A targeted cyberattack on Haruko, the London-based provider of portfolio and risk-management software for institutional crypto firms, affected 15 clients and exposed their exchange API details and trading data, with some smaller hedge funds losing funds in the breach.
The attack took place earlier this week, according to three people with knowledge of the incident who spoke to CoinDesk. The affected parties were all of Haruko’s non-whitelisted clients, according to messages from the company’s co-founder and chief technology officer, Adam Carlile, to a client that CoinDesk reviewed. Haruko’s platform connects with centralized exchanges, custodians, blockchains and decentralized finance protocols, giving institutional clients a consolidated view of their positions, transactions and risk exposure across venues.
The breach exposed clients’ read-only exchange API details and trading data, according to the messages and the people familiar with the incident. Attackers exploited a vulnerability in one of Haruko’s processes to extract user access tokens, then used those tokens to access the connected exchange data. Some of Haruko’s smaller hedge-fund clients with weaker security controls may have lost assets, the sources said. The company has not published a public statement on the incident, and the total amount of stolen funds is not yet known.
What was exposed
Read-only API keys allow a third party to view account balances, positions and trade history but not to place orders or withdraw funds. That limits direct theft, but the exposed data is still valuable to attackers. A trader’s positions and order history reveal strategy, sizing and risk limits, information that can be used to front-run trades or to target the trader directly with social engineering. Access tokens extracted from Haruko’s infrastructure could also serve as a stepping stone to further compromise at the affected funds, particularly where staff reuse credentials or where exchange accounts lack two-factor protection.
The incident is notable because Haruko sits in the middle of the institutional crypto stack. Its clients include crypto-native hedge funds and traditional firms trading digital assets, and the platform aggregates data across venues, so a compromise at the vendor touches many firms at once. Bitcoin Suisse and M2, a Dubai-based exchange and treasury operator, are among the firms that have publicly described using Haruko for treasury and risk management. Neither has commented on whether their data was affected.
A heavy year for crypto hacks
The Haruko breach lands in a year when crypto security incidents have already set records by count. TRM Labs reported that the first half of 2026 saw more hacking incidents than any prior half-year period, with losses falling below $1 billion, meaning the average incident size has shrunk while the number of attacks has grown. The spread of targets has widened accordingly: this month alone has seen the US Treasury sanction an Iranian exchange over bitcoin transfers to the IRGC, a $3 million ransom demand against Revolut customers paid in monero, and now a vendor compromise reaching hedge funds through their portfolio software.
Third-party compromise has been a recurring pattern all year. Hardware wallet maker Trezor confirmed this month that a breach at Brevo, the email provider it uses for newsletters, exposed customer contact data and was followed by phishing campaigns against hundreds of thousands of crypto owners. Security researchers have repeatedly warned that vendors with privileged API access to client trading accounts are a single point of failure for the funds management industry, and that aggregation platforms concentrate exactly the data attackers want.
What it means for institutional crypto
For institutional allocators, the incident underlines a due diligence question that traditional fund administration has long handled: what does a manager’s software vendor see, hold and risk? API keys, even read-only ones, expose position data that many funds treat as proprietary. A vendor compromise that leaks aggregate positioning across a dozen funds is a market information problem as much as a security problem, since counterparties who learn a large fund’s book can trade against it.
Funds using portfolio aggregators typically connect exchange APIs with IP allowlisting, withdrawal address controls and separate trading keys as mitigations, but those controls assume the vendor itself is secure. The Haruko case shows the assumption can fail. The report that whitelisted clients were spared suggests the attack targeted the vendor’s broader token store rather than individual client credentials, and that tighter infrastructure controls on the vendor side, not client-side hygiene alone, are what separated affected firms from unaffected ones.
Haruko was founded in 2021 by Adam Carlile, Omer Suleman and Shamyl Malik, and raised venture funding from MMC Ventures and White Star Capital. Carlile previously built high-frequency trading systems at Deutsche Bank and Voltaire Capital. The company had been expanding its product line this year, including an integration with prediction market Polymarket announced earlier in the summer. Neither the company nor its investors had publicly commented on the incident at the time of writing.
For the broader institutional crypto market, the breach arrives just as traditional finance deepens its footprint in the sector. Deutsche Bank announced digital asset custody for European institutional clients this week, and Circle launched its Arc blockchain with BlackRock, Visa and Mastercard as validators. Infrastructure providers are now handling more institutional money and data than ever, which raises the stakes for every vendor in the chain. A single compromised aggregator can now expose the trading patterns of funds across several jurisdictions at once, and insurers covering digital asset managers are likely to ask harder questions about vendor security after this incident.
