
Haruko Says Cyberattack Affected 15 Clients and Exposed API Data

Haruko Says Cyberattack Affected 15 Clients and Exposed API Data
WEEX View
- The key follow-up is whether any additional clients disclose losses or operational disruption beyond the 15 already identified. Haruko said the affected users were non-whitelisted, which narrows the immediate scope but leaves counterparty-risk questions for firms relying on shared trading infrastructure.
- Markets should also watch Haruko’s promised technical review for more detail on the attack path, how access tokens were extracted, and whether the exposure was limited to read-only data or revealed broader process weaknesses around API handling.
- For institutional trading desks, the practical issue is not only stolen funds but whether exchanges, clients, and vendors tighten API permission settings, token management, and whitelisting requirements after the incident.
Haruko said earlier this week it was hit by a cyberattack that affected 15 clients, exposing read-only exchange API details and trading data, while some hedge fund clients with weaker security suffered small fund losses, according to comments from co-founder and CTO Adam Carlile.
Haruko said the attackers exploited a vulnerability in its internal processes to extract user access tokens and obtain read-only exchange API information held in process memory. The company said clients’ login credentials were not compromised.
Carlile said the attack was initiated by an organization and that all affected clients were non-whitelisted. Haruko said some hedge fund clients with weaker security may have had small amounts of funds stolen, though it did not disclose the total value of losses, identify the affected firms, or specify which exchanges or accounts were involved.
The London-based firm provides portfolio, risk management, and trading data infrastructure to institutional digital asset companies. Haruko said it serves more than 80 clients globally and connects to more than 100 centralized exchanges, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, and M2. GSR said it was not affected by the incident.
Haruko said it has patched the vulnerability and refreshed server-side keys. The company also said it plans to publish a comprehensive technical review. For now, several material details remain undisclosed, including the timeline of client notifications, the exact number of accounts exposed at each client, and whether any outside forensic or regulatory review is under way.
Why It Matters
The incident highlights a sensitive part of crypto market structure: the software and data providers that sit between institutional clients and trading venues. Even when exchange login credentials are not compromised, exposure of API data and token-handling weaknesses can create operational and custody risks for firms that rely on automated trading connections.
It also puts more focus on basic control design in institutional crypto operations, especially API permission limits and account whitelisting. As more professional trading firms depend on connected infrastructure across exchanges and blockchains, security failures at service providers can become a direct source of counterparty and execution risk.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVietnam Targets 2026 Crypto Licenses Under Pilot Framework
Vietnam said it expects to license its first crypto asset service providers in 2026 under a pilot framework, while officials discussed regulatory cooperation with Austria's FMA on investor protection, anti-money laundering, and market supervision.
SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code
SlowMist said FomoPeek App versions 1.1 to 1.2 carried malicious code that could expose private keys and other sensitive data on affected iPhones, after users reported stolen assets linked to private key leaks.
Switchboard Says It Will Wind Down Oracle Operations
Switchboard said it is ceasing operations, with maintenance for its oracle implementations ending immediately and remaining support scheduled to end on September 25, prompting protocols to migrate to alternatives including Pyth and RedStone.
Bastion Seeks OCC Trust Charter as Stablecoin Regulation Tightens
Bastion is pursuing an OCC national trust bank charter after earlier reports framed the matter as conditional approval, highlighting growing efforts by crypto infrastructure firms to move stablecoin and custody businesses into a federal oversight framework.


