Haruko 攻击事件如何波及客户数据?
机构级加密货币技术提供商 Haruko 遭遇网络攻击,导致 15 家客户受到影响。此次事件暴露了只读交易所 API 密钥及交易信息,据报道还造成少量客户资金被盗。这家总部位于伦敦的公司为数字资产企业提供投资组合管理、风险监控和交易数据基础设施服务,连接机构客户与中心化交易所、托管方、区块链以及去中心化金融协议。
据联合创始人兼首席技术官 Adam Carlile 向客户发送的消息称,攻击者利用了 Haruko 某一流程中的漏洞,提取了一个用户访问令牌(User-Access Token)。随后,攻击者使用该令牌捕获了该进程内存中存储的信息,其中可能包含只读交易所 API 密钥及其他交易数据。客户的登录凭证并未在其自有系统中泄露,而是攻击者通过 Haruko 的基础设施获得了访问权限。
Carlile 向客户表示:“这是一次针对我们的定向攻击。”他确认共有 15 家客户受到影响。Haruko 表示已修补该漏洞并刷新了其服务器端密钥。该公司还计划发布一份技术事后分析报告,更详细地说明此次事件的经过。
IP 白名单为何至关重要?
受影响与未受影响客户之间最明显的区别在于是否配置了 IP 白名单。根据 Haruko 发送给客户的通知,受影响的 15 家客户均未配置白名单功能。IP 白名单将 API 访问限制在指定的互联网地址范围内,从而降低 stolen 凭据或令牌被未经授权的系统使用的风险。
Haruko 在攻击后告知客户,配置入站 IP 白名单可提供“最大程度的保护”。GSR 表示其未受此次事件影响。3iQ Digital Assets 也表示其资金保持安全,并特别指出 IP 白名单防止了其 API 访问暴露于受损环境中。
这一区别使得此次漏洞对依赖第三方基础设施但可能未像大型机构那样维持同等安全控制措施的中小型对冲基金和交易公司具有特别的警示意义。虽然只读 API 密钥通常无法直接授权提款,但暴露的交易数据、账户信息以及互联的基础设施仍可能创造额外的攻击面。
投资者启示
Haruko 事件表明,机构级加密货币的风险并不局限于交易所和私钥本身。交易公司日益依赖聚合头寸并连接多个交易场所的第三方系统,这意味着一旦基础设施遭到破坏,可能导致多家客户同时暴露风险。IP 白名单所提供的明显保护作用也显示,基本的访问控制措施能够实质性地改变同一漏洞事件的结果。
Why is Haruko an important part of an organization's cryptographic infrastructure?
Haruko claims to serve more than 80 customers globally and integrate with more than 100 centralized trading venues, more than 30 blockchains, and 250 on-chain protocols. Customers listed on its website include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan and Trovio Asset Management. The platform effectively serves as an intermediary between institutional trading firms and numerous exchanges and agreements, integrating position, trading and risk information into a single system.
Infrastructure providers are attractive targets even if they do not directly hold customer assets. Once an attacker breaches a service provider, it is possible to obtain details of multiple funds, their exchange relationships, and potentially trading activity data. The attack fits a pattern already evident in major cryptographic breaches in 2026: compromised infrastructure, credentials and operational systems are becoming increasingly important attack vectors in addition to traditional smart contract vulnerabilities.
Are Cryptographic Attackers Turning to Infrastructure?
Haruko breach occurred during a year when cryptographic security incidents were extremely active. According to industry estimates, more than 200 attacks were recorded in the first half of 2026, with losses of nearly US$1 billion. CertiK's broader first-half 2026 dataset estimates losses of approximately $1.32 billion in 344 security incidents. Wallet breaches alone cost hundreds of millions of dollars in losses, while other attacks increasingly target the infrastructure systems surrounding blockchain applications rather than vulnerabilities in the smart contract itself. [TAG
Security researchers have long warned that supply chain, phishing, and infrastructure attacks have become a growing part of the cryptographic threat model as adoption by organizations increases. As such, Haruko's promised post-mortem report is important not only for its own customers. Key questions include: How are access tokens extracted? What exactly is available in process memory? Were the stolen read-only credentials used in subsequent attacks? Although the exposed API is described as read-only, how exactly did the reported fund losses occur? For institutional crypto companies, this incident has transformed API security, token processing and mandatory whitelisting from technical configuration choices to adversary risk issues.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC