Haruko Breach Exposes API Data and Trading Records of 15

摘要:Haruko was targeted in a cyberattack that exposed trading data and read-only exchange API details belonging to 15 crypto clients, according to reports.

Haruko was targeted in a cyberattack that exposed trading data and read-only exchange API details belonging to 15 crypto clients, according to reports.

The breach also resulted in a small amount of client funds being stolen. Haruko said its own infrastructure was targeted rather than any specific client.

Attack Exposed Client Data

The attacker exploited a vulnerability in one of Haruko‘s processes and obtained a user access token that provided access to data stored in the process’s memory.

Related: Fake AI Crypto Tools Replace Wallet Extensions—How to Spot the Trap

The exposed information may have included read-only exchange API details and trading data. Haruko said login credentials stored on clients own systems were not affected.

“This was a targeted attack by a group on us,” Chief Technology Officer Adam Carlile told clients, adding that 15 clients were affected.

Haruko has since fixed the vulnerability and rotated its server-side secrets. The company also advised clients to use inbound IP whitelists to restrict access to approved addresses.

Crypto Security Breaches

The Haruko breach is part of a broader wave of crypto security incidents this year. TRM Labs counted 207 hacks in the first six months of 2026, with about $972 million in crypto stolen.

Attacks on infrastructure and other operational systems accounted for about 76% of the stolen funds, even though they made up only about 15% of the incidents, TRM Labs said.

Recent breaches have involved employee devices, smart contracts and company infrastructure, highlighting multiple security risks across the crypto industry.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

伊朗利用加密货币资助IRGC受限 美国财政部再制裁加密交易所

下一篇

WikiBit交易所跑路風險榜第31期CoinW:詐騙洗錢23億、扣下52萬美元賬戶、被韓國和土耳其封殺