Haruko Cyberattack Hits Certain Clients After Access Token Theft

Institutional crypto technology firm Haruko has told customers that a targeted intrusion into its own systems reached a limited group of users. The London company supplies portfolio, risk and trade-data tools that sit between hedge funds and the exchanges they use.

In messages to clients, co-founder and chief technology officer Adam Carlile said attackers exploited a flaw in one internal process, pulled a user access token from that process’s memory, and thereby obtained read-only exchange API details and trading records belonging to 15 customers.

Haruko does not hold client assets.

Its role is connectivity and visibility across more than 100 centralized venues, dozens of blockchains and hundreds of on-chain protocols.

The credentials that were exposed were described as read-only, intended only to retrieve positions and history.

Even so, people familiar with the matter have said a small quantity of funds belonging to certain clients was taken.

Those losses appear to have fallen on smaller hedge-fund users whose own security controls were lighter.

No dollar figure has been published.

Carlile described the operation as aimed at Haruko itself rather than any single customer.

The fifteen affected firms were those that had not enabled inbound IP whitelisting, a setting that confines API traffic to approved network addresses.

Company login details stored on clients’ own systems were not compromised, according to the same client messages.

Haruko says it has closed the vulnerability, rotated server-side secrets and advised every customer to turn on IP restrictions for the strongest available protection.

A fuller technical account is expected later.

The firm lists more than 80 institutional clients.

Names that appear on its public site include GSR, Bitcoin Suisse, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management) and Trovio Asset Management. GSR has said it was not affected.

The other listed firms had not issued public comments when the first accounts of the incident circulated.

One person familiar with the architecture noted that Haruko runs on dedicated bare-metal servers rather than a major public cloud, a choice that can reduce some shared-environment risks while also limiting certain managed security features.

The episode underlines a familiar problem for infrastructure providers that never take custody yet still handle live connectors into trading venues.

A token that was never meant to move money still created an opening once it left the intended process.

Smaller organizations with thinner operational security proved more exposed than larger counterparties that already enforced tighter controls.

Affected clients now face the practical work of rotating every connected key, checking whether strategy data left the environment, and confirming that no further unauthorized activity followed the token theft.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend