
Haruko cyberattack affects 15 crypto clients
- Haruko has suffered a targeted cyberattack that affected 15 clients and exposed read-only exchange API details and trading data.
- A small amount of client funds has reportedly been stolen, although the value has not been disclosed.
- Haruko has fixed the vulnerability, refreshed its server-side secrets and plans to publish a technical post-mortem.
Haruko, a crypto technology provider for institutional firms, has suffered a targeted cyberattack affecting 15 clients and exposing exchange API details and trading data.
The affected customers were Haruko clients without IP whitelisting, while the company says the breach did not compromise login credentials on clients’ own systems.
“This was a targeted attack by a group on us,” Haruko co-founder and Chief Technology Officer Adam Carlile told clients.
The attacker exploited a vulnerability in a Haruko process, extracted a user-access token and used it to capture data held in the process’s memory, including potentially read-only exchange API details.
A small amount of client funds has been stolen, according to people familiar with the incident, while Haruko has fixed the vulnerability and refreshed its server-side secrets.
Haruko says it serves more than 80 clients globally and connects with over 100 centralised trading venues, 30 blockchains and 250 onchain protocols, while it plans to publish a full technical post-mortem.
The incident has come as attacks on crypto companies have increased, with 207 attacks recorded during the first half of 2026 and $972 million in reported losses.


