One breach hit all 15 Haruko clients.

Each fund’s own security no longer matters if it shares a vendor.

Haruko holds clients’ exchange access keys on physical servers instead of cloud security controls.

Haruko has patched the flaw, but some smaller clients still lost assets.

Sources: CoinDesk