A targeted cyberattack on Haruko, a London-based provider of portfolio and risk-management infrastructure to crypto institutions, affected 15 clients and exposed their read-only exchange API details and trading data, CoinDesk reported on September 18, citing internal messages from the company's co-founder and CTO, Adam Carlile, and three people with knowledge of the matter.

The affected parties were all of Haruko's non-whitelisted clients. According to the messages, the attacker exploited a vulnerability in one of Haruko's processes, extracting a user-access token and using it to capture data held in the process's memory — which could have included read-only exchange API details and trading data. Client login credentials were not compromised on client systems. A small amount of client funds was stolen, the people said, with smaller hedge funds running weaker security controls likely the most exposed. One source tied the breach surface to Haruko's use of bare-metal servers, which lack some of the security controls offered by cloud providers.

Carlile described it as "a targeted attack by a group on us" — Haruko itself, not any particular customer — and said the company has fixed the vulnerability and refreshed its server-side secrets. Haruko told clients that configuring an inbound IP whitelist provides "maximum protection" and plans to publish a full technical post-mortem. The company did not respond to repeated requests for comment; among clients named on its website, GSR said it was not impacted and 3iQ said its API access was protected by IP whitelisting.

Haruko connects more than 80 clients to over 100 centralized venues, 30 blockchains and 250 on-chain protocols — exactly the kind of aggregation layer where a single process compromise can fan out across many funds. Secondary reporting by Shattered corroborated the core facts of the disclosure.

The Bigger Number

The incident lands in a record period. TRM Labs counted 207 crypto attacks in the first half of 2026 — more than double the 83 recorded a year earlier — totaling $972 million in losses, with infrastructure and operational compromises accounting for about 76% of the money stolen. Supply-chain and vendor-layer breaches like Haruko's are the defining shape of that trend: the attack doesn't touch the chain, only the plumbing around it.

The lesson for funds is the one Haruko's own remediation implies — read-only API keys are not harmless. They expose positions, counterparties and trading behavior, and in weaker configurations they can become a path to funds. Whitelisting, key rotation and treating every vendor process holding credentials as privileged infrastructure are now table stakes.

TrustGrade tracks the security posture of platforms and firms in digital assets. Verified trust data: trustgrade.ai.