
Haruko Says Cyberattack Affected 15 Clients and Exposed API Data

Haruko Says Cyberattack Affected 15 Clients and Exposed API Data
WEEX View
- The key follow-up is whether any additional clients disclose losses or operational disruption beyond the 15 already identified. Haruko said the affected users were non-whitelisted, which narrows the immediate scope but leaves counterparty-risk questions for firms relying on shared trading infrastructure.
- Markets should also watch Haruko’s promised technical review for more detail on the attack path, how access tokens were extracted, and whether the exposure was limited to read-only data or revealed broader process weaknesses around API handling.
- For institutional trading desks, the practical issue is not only stolen funds but whether exchanges, clients, and vendors tighten API permission settings, token management, and whitelisting requirements after the incident.
Haruko said earlier this week it was hit by a cyberattack that affected 15 clients, exposing read-only exchange API details and trading data, while some hedge fund clients with weaker security suffered small fund losses, according to comments from co-founder and CTO Adam Carlile.
Haruko said the attackers exploited a vulnerability in its internal processes to extract user access tokens and obtain read-only exchange API information held in process memory. The company said clients’ login credentials were not compromised.
Carlile said the attack was initiated by an organization and that all affected clients were non-whitelisted. Haruko said some hedge fund clients with weaker security may have had small amounts of funds stolen, though it did not disclose the total value of losses, identify the affected firms, or specify which exchanges or accounts were involved.
The London-based firm provides portfolio, risk management, and trading data infrastructure to institutional digital asset companies. Haruko said it serves more than 80 clients globally and connects to more than 100 centralized exchanges, 30 blockchains, and 250 on-chain protocols. Its listed clients include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, and M2. GSR said it was not affected by the incident.
Haruko said it has patched the vulnerability and refreshed server-side keys. The company also said it plans to publish a comprehensive technical review. For now, several material details remain undisclosed, including the timeline of client notifications, the exact number of accounts exposed at each client, and whether any outside forensic or regulatory review is under way.
Why It Matters
The incident highlights a sensitive part of crypto market structure: the software and data providers that sit between institutional clients and trading venues. Even when exchange login credentials are not compromised, exposure of API data and token-handling weaknesses can create operational and custody risks for firms that rely on automated trading connections.
It also puts more focus on basic control design in institutional crypto operations, especially API permission limits and account whitelisting. As more professional trading firms depend on connected infrastructure across exchanges and blockchains, security failures at service providers can become a direct source of counterparty and execution risk.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreWaterPlum Used Fake Crypto Jobs to Breach 30,000 Devices
A joint law enforcement advisory said North Korean-linked group WaterPlum infected at least 30,000 devices in more than 100 countries and exfiltrated funds or credentials from over 7,000 crypto wallets, with at least $10.71 million traced to DPRK-linked control.
MultiversX Says Mainnet Was Exploited and Network Has Been Paused
MultiversX said its mainnet was hacked through a virtual machine atomicity issue that caused invalid state changes, prompting a network pause while the team tests a fix and prepares a recovery plan with validators and exchanges.
Coinbase Taps Stablecore to Extend Crypto Tools to US Banks
Coinbase has partnered with Stablecore to make crypto trading, custody and stablecoin payment services available through banking technology used by more than 3,000 U.S. banks and credit unions, though adoption will depend on each institution activating the services.
US Treasury Sanctions Iran-Linked Crypto Exchange BitBank
The U.S. Treasury sanctioned Iranian digital asset exchange BitBank, its software developer, and three associates tied to Babak Zanjani, alleging the platform helped move hundreds of millions of dollars in Bitcoin to the IRGC.


