Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Haruko
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 448226197
- Off-chain at
- 2026-09-18T23:03:03.911Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- HcB4a9qTgL8j8cdrzLhgUZPaXQiPdcjwq6xMg2SqmuxQ
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (15765 chars)
{"actor":"system:backfill","investigation_id":"e3c2ffbe-d630-4133-ba9e-c7a1013ddc3a","kind":"publish","page_slug":"haruko","published_at":"2026-09-18T23:03:03.818Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Haruko","sections":[{"content":"Haruko is a London-based digital asset technology platform incorporated in March 2021. The company provides portfolio management, risk management, and trade-data infrastructure to institutional clients including hedge funds, trading firms, and asset managers. Its platform connects with over 100 centralized trading venues, more than 30 blockchains, and 250 on-chain protocols, offering clients a consolidated view of positions, transactions, and risk exposure across both centralized and decentralized venues. Named clients listed on Haruko's website include Bitcoin Suisse, GSR, Flowdesk, 3iQ Digital Assets, M2, Ampersan, MNNC Group (now Monarq Asset Management), and Trovio Asset Management. Haruko has offices in London and Singapore and, as of its July 2024 funding round, served over 50 investment management institutions. As of the date of the September 2026 incident, its client base had grown to over 80 globally.","heading":"Company Overview","severity":"low","sources":[{"credibility":1,"name":"Haruko official website","type":"official","url":"https://www.haruko.io/"},{"credibility":1,"name":"Haruko hack hits 15 crypto clients — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"},{"credibility":2,"name":"Haruko raises $6M Series A — Tech.eu","type":"news_article","url":"https://tech.eu/2024/07/15/digital-asset-management-platform-haruko-raises-6m-series-a/"}]},{"content":"Haruko has raised approximately $16 million in venture capital funding in total. Its most recent disclosed round was a $6 million Series A announced on July 15, 2024, co-led by White Star Capital's Digital Asset Fund and MMC Ventures. The round was accompanied by an announced expansion into Southeast Asia, with a new office opened in Singapore. Prior funding rounds account for the remaining approximately $10 million.","heading":"Funding and Investors","severity":"low","sources":[{"credibility":2,"name":"Haruko raises $6M Series A — Tech.eu","type":"news_article","url":"https://tech.eu/2024/07/15/digital-asset-management-platform-haruko-raises-6m-series-a/"},{"credibility":2,"name":"Haruko expands to Southeast Asia, secures $6M — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/haruko-expands-southeast-asia-6m-124500122.html"},{"credibility":1,"name":"Haruko official blog — $6M funding announcement","type":"official","url":"https://www.haruko.io/blog/haruko-raises-6m-to-eliminate-inefficiencies-in-digital-asset-management/"}]},{"content":"In September 2026, Haruko confirmed it was the target of a cyberattack that affected 15 of its institutional clients. According to co-founder and CTO Adam Carlile, who publicly confirmed the incident, attackers exploited a vulnerability in one of Haruko's internal server-side processes. This allowed them to extract a user-access token, which in turn provided access to information stored in that process's memory — including read-only exchange API credentials and trading data belonging to clients. Carlile described the attack as targeted and direct. Haruko subsequently patched the vulnerability, rotated server-side secrets, and advised affected clients to configure inbound IP whitelisting for maximum protection. The company committed to releasing a full technical post-mortem, though that report had not been published as of the date of initial reporting (September 18, 2026).","heading":"September 2026 Cyberattack","severity":"high","sources":[{"credibility":1,"name":"Haruko hack hits 15 crypto clients — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"},{"credibility":2,"name":"A Hacked Read-Only API at Haruko Just Cost Hedge Funds Real Money — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-hacked-read-only-api-at-haruko-just-cost-hedge-funds-real-money/"},{"credibility":2,"name":"Haruko Cyberattack Exposes API Data Across 15 Crypto Clients — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/haruko-cyberattack-exposes-api-data-across-15-crypto-clients/"},{"credibility":2,"name":"Haruko cyberattack exposes data of 15 clients, some funds lost — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/haruko-cyberattack-client-data-funds-lost/"}]},{"content":"Multiple reports noted that Haruko operates on bare-metal servers — dedicated physical machines used exclusively by the company — rather than cloud infrastructure such as Amazon Web Services. According to