Tag: Crypto infrastructure

  • Haruko Cyberattack Impacts 15 Clients, Causes Fund Losses for Crypto Tech Provider

    Haruko Cyberattack Impacts 15 Clients, Causes Fund Losses for Crypto Tech Provider

    Key Highlights:

    • Haruko, a London-based digital-asset infrastructure provider, suffered a security breach where an attacker exploited a process vulnerability to extract a user-access token and capture data from system memory.
    • A small amount of client funds and trading data were stolen, with smaller hedge funds described as particularly exposed due to weaker security controls.
    • GSR confirmed it was not impacted, while several other major firms including Bitcoin Suisse and Flowdesk did not respond to comment requests; client login credentials on their own systems were not compromised.

    Haruko Infrastructure Breach Exposes Institutional Crypto Clients

    A cyberattack targeting Haruko, a London-based firm providing portfolio, risk-management, and trade-data infrastructure to institutional digital-asset firms, has resulted in the theft of client funds and trading data. The company’s platform connects with centralized exchanges, custodians, blockchains, and decentralized-finance (DeFi) protocols, giving clients a consolidated view of their positions, transactions, and risk exposure. According to people familiar with the matter who spoke on condition of anonymity because the investigation is private, a small amount of client funds was stolen, and smaller hedge funds with weaker security controls may have been particularly exposed.

    Attack Vector and Data Compromise

    The attacker exploited a vulnerability in one of Haruko’s processes, extracting a user-access token and using it to capture data held in the process’s memory. That memory could have included read-only exchange API details and other data. Clients’ login credentials were not compromised on their own systems; instead, the access token was extracted through a vulnerability in Haruko’s infrastructure. Trading data was also taken during the intrusion.

    Industry Response and Exposure Assessment

    “GSR has not been impacted by any rumored breach,” a company spokesperson said. Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC, and Trovio did not reply to requests for comment before publication time. The incident underscores the persistent security challenges facing the crypto industry, where transactions are generally irreversible and platforms rely on digital credentials and signing systems that can give attackers direct access to assets.

    Why This Matters

    The Haruko breach highlights the systemic risk posed by infrastructure providers that aggregate access to multiple exchanges, custodians, and DeFi protocols. As institutional adoption of digital assets accelerates, the concentration of API credentials and trade data in centralized platforms creates high-value targets for attackers. The fact that smaller hedge funds with weaker security controls were particularly exposed suggests a tiered risk landscape where resource-constrained firms may suffer disproportionate harm. The incident also demonstrates how memory-resident data—such as read-only API keys—can be weaponized even when full login credentials remain secure, a nuance that may prompt reassessment of token rotation and memory-hardening practices across the sector.

    Frequently Asked Questions

    Was GSR affected by the Haruko breach?

    No. A GSR spokesperson explicitly stated: “GSR has not been impacted by any rumored breach.”

    Were client login credentials stolen from their own systems?

    No. According to messages from Haruko’s Carlile to clients, login credentials were not compromised on client systems. The access token was extracted through a vulnerability in Haruko’s own infrastructure.

    Which other firms were contacted regarding potential exposure?

    Bitcoin Suisse, Flowdesk, 3iQ, M2, Ampersan, MNNC, and Trovio were contacted for comment but did not reply before publication time.

  • Ray Zhang Wants Crypto Infrastructure to Become Safer Without Becoming Opaque

    Ray Zhang Wants Crypto Infrastructure to Become Safer Without Becoming Opaque

    Key Highlights

    • An Ellipsis Labs engineer contends that blockchain systems must establish clearer risk boundaries to protect users and build trust.
    • The engineer emphasizes the need for smoother onboarding processes to lower barriers to entry for mainstream adoption.
    • Financial tools built on blockchain should be designed so that users can actually understand them, rather than requiring specialized technical knowledge.

    Ellipsis Labs Engineer Outlines Three Pillars for Blockchain Usability

    An engineer at Ellipsis Labs has argued that the future viability of blockchain systems depends on addressing three fundamental usability gaps: clearer risk boundaries, smoother onboarding, and financial tools that users can genuinely comprehend. The critique targets persistent friction points that have limited mainstream adoption despite years of infrastructure development.

    Risk Boundaries and User Protection

    According to the engineer, current blockchain environments often expose participants to opaque risks — ranging from smart contract vulnerabilities to irreversible transaction errors — without adequate guardrails or transparent disclosures. The argument posits that defining and enforcing clearer risk boundaries is essential not only for consumer protection but also for establishing the institutional credibility required for broader financial integration.

    Onboarding as a Critical Bottleneck

    The engineer identifies onboarding as a primary bottleneck. Complex wallet setups, seed phrase management, gas fee mechanics, and network selection create a steep learning curve that deters non-technical users. Smoother onboarding, in this view, means abstracting away low-level complexity while preserving user sovereignty — a design challenge that many protocols have yet to solve convincingly.

    Comprehensible Financial Tools

    Beyond access, the engineer stresses that the financial primitives themselves — lending markets, derivatives, yield strategies — must be presented in terms that users can actually understand. This includes transparent risk disclosures, intuitive interfaces, and documentation that does not assume prior expertise in cryptography or game theory. The goal is to shift the user experience from “read the code” to “understand the product.”

    Why This Matters

    The remarks from Ellipsis Labs reflect a growing consensus among infrastructure builders that technical elegance alone is insufficient for mass adoption. As blockchain networks scale and intersect with traditional finance, regulatory scrutiny and user expectations are rising in tandem. Protocols that fail to address risk transparency, onboarding friction, and product comprehensibility risk remaining niche tools for a technical minority rather than becoming foundational rails for the global financial system. The engineer’s framework aligns with broader industry efforts — such as account abstraction, intent-based architectures, and standardized risk scoring — but underscores that these solutions must be evaluated against real-world usability, not just cryptographic soundness.

    Frequently Asked Questions

    Who made these arguments about blockchain usability?

    An engineer at Ellipsis Labs, a blockchain infrastructure and research team known for work on decentralized finance protocols and scaling solutions.

    What are the three specific improvements the engineer recommends?

    The engineer calls for clearer risk boundaries, smoother onboarding processes, and financial tools that users can actually understand.

    Why is this perspective significant for the blockchain industry?

    It highlights a shift in focus from pure technical performance to user-centric design as a prerequisite for mainstream adoption and regulatory acceptance.

  • The Next Trillion-Dollar Currency May Not Be a Stablecoin

    The Next Trillion-Dollar Currency May Not Be a Stablecoin

    A new CoinDesk analysis examines why the next trillion-dollar currency could emerge outside the stablecoin model used today—and why it may not have a name yet.

    What the CoinDesk Analysis Says

    The development is significant because it could alter the outlook for the next trillion-dollar currency. However, the available reporting identifies a specific development without establishing that it represents a completed, industry-wide shift.

    The figures and descriptions remain limited to the scope and claims presented in the source. Further evidence is needed before drawing broader conclusions about the digital-asset market.

    Why It Matters for Digital Assets

    Crypto infrastructure is increasingly linking payments, financial markets and software systems. These connections may create new opportunities for adoption, while also raising questions about security, regulation, liquidity and operational reliability.

    Those factors will help determine whether the reported development advances beyond an initial test, study or proposal. They will also indicate whether the system can support broader participation from users and institutions.

    What Comes Next

    The key milestones will be additional disclosures, implementation details and evidence of adoption by users or institutions. Until those details emerge, the development should be viewed as a dated event rather than a prediction about market prices or a guarantee of future adoption.

    BlockchainReporter has previously covered related digital-asset infrastructure in earlier reporting.

    Source: cryptonews.net