Haruko Breach Exposes API Data and Trading Records of 15
Haruko was targeted in a cyberattack that exposed trading data and read-only exchange API details belonging to 15 crypto clients, according to reports. The breach also resulted in a small amount of client funds being stolen. Haruko said its own infrastructure was targeted rather than any specific client. Attack Exposed Client Data The attacker exploited a vulnerability in one of Haruko‘s processes and obtained a user access token that provided access to data stored in the process’s memory. Related: Fake AI Crypto Tools Replace Wallet Extensions—How to Spot the Trap The exposed information may have included read-only exchange API details and trading data. Haruko said login credentials stored on clients own systems were not affected. “This was a targeted attack by a group on us,” Chief Technology Officer Adam Carlile told clients, adding that 15 clients were affected. Haruko has since fixed the vulnerability and rotated its server-side secrets. The company also advised clients to use inbound IP whitelists to restrict access to approved addresses. Crypto Security Breaches The Haruko breach is part of a broader wave of crypto security incidents this year. TRM Labs counted 207 hacks in the first six months of 2026, with about $972 million in crypto stolen. Attacks on infrastructure and other operational systems accounted









