Live News

Batch could also let exchanges, wallets and marketplaces attach their service charges directly to a customer transaction...

“The dead cat continues to bounce,” wrote investor Jason Calacanis as bitcoin returned to the $80,000 level on Friday...

Treasury desks at major institutions are juggling three systems for the same job, said Jerald David, CEO of Lynq Network...

19/09/26

Volg ons:

Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost

Crypto tech provider Haruko hit by cyberattack affecting 15 clients, some funds lost
Default Door Remote - 18 Sep 2026
The London-based firm provides portfolio, risk-management and trade-data infrastructure to institutional digital-asset firms. Its platform connects with centralized exchanges, custodians, blockchains and decentralized-finance (DeFi) protocols, giving clients a consolidated view of their positions, transactions and risk exposure.

“GSR has not been impacted by any rumored breach,” a company spokesperson said.

“3iQ was not affected by this breach. Our funds remain fully secure, and our API access is restricted through IP whitelisting, preventing any exposure to the compromised environment,” a representative for the firm said in emailed comments.

Bitcoin Suisse, Flowdesk, M2, Ampersan, MNNC and Trovio did not reply to requests for comment before publication time.

A small amount of client funds was stolen, the people said, who spoke on condition of anonymity because the matter is private. Smaller hedge funds with weaker security controls may have been particularly exposed, the people said. Trading data was also taken.

Hacks remain a persistent problem for the crypto industry because transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory, Carlile told clients. That memory could have included read-only exchange API details and other data.