← Haruko

2026 Haruko — process vuln + stolen access token; 15 clients’ read-only exchange APIs/trading data

2026 15 records affected Share on X

Data compromised

Read-only exchange API details and trading data for 15 non-IP-whitelisted clients. Client login credentials on client systems not compromised per Haruko. Sources told CoinDesk a small amount of client funds was also stolen (amount undisclosed).

Technical writeup

Verified via Haruko CTO Adam Carlile client messages reviewed by CoinDesk (published Sep 18, 2026). Attacker exploited a vulnerability in a Haruko process, extracted a user access token, and captured memory that could include read-only exchange API details and trading data. 15 clients impacted — all without inbound IP whitelisting. Haruko fixed the vulnerability, rotated server-side secrets, and urged IP whitelisting; plans a technical post-mortem. Client-system login credentials not compromised per company. Sources said a small amount of client funds was stolen (undisclosed). GSR and 3iQ said they were not impacted. recordsAffected 15 (clients); companyConfirmed true.

Root cause

Targeted attack exploiting a vulnerability in a Haruko process; attacker extracted a user access token and captured data from process memory

References