Haruko Cyberattack Exposed 15 Client Exchange APIs

The crypto technology provider confirmed that trading data was accessed through a server-side vulnerability.

Updated on Sept. 18, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a monolithic server rack stack, evoking institutional infrastructure and digital security.
Crypto infrastructure firm Haruko patched a server vulnerability after a cyberattack exposed API trading data for 15 institutional clients. AI Illustration. Upload story photo >

Live Poll

Do you trust crypto technology providers to keep your institutional data and funds secure?

A cyberattack targeting crypto technology provider Haruko exposed exchange API details and trading data for 15 clients. The incident impacted only non-whitelisted accounts.

Why it matters

The breach highlights the security challenges inherent in infrastructure that relies on custom, bare-metal server deployments. It underscores the importance of securing API communication processes to protect institutional trading environments.

The incident involved an exploit within the API communication process on Haruko's proprietary infrastructure. Unlike many competitors that utilize cloud service providers, Haruko maintains a bare-metal server architecture.

The players

Haruko

A crypto technology provider that maintains infrastructure using bare-metal servers rather than public cloud services.

The details

The attacker leveraged a flaw in the API communication process to gain unauthorized access to client data. Haruko, which manages infrastructure using bare-metal servers—physical hardware dedicated to a single user—was forced to respond by patching the vulnerability. Following the detection of the breach, the firm conducted a full refresh of its server-side secrets to prevent further unauthorized access.

Timeline

  1. The cyberattack occurred during the week leading up to September 14, 2026.

The Tech Race

Most institutional crypto providers rely on managed cloud services to offload security and patching responsibilities. Haruko's reliance on bare-metal servers necessitates a higher level of internal security maintenance compared to firms utilizing standardized cloud environments.

Affected clients with non-whitelisted accounts should verify their API key permissions and rotation status immediately. The firm has already completed a refresh of server-side secrets to mitigate further unauthorized access.

The takeaway

The event serves as a reminder to institutional traders that custom server configurations require rigorous API communication security. Watch for future audits regarding how Haruko hardens its bare-metal infrastructure against similar communication exploits.

Further reading

For more on the current threat landscape, visit the Cybersecurity section.

Live Poll

Do you trust crypto technology providers to keep your institutional data and funds secure?