A targeted cyberattack against crypto technology provider Haruko has affected 15 institutional clients, exposing exchange API details and trading information and reportedly resulting in the theft of a small amount of client funds.
The incident has highlighted the security risks faced by crypto hedge funds and trading firms that rely on third-party infrastructure to connect their operations with centralized exchanges, custodians, blockchains and decentralized finance platforms.
Haruko said the attackers exploited a vulnerability in one of its internal processes and obtained a user access token. The token provided access to information held in the affected process’s memory, which could have included read-only exchange API information and trading data.
The company has since fixed the vulnerability and refreshed its server-side secrets.
What Happened in the Haruko Hack?
The Haruko hack was a targeted attack against the company’s own infrastructure rather than a direct attack against one particular crypto exchange or hedge fund.
According to information provided to customers, an attacker exploited a vulnerability in one of Haruko’s processes and extracted a user access token from memory.
That token gave the attacker access to information associated with the affected clients.
Haruko said that 15 customers were affected by the incident. The affected clients were reportedly customers that had not configured inbound IP whitelisting.
The exposed information included read-only exchange API details and trading data.
Client login credentials stored on their own systems were not compromised as part of the incident, according to the company’s communications with customers.
Exchange API Details Were Exposed
One of the most important aspects of the incident was the exposure of exchange API information.
API keys allow different software systems to communicate with one another. In institutional crypto trading, APIs are commonly used to connect portfolio-management systems with cryptocurrency exchanges and other financial platforms.
The permissions attached to an API key can vary.
Some keys can only retrieve information about account balances, transactions and trading activity. Others may have permission to execute trades or perform additional account functions.
The API information exposed in the Haruko incident was described as read-only.
Read-only access normally prevents an API credential from directly authorizing trades or withdrawals. However, the exposure can still create security concerns because it may reveal sensitive information about a firm’s positions, trading activity and relationships with different exchanges.
The incident therefore demonstrates why API security remains important even when credentials do not have direct trading or withdrawal permissions.
Trading Data Was Also Stolen
The Haruko breach was not limited to API information.
Trading data belonging to affected clients was also exposed, according to information surrounding the incident.
For institutional trading firms and hedge funds, trading data can be highly sensitive.
Information about positions, strategies, transaction histories and trading patterns can potentially reveal how a fund operates in the market.
Even when attackers cannot immediately move funds, access to this information can create other risks.
Competitors or malicious actors could potentially use exposed information to understand a firm’s market activity. Attackers could also combine stolen information with vulnerabilities elsewhere in a firm’s infrastructure.
The full scope of the trading information accessed during the Haruko attack has not yet been publicly disclosed.
Were Client Funds Stolen?
A small amount of client funds was reportedly stolen during the incident.
The exact amount has not been publicly disclosed.
The reported theft is particularly notable because the exposed exchange credentials were described as read-only. Read-only API access by itself would ordinarily not provide permission to withdraw assets.
This means the precise relationship between the exposed information and the reported loss remains an important unanswered question.
Further technical information from Haruko is expected to provide greater clarity about how the attack unfolded and how the reported funds were taken.
Smaller hedge funds with weaker security controls were reportedly more exposed during the incident.
Why Did IP Whitelisting Matter?
IP whitelisting has emerged as one of the most important security details surrounding the Haruko breach.
An IP whitelist restricts API connections to a predefined group of approved internet addresses.
If an attacker obtains an API credential but attempts to use it from an unauthorized location, the whitelist can prevent the connection from being accepted.
The 15 clients affected in the Haruko incident reportedly had not enabled this protection.
Haruko has subsequently advised customers to configure inbound IP whitelisting and described the measure as providing the strongest available protection.
The incident demonstrates why organizations should consider multiple layers of security rather than relying solely on API permissions.
Haruko’s Response to the Attack
Following the discovery of the vulnerability, Haruko said it fixed the affected system and refreshed its server-side secrets.
The company also advised clients to strengthen their security controls.
A technical post-mortem is expected to provide additional information about the vulnerability, the attack path and the company’s response.
Such a report could be particularly important for institutional customers because Haruko operates as an infrastructure provider connecting financial firms to numerous digital-asset platforms.
Understanding exactly how the attacker obtained the access token could help other companies identify similar weaknesses in their own systems.
Why Haruko Is Important to Crypto Trading Firms
Haruko provides technology infrastructure for institutional digital-asset businesses.
Its platform helps firms manage portfolio information, monitor risk and consolidate trading data across multiple platforms.
