exploited a process vulnerability to obtain the token, bypassing clients' login systems entirely. Smaller hedge funds operating with less robust security protocols were identified as particularly vulnerable to asset loss in the incident.
Haruko has patched the vulnerability and rotated server-side secrets, recommending clients implement inbound IP whitelists to restrict access to approved addresses. The company pledged to release a full technical post-mortem. Several named clients, including GSR, did not acknowledge impact, while others including Bitcoin Suisse and Flowdesk declined to comment before publication. Haruko's full customer roster remains undisclosed.