AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsHaruko breach hit 15 non-whitelisted clients via stolen access token
Crypto NewsDeFiTechnology

Haruko breach hit 15 non-whitelisted clients via stolen access token

London-based crypto infrastructure provider Haruko confirmed a targeted cyberattack in the week of Sept.

BBikash Deka•Sep 18, 2026
Pop-art illustration of a cracked safe with a glowing API key fob sliding out and a Haruko badge on its face, next to a headline reading TOKEN BREACH AT HARUKO.

Haruko breach hit 15 non-whitelisted clients via stolen access token

Fifteen of Haruko's non-whitelisted hedge-fund clients had read-only exchange API details and trading data stolen in a targeted cyberattack earlier the week of Sept. 18, the London-based crypto infrastructure provider said. All 15 affected parties were clients that had not configured Haruko's IP-whitelist feature, according to co-founder and chief technology officer Adam Carlile.

Haruko provides portfolio, risk-management and trade-data tooling to institutional digital-asset firms, connecting to centralized exchanges, custodians, blockchains and DeFi protocols. The firm says it serves more than 80 clients globally and links to over 100 centralized trading venues, 30 blockchains and 250 on-chain protocols. The attacker exploited a vulnerability in one of Haruko's processes, extracted a user-access token, and used it to capture data held in the process's memory, what Carlile described as "a targeted attack by a group on us."

Why the breach landed where it did

All 15 affected parties were clients that had not configured an inbound IP whitelist, a setting that restricts access to specified internet addresses, and Haruko has since told clients to enable it for what the firm calls maximum protection. The breach was possible in the first place because Haruko runs on bare-metal servers, physical machines used exclusively by the firm, rather than cloud infrastructure such as AWS, which ships with extra security controls. Haruko has fixed the vulnerability and refreshed its server-side secrets, and plans to publish a full technical post-mortem.

What was lost, and what is not yet known

A small amount of client funds was stolen, according to three people familiar with the matter. The exact dollar figure has not been disclosed. Smaller hedge funds with weaker security controls may have been particularly exposed, those people said. Haruko has not named which 15 of its more than 80 clients were affected. Of the eight firms listed on Haruko's public website, only GSR has confirmed its status: GSR publicly said it was not impacted. The other seven publicly listed clients, Bitcoin Suisse, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management, have not commented.

The wider attack landscape

TRM Labs counted 207 crypto attacks in the first half of 2026, more than double the 83 recorded a year earlier, with $972 million in losses. Infrastructure and operational compromises accounted for about 76% of the money stolen despite representing only 15% of incidents, TRM said. Security firm CertiK, using a broader definition, put first-half losses at $1.32 billion across 344 incidents.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

A pop-art comic cover showing a large tokenized Treasury coin bearing the WisdomTree mark flowing into a MoonPay-marked stablecoin reserve badge, with a speech bubble reading WTGXX INTO RESERVES.
StablecoinsRWA
Sep 18, 2026

WisdomTree's $1.23B WTGXX enters MoonPay, stablecoin reserves

WTGXX, WisdomTree's $1.23 billion tokenized U.S. Treasury money market fund, will be sold through MoonPay to U.S.

Shitij Gupta
Pop-art illustration of a balance scale weighing a coin with an Apple mark against a stack of USDC tokens, with Morpho and Coinbase logos placed over the beam and top-left corner.
DeFiRWA
Sep 18, 2026

Morpho opens borrowing against Coinbase stock tokens on Base

Morpho on Base lets holders borrow USDC against Coinbase's tokenized stocks at variable or fixed rates. At a Friday snapshot, $104k was pledged and $54k drawn.

USDCMORPHO
Anmol Billa
A pop-art comic illustration of a CFTC seal stamped over a stalled CLARITY Act document, with a White House dome in the background.
Regulation
Sep 18, 2026

CFTC files crypto market rules with White House as CLARITY Act stalls

The CFTC filed its crypto market-structure rulemaking with OIRA on Sept.

Anmol Billa