Crypto Tech Provider Haruko Hit by Cyberattack, Client Assets Stolen

The420.in Staff
5 Min Read

Crypto tech provider Haruko has suffered a cyberattack that affected 15 clients and resulted in the theft of digital assets after attackers compromised credentials stored in a third-party password manager.

The attack did not directly breach Haruko’s core platform. Instead, the attackers used stolen credentials to gain access to client environments, showing how a compromise at an external service can create a path into connected cryptocurrency systems.

What Happened to Haruko?

Haruko detected suspicious activity involving several client environments and began investigating the incident. The company brought in external cybersecurity specialists to determine how the attackers had gained access and how widely the breach had spread.

The investigation traced the initial compromise to a third-party password manager used to store credentials. Attackers were able to obtain credentials from the service and later use them against Haruko client environments.

The incident affected 15 clients and led to the theft of digital assets.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

How Did Hackers Get Access?

The attackers did not need to directly break into Haruko’s main platform. Instead, they compromised the external password-management service and obtained credentials that could be used to access connected environments.

Once those credentials were available, the attackers could use legitimate access paths rather than relying solely on a conventional direct attack against Haruko’s central infrastructure.

This made the third-party service an important part of the attack chain.

Was Haruko’s Platform Hacked?

Haruko said its investigation found no evidence that its core platform had been compromised.

The distinction is important because the incident involved credentials associated with an outside service rather than a direct breach of Haruko’s principal platform. However, the stolen credentials still gave the attackers a route to environments connected with affected clients.

Haruko continued examining its infrastructure and access controls after discovering the attack.

How Were 15 Clients Affected?

The cyberattack affected 15 Haruko clients. Attackers used compromised credentials to gain access to client environments and steal digital assets.

Haruko began working with affected clients after detecting the incident. Investigators also examined the movement of stolen assets and the methods used by the attackers.

The attack was limited to a section of Haruko’s client base rather than affecting every customer.

What Did Haruko Do Next?

Haruko moved to contain the incident after discovering the suspicious activity and began reviewing the credentials and systems that could have been exposed.

External cybersecurity specialists were involved in investigating the attack. The company also reviewed access controls and introduced additional security measures intended to reduce the risk of similar attacks.

The investigation included determining which credentials had been exposed, how they were subsequently used and which client environments had been affected.

Why Does This Attack Matter?

The attack demonstrates how a company can face a serious security incident even when its main platform is not directly compromised.

A third-party tool holding sensitive credentials can become another route for attackers. If those credentials provide access to important systems, compromising the external service can allow criminals to move further into connected environments.

For companies dealing with cryptocurrency and other digital assets, the incident highlights the importance of controlling privileged credentials and reviewing the security of third-party services that can provide access to sensitive infrastructure.

The420 Crypto Security Watch

The Haruko attack shows that protecting a core platform alone may not be enough. Credentials stored with third-party services can provide another route into sensitive systems, making access controls, credential protection and third-party security important parts of safeguarding digital assets.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected