Cyberattack Hit 15 Haruko Clients
A security breach at the crypto firm exposed client exchange API details and trading data.
Updated on Sept. 18, 2026 in Cybersecurity

Live Poll
Do you trust crypto technology providers to keep your institutional data and funds secure?
A cyberattack targeting the crypto technology provider Haruko compromised the data of 15 non-whitelisted clients. The incident resulted in the unauthorized exposure of client exchange API details and proprietary trading information.
Why it matters
The breach highlights the persistent security risks faced by crypto infrastructure providers, particularly those managing sensitive API connections. Securing these communication channels is critical for maintaining the integrity of digital asset trading environments.
The attackers gained access to data through the API communication process used by the platform. Haruko operates using bare-metal servers rather than relying on standard cloud-based infrastructure.
The players
Haruko
Haruko is a crypto technology provider that specializes in digital asset infrastructure.
The details
The attackers specifically targeted non-whitelisted clients during the incident, successfully accessing sensitive exchange API details and trading data. In response, Haruko has patched the vulnerability and refreshed its server-side secrets to prevent further unauthorized access.
Timeline
The cyberattack occurred during the week of September 14, 2026.
The Tech Race
This incident underscores the ongoing arms race between security providers and attackers targeting API-based trading communication protocols. As firms move away from cloud services toward bare-metal servers, they must adapt their security models to protect against evolving endpoint exploits.
Users of crypto technology providers should review their own API key permissions and ensure that only authorized services have access to their exchange accounts. Regularly rotating keys and auditing third-party integrations remains a vital practice for maintaining account privacy.
The takeaway
Entities managing digital asset data must prioritize the hardening of API communication processes to protect user trading information. Clients should proactively manage and rotate their API credentials to mitigate the impact of potential future service vulnerabilities.
Further reading
For more information on digital safety, visit the Cybersecurity section.
Live Poll
Do you trust crypto technology providers to keep your institutional data and funds secure?







