Haruko Suffers Targeted Cyberattack, 15 Clients Impacted
TREE NEWS reports: Crypto technology service provider Haruko has fallen victim to a targeted cyberattack, affecting 15 of its clients and resulting in the theft of funds from some accounts. The exact amount stolen has not been disclosed, but the breach has forced affected clients to revoke exchange read-only API keys as a precaution.
Haruko provides portfolio management and risk infrastructure for institutional crypto traders, connecting to exchanges and custodians. The attack appears to have exploited its integration layer, potentially compromising client credentials and trading permissions.
Industry Implications: A Growing Attack Surface
This incident underscores the rising sophistication of cyber threats targeting crypto infrastructure. Unlike decentralized protocols, centralized service providers like Haruko act as trusted intermediaries, aggregating sensitive data and access rights across multiple venues. A single breach can cascade across dozens of clients, magnifying the damage.
The timing is particularly concerning. It follows the massive Bybit hack, which rattled confidence in exchange security. Attackers may now be pivoting to softer targets—technology vendors that sit between funds and exchanges—where security budgets are often smaller and oversight less rigorous.
- Concentration risk: 15 clients affected in one stroke highlights systemic vulnerability in shared infrastructure.
- Credential management: The theft of read-only keys, while limited, raises questions about API permission hygiene.
- Regulatory scrutiny: Expect increased demands for third-party risk assessments and incident disclosure.
Forward-Looking Perspective
Institutional adoption of crypto hinges on robust operational security. Haruko’s breach will likely accelerate demand for decentralized identity solutions, hardware-based key management, and zero-trust architectures. Service providers must now prove not just functionality but resilience against nation-state-grade adversaries.
For clients, the lesson is clear: diversify counterparty exposure and enforce strict API key rotation. As the industry matures, security will become a primary competitive differentiator, and those who fail to prioritize it may find themselves on the wrong side of the next headline.




