A targeted cyberattack has affected 15 clients of crypto infrastructure company Haruko, exposing read-only exchange API information and trading data, according to people familiar with the incident and messages reviewed in connection with the attack.
Some smaller hedge-fund clients also reportedly suffered limited financial losses. The total value of the losses has not been disclosed.
Haruko said on September 18 that it had identified and fixed the vulnerability responsible for the incident and had rotated its server-side secrets as part of its response.
Read-Only API Information Exposed
The information accessed during the incident included read-only exchange API details and trading data associated with affected clients.
Read-only API permissions generally allow an application to retrieve account or trading information without giving it authority to execute trades or withdraw funds. However, the specific permissions and configurations associated with each affected account have not been disclosed.
Haruko has not publicly provided detailed information about how long the vulnerability was exposed, when the intrusion was first detected or exactly what information was accessed from each client.
The company said its remediation efforts included fixing the vulnerability and replacing server-side secrets.
Attack Reportedly Involved Process Memory
Reports about the incident indicate that the attackers gained access through a vulnerability within a Haruko process.
According to those reports, the attackers were able to obtain an access token from process memory and use it to access information associated with affected clients.
The reported method is significant because it differs from a conventional attack involving the theft of customers’ own login credentials.
There is no indication in the available information that the clients’ personal login credentials were compromised within their own systems.
Some Clients Report Financial Losses
People familiar with the incident said several smaller hedge-fund clients suffered relatively small losses.
The overall amount involved has not been disclosed, and details about how the funds were lost remain unclear.
It is also not clear whether the reported financial losses were directly connected to the read-only API information that was exposed or resulted from another aspect of the incident.
Haruko has not publicly disclosed a detailed breakdown of the affected clients or any financial losses linked to the attack.
Haruko Responds to Vulnerability
Haruko said it had resolved the exploited vulnerability and rotated its server-side secrets as part of its response.
The company has not disclosed further technical details about the vulnerability or the full scope of the incident.
The attack highlights the security risks associated with third-party infrastructure that connects institutional trading firms and hedge funds to cryptocurrency exchanges.
Even when API credentials are configured with limited permissions, access to trading information and infrastructure-level tokens can create security concerns for affected customers.
The incident also underscores the importance of isolating sensitive credentials, monitoring process environments and promptly rotating secrets when a compromise is suspected.
Further details about the attack, including the exact scope of the exposure and the amount of any financial losses, could emerge as the investigation continues.
Disclaimer: This article is for informational purposes only and does not constitute legal, tax, investment, financial or other professional advice.



