Haruko Breach Exposes 15 Clients and Drains Funds

A cyberattack on digital asset infrastructure firm Haruko compromised 15 clients, stealing exchange API keys and trading data. Some smaller hedge funds lost assets, while the company claims to have patched the vulnerability.
Fifteen clients of crypto technology provider Haruko were affected by a targeted cyberattack. The breach exposed read-only exchange application programming interface details. Trading data was also stolen from the system. A small amount of client funds was drained during the incident.
Smaller hedge funds with weaker security controls were likely the most exposed. These entities may have suffered the majority of the financial losses. Larger institutional clients reported no impact on their assets. The attack targeted Haruko’s infrastructure rather than individual client logins.
Breach mechanics and data loss
The attacker exploited a vulnerability in one of Haruko’s internal processes. A user-access token was extracted during the intrusion. This token allowed the attacker to capture data held in the process memory. The compromised data included read-only API keys and trading records.
Haruko uses bare-metal servers for its operations. These physical computers lack the additional security controls of cloud services. The company stated that clients’ login credentials remained safe. The compromise occurred through the extracted access token, not direct credential theft.
Client responses and firm status
Several named clients denied any impact from the incident. GSR stated it was not affected by the rumored breach. 3iQ Digital Assets confirmed its funds remain secure. The firm cited IP whitelisting as a key protective measure. Other clients did not respond to comment requests.
Haruko’s co-founder and CTO confirmed the scope of the attack. He described the incident as a targeted group effort. The company identified all 15 affected parties as non-whitelisted clients. Haruko did not respond to repeated media requests for comment.
Remediation and security upgrades
Haruko has fixed the specific vulnerability used in the attack. The company refreshed its server-side secrets to prevent reuse. Clients were advised to configure inbound IP whitelists. This step restricts access to specified internet addresses for maximum protection.
The firm plans to publish a full technical report. The report will detail the timeline of the breach. It will also outline the specific remediation steps taken. The incident highlights persistent risks in digital asset infrastructure. Irreversible transactions and digital credentials remain key attack vectors.






