Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost
Some smaller hedge funds with weaker security controls may have lost funds in the targeted attack, sources said.

Some of Haruko’s smaller hedge-fund clients may have lost assets after the provider of crypto technology to institutions was targeted in a cyberattack earlier this week that affected 15 customers, according to three people with knowledge of the matter.
The breach exposed clients’ read-only exchange application programming interface (API) details and trading data, according to messages reviewed by CoinDesk and people familiar with the incident. APIs allow clients’ and Haruko’s computers to communicate and exchange information.
The affected parties were all of Haruko’s non-whitelisted clients, according to messages from the company’s co-founder and chief technology officer, Adam Carlile, to a client and seen by CoinDesk. A whitelist allows communication only with approved computers or websites.
The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory, Carlile told clients. That memory could have included read-only exchange API details and other data.