Haruko Cyberattack Exposed 15 Client Exchange APIs
The crypto technology provider confirmed that trading data was accessed through a server-side vulnerability.
Updated on Sept. 18, 2026 in Cybersecurity

Live Poll
Do you trust crypto technology providers to keep your institutional data and funds secure?
A cyberattack targeting crypto technology provider Haruko exposed exchange API details and trading data for 15 clients. The incident impacted only non-whitelisted accounts.
Why it matters
The breach highlights the security challenges inherent in infrastructure that relies on custom, bare-metal server deployments. It underscores the importance of securing API communication processes to protect institutional trading environments.
The incident involved an exploit within the API communication process on Haruko's proprietary infrastructure. Unlike many competitors that utilize cloud service providers, Haruko maintains a bare-metal server architecture.
The players
Haruko
A crypto technology provider that maintains infrastructure using bare-metal servers rather than public cloud services.
The details
The attacker leveraged a flaw in the API communication process to gain unauthorized access to client data. Haruko, which manages infrastructure using bare-metal servers—physical hardware dedicated to a single user—was forced to respond by patching the vulnerability. Following the detection of the breach, the firm conducted a full refresh of its server-side secrets to prevent further unauthorized access.
Timeline
The cyberattack occurred during the week leading up to September 14, 2026.
The Tech Race
Most institutional crypto providers rely on managed cloud services to offload security and patching responsibilities. Haruko's reliance on bare-metal servers necessitates a higher level of internal security maintenance compared to firms utilizing standardized cloud environments.
Affected clients with non-whitelisted accounts should verify their API key permissions and rotation status immediately. The firm has already completed a refresh of server-side secrets to mitigate further unauthorized access.
The takeaway
The event serves as a reminder to institutional traders that custom server configurations require rigorous API communication security. Watch for future audits regarding how Haruko hardens its bare-metal infrastructure against similar communication exploits.
Further reading
For more on the current threat landscape, visit the Cybersecurity section.
Live Poll
Do you trust crypto technology providers to keep your institutional data and funds secure?






