< Back to all clusters
[TECHNOLOGY] · United Kingdom · 2 sources

started · updated

Haruko cyberattack exposes client data and results in fund theft

Haruko, a London-based digital asset technology platform, has suffered a cyberattack that exposed the data of 15 clients. The breach involved the exploitation of a vulnerability in one of the company’s processes, allowing attackers to obtain a user access token and access data stored in the process’s memory.

The exposed information reportedly included trading data and read-only exchange API details. While Haruko stated that login credentials stored on clients’ own systems were not affected, the company confirmed that a small amount of client funds were stolen during the incident.

Chief Technology Officer Adam Carlile described the event as a “targeted attack by a group on us.” In response, Haruko has fixed the vulnerability, rotated its server-side secrets, and advised clients to implement inbound IP whitelists to restrict access to approved addresses.

The incident highlights ongoing security challenges in the cryptocurrency sector. According to TRM Labs, there were 207 hacks in the first half of 2026, resulting in approximately $972 million in stolen assets, with attacks on infrastructure and operational systems accounting for 76% of those funds.

Entities

Adam Carlile · Haruko · MMC Ventures · TRM Labs · White Star Capital