Haruko cyberattack exposes data of 15 clients, some funds lost

1 hour ago 28

Haruko, a London-based digital asset technology platform that serves as connective tissue between hedge funds and the exchanges they trade on, has been hit by a cyberattack that exposed data belonging to 15 clients. Some funds were also lost in the incident.

What Haruko does, and why this matters

Founded in March 2021, Haruko built its business by solving one of institutional crypto’s most persistent headaches: fragmented visibility. The platform connects centralized finance exchanges, on-chain protocols, and over-the-counter trading venues into a single dashboard, giving hedge funds, market makers, and treasury teams real-time insight into their financial exposures.

The company raised approximately $16 million in total funding, including a $6 million Series A round in July 2024 co-led by White Star Capital and MMC Ventures. It integrates with over 100 centralized trading venues and supports more than 30 blockchains and 250 on-chain protocols.

Haruko advertises role-based permissions, multi-factor authentication, single sign-on integration, and IP whitelisting. The fact that a breach still occurred despite those safeguards raises questions about the attack vector.

The institutional trust problem

The confirmation that some funds were actually lost elevates this from a data breach to a theft. The distinction matters for legal liability, insurance claims, and the regulatory response that’s likely to follow.

A pattern the industry can’t shake

Haruko occupies a different layer of the stack than typical crypto attack targets. It’s a data and analytics platform, not a custodian. The fact that funds were still lost suggests the attackers may have gained access to API keys, trading credentials, or other sensitive connectors that Haruko maintains to link client accounts across venues.

The same feature that makes Haruko valuable to clients — its ability to unify fragmented data across 100-plus exchanges and 250-plus protocols — also creates a single point of compromise.

What comes next

The UK’s Financial Conduct Authority has been expanding its digital asset regulatory perimeter, and a breach at a London-based provider with institutional clients will almost certainly draw scrutiny.

The 15 affected clients now face their own set of decisions. Beyond any immediate financial losses, they need to assess what data was exposed, whether their trading strategies have been compromised, and how to rotate credentials across every venue Haruko connected to.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article