How many clients lost funds in the Haruko crypto tech provider cyberattack?

The recent cyberattack on crypto technology provider Haruko affected 15 institutional clients, leading to direct financial losses for several smaller hedge funds. This targeted breach underscores the growing risks associated with third-party infrastructure in the institutional digital asset space.
How many clients lost funds in the Haruko crypto tech provider cyberattack?

A targeted cyberattack on the institutional crypto technology provider Haruko has resulted in a breach affecting 15 of its clients, with some smaller hedge funds suffering direct losses of funds. While Haruko provides sophisticated portfolio management and connectivity tools, sources indicate that firms with weaker internal security controls were particularly vulnerable to the exploit. The attack appears to have specifically aimed at compromising the bridge between tech providers and fund execution layers.

This incident highlights a critical vulnerability in the institutional crypto ecosystem: the reliance on third-party aggregators for sensitive data and asset management. For U.S.-based hedge funds, this breach serves as a stark reminder that even robust external platforms cannot replace rigorous internal security protocols. The loss of funds, though currently limited to a subset of 'smaller' clients, raises questions about the scalability of security measures as more boutique firms enter the digital asset market in 2026.

From a regulatory perspective, the Haruko breach is likely to draw the attention of the SEC and CFTC, which have been increasingly focused on third-party risk management for digital asset advisors. This event may accelerate the implementation of stricter cybersecurity mandates for technology providers serving the financial sector, potentially requiring more frequent SOC 2 audits and real-time monitoring of API permissions.

Market participants should watch for a full post-mortem report from Haruko to determine the exact vector of the attack—whether it was an API compromise, a social engineering effort, or a deeper system vulnerability. In the immediate future, smaller institutional players may move toward more fragmented custody solutions to mitigate the risk of a single point of failure in their tech stack. As the investigation continues, the focus will remain on whether any larger, more systemic entities were exposed during the breach.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.