Key Highlights
- A cyberattack on crypto infrastructure provider Haruko affected 15 clients, according to messages reviewed by CoinDesk.
- Attackers obtained an access token that exposed exchange API information and trading data.
- People familiar with the incident said a small amount of client funds was stolen, although no amount has been disclosed.
Crypto infrastructure provider Haruko was reportedly targeted in a cyberattack that affected 15 clients and exposed exchange API information and trading data.
According to a September 18 report by CoinDesk, attackers exploited a vulnerability in one of Haruko’s processes and obtained an access token that allowed them to access information associated with affected customers. People familiar with the incident also said that a small amount of client funds was stolen. The amount and the method of the reported theft have not been disclosed.
The Crypto Times has reached out to Haruko for additional information about the incident, including the data accessed and the reported financial loss. A response was awaited at the time of publication.
Attackers obtained Haruko access token
Haruko co-founder and Chief Technology Officer Adam Carlile said the attackers exploited a vulnerability in one of the company’s processes and extracted an access token.
The token provided access to information stored in the process’s memory.
Carlile told customers that 15 clients were affected. “This was a targeted attack by a group on us. 15 clients were impacted.”
The exposed information reportedly included read-only exchange API credentials and trading data.
Haruko has not publicly identified all affected clients.
Read-only API credentials were exposed
Read-only API credentials generally allow software to retrieve account or market information without authorizing trades or withdrawals. Their exposure can still create security risks depending on the permissions attached to individual accounts and the security controls surrounding those credentials.
Haruko advised affected customers to enable inbound IP whitelisting, which restricts API connections to approved addresses.
Haruko’s website lists Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group and Trovio Asset Management among its customers.
Reported fund theft has not been quantified
People familiar with the matter said that a small amount of client funds was stolen during the incident. However, neither the amount nor the exact attack path leading to the reported theft has been disclosed.
The exposure of read-only API credentials alone would not ordinarily authorize withdrawals. Haruko has not released enough technical information to establish whether the reported loss was directly connected to the exposed credentials.
Further details may emerge when the company publishes its planned technical post-mortem.
Haruko says vulnerability was fixed
Haruko told customers that it had fixed the exploited vulnerability and rotated its server-side secrets following the attack.
The company also recommended IP whitelisting for affected customers.
Haruko said it plans to publish a technical post-mortem covering the incident and its response. The report is expected to provide additional information about the attack path, affected systems, and the scope of the data exposure.
Attack comes amid broader crypto security losses
The Haruko incident adds to a wider series of security incidents affecting the digital-asset industry this year.
TRM Labs reported 207 crypto attacks during the first half of 2026, resulting in approximately $972 million in losses. The firm said infrastructure and operational compromises accounted for about 76% of stolen funds while representing roughly 15% of reported incidents.
CertiK, using a different methodology, estimated first-half crypto losses at approximately $1.32 billion across 344 incidents.
The figures are not directly comparable because the firms use different methodologies, but both reports point to continued losses from security incidents across the sector.
Recent attacks have involved different parts of the ecosystem, including third-party infrastructure, individual devices and smart contracts.
Attack adds to broader crypto security concerns
The Haruko incident comes amid continued attacks across different layers of the digital-asset industry.
In September, Japan’s National Police Agency said the North Korea-linked group WaterPlum, also known as Contagious Interview, used fake recruitment processes and malicious coding assignments to target IT workers in Japan, the United States, Europe and other regions.
The campaign relied on social engineering and malicious software rather than an attack on crypto infrastructure.
In another recent incident, Blockaid identified an exploit involving older FlamingoFinance contracts. The attacker used an $18 million USDT flash loan to manipulate VaultYUSDT pricing and extracted approximately $345,900.
The incidents involved different attack methods and affected separate parts of the crypto ecosystem, including third-party infrastructure, individual devices, and smart contracts.
Haruko incident remains under investigation
Several details of the attack remain unresolved, including the amount of funds reportedly stolen and the full scope of the information accessed.
Haruko’s planned technical post-mortem could provide further details about the vulnerability and the systems involved.
For now, the incident shows how a compromise at a third-party infrastructure provider can expose information connected to multiple crypto clients, even when the affected exchange credentials are configured with read-only permissions.
Also Read: Nostra Halts Starknet Money Market After $3.5M NSTR Oracle Exploit
