Some of Haruko’s smaller hedge-fund clients may have lost assets after the provider of crypto technology to institutions was targeted in a cyberattack earlier this week that affected 15 customers, according to three people with knowledge of the matter.
The breach exposed clients’ read-only exchange application programming interface (API) details and trading data, according to messages reviewed by CoinDesk and people familiar with the incident. APIs allow clients’ and Haruko’s computers to communicate and exchange information.
The affected parties were all of Haruko’s non-whitelisted clients, according to messages from the company’s co-founder and chief technology officer, Adam Carlile, to a client and seen by CoinDesk. A whitelist allows communication only with approved computers or websites.
Haruko did not respond to repeated requests for comment.
The breach was possible because Haruko uses bare-metal servers, or physical computers used exclusively by itself, rather than cloud services such as Amazon Web Services, which offer additional security controls, according to one of the people.
Haruko does not disclose its full customer roster, though its website names Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now operating as Monarq Asset Management) and Trovio Asset Management as clients.
The London-based firm provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of their positions, transactions and risk exposure.
“GSR has not been impacted by any rumored breach,” a company spokesperson said. Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication time.
A small amount of client funds was stolen, the people said, who spoke on condition of anonymity because the matter is private. Smaller hedge funds with weaker security controls may have been particularly exposed, the people said. Trading data was also taken.
Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.
The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory, Carlile told clients. That memory could have included read-only exchange API details and other data.
Clients’ login credentials were not compromised on their own systems, according to the messages. Instead, the access token was extracted through a vulnerability in Haruko’s infrastructure.
coindesk.com