Crypto World

Haruko hack hits 15 crypto clients, with exchange API details, trading data and funds stolen

Published

on

The London-based firm provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of their positions, transactions and risk exposure.

“GSR has not been impacted by any rumored breach,” a company spokesperson said. Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication time.

A small amount of client funds was stolen, the people said, who spoke on condition of anonymity because the matter is private. Smaller hedge funds with weaker security controls may have been particularly exposed, the people said. Trading data was also taken.

Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

Advertisement

The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory, Carlile told clients. That memory could have included read-only exchange API details and other data.

Clients’ login credentials were not compromised on their own systems, according to the messages. Instead, the access token was extracted through a vulnerability in Haruko’s infrastructure.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version