The company connects clients with centralized exchanges, custodians, blockchains and decentralized finance protocols.
This makes infrastructure providers an increasingly important part of the institutional crypto ecosystem.
A trading firm may have strong security at its own headquarters and still face additional risks when it connects its systems to external technology providers.
The Haruko incident illustrates how a vulnerability at one service provider can potentially affect multiple customers simultaneously.
Third-Party Infrastructure Creates New Security Risks
The Haruko hack also highlights a broader problem facing the cryptocurrency industry: third-party risk.
Crypto companies increasingly rely on specialized providers for trading, custody, analytics, portfolio management, compliance and blockchain connectivity.
These services can make institutional operations more efficient, but they also create additional connections between different systems.
Each connection can become a potential attack surface.
If a third-party provider manages connections to dozens of exchanges and blockchain networks, a successful attack against that provider could expose information belonging to many different organizations.
This is why institutional investors increasingly need to evaluate not only their own security systems but also the security practices of their technology providers.
Read-Only Does Not Mean Risk-Free
One of the biggest lessons from the Haruko incident is that read-only API access should not automatically be considered risk-free.
Read-only permissions can substantially limit what an attacker can do directly with a compromised credential.
However, sensitive information can still have significant value.
An attacker may obtain information about account balances, trading history, asset positions or investment strategies.
In some circumstances, this information could be combined with other compromised credentials or weaknesses elsewhere in an organization’s security environment.
For that reason, institutional crypto firms should treat all API credentials as sensitive information and protect them accordingly.
Crypto Industry Faces Growing Cybersecurity Pressure
The Haruko incident comes as cryptocurrency companies continue to face persistent cyberattacks.
Crypto businesses remain attractive targets because digital assets can potentially be moved quickly across borders and transactions on many blockchain networks are difficult or impossible to reverse.
Attackers have targeted exchanges, decentralized finance protocols, blockchain infrastructure providers, individual wallets and technology companies.
The industry has also seen an increasing focus on attacks against infrastructure rather than simply attacking individual cryptocurrency wallets.
This means that cybersecurity strategies must increasingly cover the entire technology supply chain.
What Crypto Firms Can Learn From the Haruko Hack
The incident provides several security lessons for institutional crypto businesses.
First, companies should carefully review the permissions assigned to every API credential. Credentials should have only the permissions required for their intended purpose.
Second, organizations should consider IP whitelisting wherever it is available.
Third, API credentials should be rotated regularly and immediately after any suspected compromise.
Fourth, companies should monitor API activity for unusual access patterns, unfamiliar IP addresses and unexpected requests.
Finally, firms should evaluate the security architecture of third-party providers before connecting sensitive systems to them.
Security cannot stop at the boundary of a company’s own network.
What Happens Next?
The full implications of the Haruko hack will depend on the results of the company’s continuing investigation and its planned technical post-mortem.
Important questions remain about the precise information accessed, the number of API credentials exposed, the circumstances surrounding the reported fund theft and whether attackers attempted to use the stolen information elsewhere.
Affected clients will also need to review their exchange connections, rotate credentials where appropriate and monitor their accounts for unusual activity.
The incident could also encourage other institutional crypto technology providers to strengthen access controls and require customers to adopt additional protections such as IP whitelisting.
Conclusion
The Haruko hack hits 15 crypto clients and has exposed an important weakness in the security infrastructure supporting institutional cryptocurrency trading.
The attack compromised information including read-only exchange API details and trading data after an attacker exploited a vulnerability in a Haruko process and obtained an access token.
Although the exposed API credentials were described as read-only, people familiar with the incident reported that a small amount of client funds was stolen. The exact amount and the precise mechanism behind the reported losses have not been publicly disclosed.
Haruko has fixed the vulnerability, refreshed its server-side secrets and advised customers to use IP whitelisting.
The incident serves as a reminder that crypto security extends beyond private keys and exchange accounts. Third-party infrastructure, API connections and trading data can all become targets.
For institutional crypto firms, the Haruko attack reinforces the importance of strict API permissions, IP restrictions, credential rotation, continuous monitoring and careful assessment of third-party technology providers.
As the digital-asset industry becomes more interconnected, securing the infrastructure between trading firms and exchanges will become just as important as protecting the assets themselves.
Disclaimer: This article is provided for informational and educational purposes only. The information presented is based on publicly available reports and may change as further details emerge. Readers should conduct their own research and verify information before making any financial, investment, or business decisions. We do not provide financial, legal, or investment advice.



