2026 Haruko — process vuln + stolen access token; 15 clients’ read-only exchange APIs/trading data
Data compromised
Read-only exchange API details and trading data for 15 non-IP-whitelisted clients. Client login credentials on client systems not compromised per Haruko. Sources told CoinDesk a small amount of client funds was also stolen (amount undisclosed).
Technical writeup
Verified via Haruko CTO Adam Carlile client messages reviewed by CoinDesk (published Sep 18, 2026). Attacker exploited a vulnerability in a Haruko process, extracted a user access token, and captured memory that could include read-only exchange API details and trading data. 15 clients impacted — all without inbound IP whitelisting. Haruko fixed the vulnerability, rotated server-side secrets, and urged IP whitelisting; plans a technical post-mortem. Client-system login credentials not compromised per company. Sources said a small amount of client funds was stolen (undisclosed). GSR and 3iQ said they were not impacted. recordsAffected 15 (clients); companyConfirmed true.
Root cause
Targeted attack exploiting a vulnerability in a Haruko process; attacker extracted a user access token and captured data from process memory
References
- https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost
- https://www.altcoinbuzz.io/haruko-breach-hit-15-non-whitelisted-clients-via-stolen-access-token
- https://coinedition.com/crypto-live-news/haruko-breach-exposes-api-data-and-trading-records-of-15/