Cyberattack Hit 15 Haruko Clients

A security breach at the crypto firm exposed client exchange API details and trading data.

Updated on Sept. 18, 2026 in Cybersecurity

Bold flat-color editorial illustration of a heavy geometric architectural facade, evoking the gravity of digital infrastructure security risks.
Cybersecurity firm Haruko confirmed a breach that exposed the API and trading data of 15 clients, prompting immediate system-wide security patches. AI Illustration. Upload story photo >

Live Poll

Do you trust crypto technology providers to keep your institutional data and funds secure?

A cyberattack targeting the crypto technology provider Haruko compromised the data of 15 non-whitelisted clients. The incident resulted in the unauthorized exposure of client exchange API details and proprietary trading information.

Why it matters

The breach highlights the persistent security risks faced by crypto infrastructure providers, particularly those managing sensitive API connections. Securing these communication channels is critical for maintaining the integrity of digital asset trading environments.

The attackers gained access to data through the API communication process used by the platform. Haruko operates using bare-metal servers rather than relying on standard cloud-based infrastructure.

The players

Haruko

Haruko is a crypto technology provider that specializes in digital asset infrastructure.

The details

The attackers specifically targeted non-whitelisted clients during the incident, successfully accessing sensitive exchange API details and trading data. In response, Haruko has patched the vulnerability and refreshed its server-side secrets to prevent further unauthorized access.

Timeline

  1. The cyberattack occurred during the week of September 14, 2026.

The Tech Race

This incident underscores the ongoing arms race between security providers and attackers targeting API-based trading communication protocols. As firms move away from cloud services toward bare-metal servers, they must adapt their security models to protect against evolving endpoint exploits.

Users of crypto technology providers should review their own API key permissions and ensure that only authorized services have access to their exchange accounts. Regularly rotating keys and auditing third-party integrations remains a vital practice for maintaining account privacy.

The takeaway

Entities managing digital asset data must prioritize the hardening of API communication processes to protect user trading information. Clients should proactively manage and rotate their API credentials to mitigate the impact of potential future service vulnerabilities.

Further reading

For more information on digital safety, visit the Cybersecurity section.

Live Poll

Do you trust crypto technology providers to keep your institutional data and funds secure?

Cyberattack Hit 15 Haruko Clients