London-based crypto technology services provider Haruko was hit by a targeted cyberattack this week, affecting 15 clients and allegedly causing asset losses for some smaller hedge fund customers. Trading data was also stolen. According to Foresight News, the attacker exploited a vulnerability in Haruko's infrastructure to extract user access tokens and obtain read-only exchange API information and other data stored in process memory, while customer login credentials were not affected.

Haruko co-founder and Chief Technology Officer Adam Carlile said the attack was directed at Haruko itself. He added that the vulnerability has been fixed, server keys have been refreshed, and a full technical postmortem will be released. Haruko's website lists clients including Bitcoin Suisse, GSR, and Flowdesk, and GSR said it was not affected.