reporting by Startup Fortune and CoinDesk, this architectural choice meant that cloud-provider security controls, such as process isolation, managed secret storage, and hardware-level memory protection layers available through major cloud providers, were not present. Reporters noted that this reduced the number of barriers between a single exploited process and the access tokens held in its memory. Haruko has not publicly commented on whether it plans to change its infrastructure model in response to the incident.","heading":"Infrastructure Risk: Bare-Metal Servers","severity":"high","sources":[{"credibility":2,"name":"A Hacked Read-Only API at Haruko Just Cost Hedge Funds Real Money — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-hacked-read-only-api-at-haruko-just-cost-hedge-funds-real-money/"},{"credibility":1,"name":"Haruko hack hits 15 crypto clients — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"}]},{"content":"A small but confirmed amount of client funds was stolen in the incident. Haruko has not disclosed the specific dollar value of stolen funds. Reporting indicates that smaller hedge fund clients with weaker in-house security controls faced the greatest exposure. Even though the access tokens obtained were read-only — meaning they could not directly authorize withdrawals — reporting by Startup Fortune noted that this data still revealed fund holdings, trading positions, and strategies, and that some smaller clients may have had weaker secondary controls (such as unrevoked withdrawal permissions or non-rotated wallet addresses) that amplified the harm. The 15 affected clients were described by Haruko as its non-whitelisted clients — those who had not configured IP-address restrictions on their API access. Haruko serves over 80 clients globally, giving the potential blast radius of such an incident broad scope, though reported impact was limited to 15 clients.","heading":"Financial Impact and Client Exposure","severity":"high","sources":[{"credibility":1,"name":"Haruko hack hits 15 crypto clients — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"},{"credibility":2,"name":"A Hacked Read-Only API at Haruko Just Cost Hedge Funds Real Money — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-hacked-read-only-api-at-haruko-just-cost-hedge-funds-real-money/"},{"credibility":2,"name":"Crypto tech service provider Haruko hit by cyberattack — PANews","type":"news_article","url":"https://panews.io/articles/01a0b51f-f499-77f8-8071-d9563a3c409b"}]},{"content":"Haruko stated publicly that it fixed the exploited server-side vulnerability promptly after discovery and rotated all server-side secrets. It advised clients — particularly those not already using IP whitelisting — to enable inbound IP address restrictions on their API configurations for maximum protection. Co-founder and CTO Adam Carlile confirmed the breach directly, describing it as a targeted attack. Haruko committed to issuing a full technical post-mortem; as of the initial reporting date of September 18, 2026, that post-mortem had not yet been published. Haruko also advertises several security controls including role-based permissions, multi-factor authentication, single sign-on integration, and IP whitelisting; these controls did not prevent the breach affecting non-whitelisted clients.","heading":"Remediation and Company Response","severity":"medium","sources":[{"credibility":1,"name":"Haruko hack hits 15 crypto clients — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"},{"credibility":2,"name":"Haruko cyberattack exposes data of 15 clients, some funds lost — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/haruko-cyberattack-client-data-funds-lost/"},{"credibility":2,"name":"Haruko Cyberattack Exposes API Data Across 15 Crypto Clients — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/haruko-cyberattack-exposes-api-data-across-15-crypto-clients/"}]},{"content":"The Haruko breach occurred against a backdrop of record-high crypto hack frequency. TRM Labs reported that attackers carried out 207 crypto hacks in the first half of 2026, a record for any six-month period, though total losses of approximately $972 million represented less than half of the $2.3 billion stolen in the same period a year prior. TRM Labs noted that infrastructure and operational compromises, though representing roughly 15 percent of incidents, accounted for approximately 76 percent of total losses. The Haruko breach falls into the infrastructure-compromise category, illustrating the systemic risk that third-party infrastructure providers pose to institutional clients who aggregate credentials and data with a single vendor.","heading":"Industry Context","severity":"medium","sources":[{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":2,"name":"Haruko Cyberattack Exposes API Data Across 15 Crypto Clients — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/haruko-cyberattack-exposes-api-data-across-15-crypto-clients/"}]},{"content":"Haruko is headquartered in London. Its regulatory status with the UK's Financial Conduct Authority (FCA) has not been publicly confirmed or denied in available reporting at the time of this investigation. Crypto Briefing noted that as a London-based provider serving institutional clients, Haruko's breach is likely to attract FCA scrutiny; however, no formal regulatory inquiry or action had been announced as of September 18, 2026. No enforcement actions, court filings, or regulatory findings against Haruko have been identified in available records.","heading":"Regulatory Considerations","severity":"low","sources":[{"credibility":2,"name":"Haruko cyberattack exposes data of 15 clients, some funds lost — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/haruko-cyberattack-client-data-funds-lost/"}]}],"sources_used":[{"credibility":1,"name":"Haruko hack hits 15 crypto clients, with exchange API details, trading data and funds stolen — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"},{"credibility":2,"name":"Haruko cyberattack exposes data of 15 clients, some funds lost — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/haruko-cyberattack-client-data-funds-lost/"},{"credibility":2,"name":"A Hacked Read-Only API at Haruko Just Cost Hedge Funds Real Money — Startup Fortune","type":"news_article","url":"https://startupfortune.com/a-hacked-read-only-api-at-haruko-just-cost-hedge-funds-real-money/"},{"credibility":2,"name":"Haruko Cyberattack Exposes API Data Across 15 Crypto Clients — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/09/18/haruko-cyberattack-exposes-api-data-across-15-crypto-clients/"},{"credibility":2,"name":"Haruko, a London-based crypto tech provider, hit by targeted cyberattack affecting 15 clients — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/haruko-a-london-based-crypto-tech-provider-hit-by-targeted-cyberattack-affecting-15-clients"},{"credibility":2,"name":"Crypto tech service provider Haruko hit by cyberattack, 15 clients affected — PANews","type":"news_article","url":"https://panews.io/articles/01a0b51f-f499-77f8-8071-d9563a3c409b"},{"credibility":2,"name":"Haruko raises $6M Series A — Tech.eu","type":"news_article","url":"https://tech.eu/2024/07/15/digital-asset-management-platform-haruko-raises-6m-series-a/"},{"credibility":2,"name":"Haruko expands to Southeast Asia, secures $6M — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/news/haruko-expands-southeast-asia-6m-124500122.html"},{"credibility":1,"name":"Haruko official blog — $6M funding announcement","type":"official","url":"https://www.haruko.io/blog/haruko-raises-6m-to-eliminate-inefficiencies-in-digital-asset-management/"},{"credibility":2,"name":"H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion — TRM Labs","type":"research","url":"https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion"},{"credibility":1,"name":"Haruko official website","type":"official","url":"https://www.haruko.io/"}],"summary":"Haruko is a London-based institutional digital asset infrastructure provider founded in 2021, serving over 80 clients globally across 100+ centralized venues, 30 blockchains, and 250 on-chain protocols. In September 2026, the company confirmed a targeted cyberattack affecting 15 institutional clients, in which attackers exploited a server-side process vulnerability to extract access tokens and gain read-only API access to client data; a small but confirmed amount of client funds was stolen. Haruko stated it patched the vulnerability, rotated server-side secrets, and committed to publishing a technical post-mortem.","timeline":[{"date":"2021-03-01","event":"Haruko founded in London as a digital asset portfolio management and infrastructure platform.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/haruko-cyberattack-client-data-funds-lost/"},{"date":"2024-07-15","event":"Haruko announces $6 million Series A funding round co-led by White Star Capital and MMC Ventures, bringing total funding to approximately $16 million, and announces expansion into Southeast Asia with a Singapore office.","source":"Tech.eu","source_url":"https://tech.eu/2024/07/15/digital-asset-management-platform-haruko-raises-6m-series-a/"},{"date":"2026-09-18","event":"Haruko publicly confirms a targeted cyberattack affecting 15 institutional clients. Attackers exploited a server-side process vulnerability to extract access tokens, gaining read-only API access to client exchange credentials and trading data. A small but confirmed amount of client funds was stolen. Co-founder and CTO Adam Carlile states the vulnerability has been patched and server-side secrets rotated. A technical post-mortem is announced as forthcoming.","source":"CoinDesk","source_url":"https://www.coindesk.com/business/2026/09/18/crypto-tech-provider-haruko-hit-by-cyberattack-affecting-15-clients-some-funds-lost"}]},"v":1}