HomeSecurityLastPass: Previous breach allowed $4.4 million worth of crypto to be stolen

LastPass: Previous breach allowed theft of $4.4 million worth of crypto.

Hackers stole $4.4 million in crypto a few days ago, specifically on October 25th, using private keys and passphrases stored in stolen databases LastPass.

The news comes from ZachXBT and MetaMask developer Taylor Monahan, who have been tracking these crypto thefts.

LastPass breach crypto theft

We regularly see people reaching out via DM saying their crypto assets have been stolen. We also reach out to victims we discover on-chain,” ZachXBT told BleepingComputer.

According to a tweet by ZachXBT on X, attackers stole $4.4 million from 25+ victims due to a LastPass breach in 2022.

LastPass breach

In 2022, password manager service, LastPass, suffered two breaches that allowed attackers to steal source code, customer data, and backups stored in services that included encrypted password vaults.

See also: Crypto donation scams emerge amid Israel-Hamas war

The company's CEO, Karim Toubba, said at the time that despite the theft, only customers knew the master password required to decrypt the vaults. So the company had proposed some password security best practices thatwould ensure that customers' vaults remained secure.

However, LastPass warned that those using weaker passwords should reset their master password.

Depending on the length and complexity of your master password and iteration count setting, you may want to reset your master password,” a support ticket about the cyberattack said.

Weak passwords can be more easily cracked with special programs used by hackers.

LastPass: Previous breach allowed theft of $4.4 million worth of crypto.

However, according to new research conducted by Monahan and ZachXBT, it is believed that attackers are cracking these stolen password vaults to gain access to stored cryptocurrency wallet passphrases, credentials , and private keys.

Once they have access to this information, they can load the wallets onto their own devices and “empty” them.

See also: HTX: Crypto Exchange Lost $8 Million in Ether Due to Hack

According to a report by Brian Krebs about this research, Monahan and other researchers have created a unique signature that links the theft of over $35 million to the same threat.

At this point I am also confident that in most of these cases, the compromised keys were stolen from LastPass ,” Monahan tweeted in August .

The number of victims affected who had this particular set of seeds/keys stored in LastPass is simply too large to ignore.”.

It is becoming increasingly clear that the threat actors behind the attack have successfully cracked the passwords for the vaults and are using the stolen information for their attacks.

If you had a LastPass account during the August and December 2022 breaches, it is highly recommended that you reset all of your passwords.

LastPass: Previous breach allowed theft of $4.4 million worth of crypto.

Crypto theft

Sophisticated cyberattacks target digital wealth in a variety of ways. One of the main ways is through crypto theft. These cyberattacks typically target weak spots in the security of digital wallets and cryptocurrency exchanges.

See also: Xenomorph Android malware: Targets banking and crypto wallet users in the US

Attackers use a variety of techniques, such as fraud social engineering, exploiting weaknesses in system , and using stolen databases with valuable data, as was the case with LastPass.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS