A select group of smaller hedge-fund clients utilizing Haruko may have experienced capital losses following a cyber intrusion earlier in the week directed at the institutional crypto technology supplier, impacting 15 accounts according to three informed individuals.
The security breach compromised users’ read-only exchange application programming interface details alongside transaction records, based on communications reviewed by CoinDesk and insiders acquainted with the situation. APIs facilitate communication and data exchange between client systems and Haruko’s architecture.
The impacted entities consisted entirely of Haruko’s non-whitelisted customers, as stated in communications from co-founder and Chief Technology Officer Adam Carlile directed to a client and reviewed by CoinDesk. A whitelist restricts network communication exclusively to approved IP addresses or digital hosts.
Haruko declined multiple requests for commentary.
The security failure occurred because Haruko relies upon bare-metal servers—dedicated physical hardware operated independently—rather than utilizing external cloud environments such as Amazon Web Services that incorporate built-in defensive configurations, an insider noted.
Haruko maintains confidentiality regarding its complete client directory, though its official portal identifies Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (currently functioning as Monarq Asset Management), and Trovio Asset Management as users.
Headquartered in London, the organization supplies portfolio tracking, risk management, and transaction data systems to institutional digital asset operators. Its infrastructure integrates with centralized trading platforms, asset custodians, blockchains, and decentralized finance protocols, offering users an aggregated dashboard of holdings, activities, and risk exposures.
“GSR has not been impacted by any rumored breach,” a spokesperson for the company stated.
“3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment,” a representative for the firm remarked via email.
Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC, and Trovio did not respond to inquiries before publication.
Minor amounts of client capital were drained, noted the sources, who requested anonymity due to the confidentiality of the issue. Boutique hedge funds operating with minimal internal security protocols were potentially most vulnerable, according to the informants. Transaction logs were likewise extracted.
Digital asset exploits remain an ongoing hurdle for the sector given that transfers are fundamentally irreversible and networks depend heavily on cryptographic authorizations and validation mechanisms that can supply malicious actors direct paths to funds.
The wrongdoer exploited a flaw within a specific Haruko operational process, stealing a user authentication token and leveraging it to harvest data stored inside the operational process memory, Carlile informed users. That memory space potentially contained read-only exchange API configurations alongside other information.
Client login credentials within their personal environments remained secure, according to the messages. Instead, the authorization token was acquired via a flaw within Haruko’s foundational network.
“This was a targeted attack by a group on us,” the chief technology officer noted within the statements, indicating that Haruko itself, rather than any individual user, served as the primary target. “It was 15 clients impacted.”
Haruko reported that it patched the vulnerability and updated its backend cryptographic secrets. The company advised clients that configuring an inbound IP whitelist to limit access to designated web locations delivers “maximum protection.” Furthermore, the organization intends to release a comprehensive technical post-mortem analysis.
The business indicates that it services over 80 global clients and links to upwards of 100 centralized marketplaces, 30 blockchains, and 250 on-chain protocols, as stated on its platform.
This penetration transpires amidst a rising tide of security compromises targeting digital asset enterprises. Malicious operators executed a record 207 attacks during the initial half of 2026, marking more than double the 83 occurrences logged during the preceding year, data from TRM Labs indicates. These events led to $972 million in financial damage.
Infrastructure and workflow exploits represented approximately 76% of capital stolen despite accounting for merely 15% of total events, TRM reported. Security organization CertiK, applying a wider scope, estimated H1 losses at $1.32 billion across 344 distinct incidents.
Originally published at https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost.