Haruko Breach Hits 15 Institutional Clients, Some Funds Stolen

Haruko, the London firm that supplies portfolio management and trade-data plumbing to institutional crypto desks, was breached in a targeted attack that reached 15 of its clients. Read-only exchange API details and trading records were taken. A small amount of client money went with them. CoinDesk, which published the account on Friday afternoon, was told by three people familiar with the matter that smaller hedge funds with weaker security controls may have lost assets. Nobody has published a loss figure.
What one access token opened
The way in was a flaw in one of Haruko's own processes. It exposed a user access token, and the token gave up the data sitting in that process's memory. Clients' own systems were never touched. CoinEdition adds that login credentials escaped because they live on the client side, a point no other account read for this piece confirms. What the attackers reached instead was the connective layer between a trading firm and the venues it uses: read-only keys to exchange accounts, plus the trading data Haruko aggregates for the firms that hire it. The company says it works with more than 80 institutional clients and plugs into over 100 centralised exchanges, 30 blockchains and 250 on-chain protocols. Seven separate accounts carry the figure of 15 affected clients without variation.
No day, no clock time, no total
The timing is vague in every version of the story. CoinDesk dates the intrusion to earlier in the week of 18 September and names no day, and PANews and Phemex repeat that phrasing without narrowing it. No clock time exists anywhere in this week's coverage. The loss is described the same way in all seven accounts, as a small amount, and none of them arrives at a total. Haruko's co-founder and chief technology officer, Adam Carlile, told clients what had happened in two sentences.
"This was a targeted attack by a group on us...It was 15 clients impacted," Carlile said.
A client list is not a casualty list
CoinDesk's account is that every customer without an inbound IP whitelist was caught, which turns one configuration setting into the line between the 15 and everyone else. The firms publicly known to use Haruko include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group and Trovio Asset Management. That roster is not a list of the affected, and the distinction matters. GSR is the only one on the record, and it said it was unaffected. M2, which holds a licence from Abu Dhabi's ADGM and engaged Haruko for treasury risk management in earlier reporting, has said nothing this week. Whether any named firm sits among the 15 is unestablished here.
Where the fix leaves everyone else
Haruko patched the vulnerability, rotated its server-side secrets and told clients to configure inbound IP whitelists. A full technical post-mortem has been promised and had not appeared by Saturday. Two of the accounts note that the firm runs bare-metal servers instead of a cloud provider, though both trace that observation to CoinDesk, so it is one source repeated. Read-only keys cannot move money on their own, and the practical work for an affected desk is rotating every credential across every connected venue and reading its own fills for anything it did not place. Extortion has followed this kind of theft before, and hackers holding Revolut customer files demanded 6,000 monero for them earlier in the week. The sector tallies quoted around the story do not agree either. TRM Labs counts 207 attacks and about $972 million stolen in the first half of 2026, CertiK about $1.32 billion across 344 incidents, a gap of $348 million and 137 incidents that neither firm's published method closes. Rival counts of the same period have split like this before. Both sets agree on one shape: infrastructure and operational compromises took roughly 76% of all stolen value from about 15% of incidents. Haruko is the second kind of target in that split, and the post-mortem is the only document that would show how it was reached.
Read also: Bits of Gold Breach Exposes Data of Up to 250,000 Customers