Finst

Haruko Hack Hits 15 Customers and Leaks Trading Data

At the London-based portfolio and risk management provider, read-only exchange APIs and trading data were stolen. The attack fits into a broader wave of hacks targeting crypto infrastructure.

Haruko Hack Hits 15 Customers and Leaks Trading Data

Key Takeaways

  • Haruko was hit by a targeted cyberattack that affected 15 customers.
  • Attackers stole read-only exchange API data and trading data; a small amount may have been stolen from some smaller hedge funds.
  • Haruko says it has fixed the vulnerability and refreshed its server-side secrets.

Haruko was hit by a targeted cyberattack that affected 15 customers. Read-only exchange API data and trading data were stolen, and according to sources, a small amount of funds may have been stolen from some smaller hedge funds with weaker security.

What Was Stolen

According to reports, the attack hit all of Haruko's non-whitelisted customers. A whitelist only allows pre-approved computers or websites, and that extra layer was missing for the affected accounts. According to messages sent to customers, a vulnerability in one of Haruko's processes was exploited, after which a user access token was stolen and data from that process's memory could be read.

Customers' login details on their own systems were not compromised. However, attackers were able to access data through Haruko's infrastructure that could include exchange API details and trading information. Haruko said it has fixed the vulnerability and refreshed its server-side secrets.

Why This Matters for the Crypto Market

The hack fits into a broader wave of attacks on crypto companies. In the first half of 2026, TRM Labs reported a record 207 attacks, with total losses of $972 million (€848 million). That matters for European crypto investors because institutional players in particular are becoming more and more dependent on outside infrastructure for trading, custody, and risk management.

Haruko is a London-based crypto company that provides portfolio, risk management, and trade data infrastructure to institutional digital asset firms. The platform connects to crypto exchanges, custodians, blockchains, and DeFi protocols, which means an incident at a company like this can quickly affect multiple customers without their own systems being directly hit. That makes this incident similar to other infrastructure leaks, such as the shift toward key and infrastructure attacks that has been seen more often this year.

A Broader Pattern of Attacks

TRM Labs said infrastructure and operational compromises accounted for about 76% of stolen funds, while making up only 15% of incidents. That suggests attackers are increasingly focusing on access and processes around crypto infrastructure, instead of only smart contracts or individual wallets.

Haruko says it serves more than 80 customers worldwide and connects to more than 100 centralized trading platforms, 30 blockchains, and 250 onchain protocols. The company has said it will publish a full technical post-mortem later.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.