Haruko Hit by Targeted Network Attack Affecting 15 Clients
Haruko, a provider of cryptographic technology, has been hit by a targeted network attack that affected 15 clients. The attack exposed client details and trading data from their read-only exchange API, with some security-weak fund clients potentially losing small amounts of funds.
The attack was initiated by an organization targeting Haruko's non-whitelist clients, according to Adam Carlile, the company's co-founder and chief technology officer. Clients' login credentials were not compromised, but attackers exploited a vulnerability in one of Haruko's processes to extract user access tokens, which gave them access to internal memory where API information was stored.
Haruko has fixed the vulnerability, refreshed server-side keys, and plans to release a comprehensive technical post-mortem report. The company provides investment portfolio, risk management, and trading data infrastructure for institutional digital asset companies, connecting centralized exchanges, custodians, blockchain, and DeFi protocols. Haruko services over 80 clients worldwide, with access to more than 100 centralised exchanges, 30 blockchains, and 250 on-chain protocols.