Haruko Breach Exposes API Data and Trading Records of 15

摘要:Haruko was targeted in a cyberattack that exposed trading data and read-only exchange API details belonging to 15 crypto clients, according to reports.

Haruko was targeted in a cyberattack that exposed trading data and read-only exchange API details belonging to 15 crypto clients, according to reports.

The breach also resulted in a small amount of client funds being stolen. Haruko said its own infrastructure was targeted rather than any specific client.

Attack Exposed Client Data

The attacker exploited a vulnerability in one of Haruko‘s processes and obtained a user access token that provided access to data stored in the process’s memory.

Related: Fake AI Crypto Tools Replace Wallet Extensions—How to Spot the Trap

The exposed information may have included read-only exchange API details and trading data. Haruko said login credentials stored on clients own systems were not affected.

“This was a targeted attack by a group on us,” Chief Technology Officer Adam Carlile told clients, adding that 15 clients were affected.

Haruko has since fixed the vulnerability and rotated its server-side secrets. The company also advised clients to use inbound IP whitelists to restrict access to approved addresses.

Crypto Security Breaches

The Haruko breach is part of a broader wave of crypto security incidents this year. TRM Labs counted 207 hacks in the first six months of 2026, with about $972 million in crypto stolen.

Attacks on infrastructure and other operational systems accounted for about 76% of the stolen funds, even though they made up only about 15% of the incidents, TRM Labs said.

Recent breaches have involved employee devices, smart contracts and company infrastructure, highlighting multiple security risks across the crypto industry.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

研究员利用 Claude 攻破 OpenAI 获 6500 美元

下一篇

每周编辑精选 Weekly Editor's Picks ( 0912-0918 )