HomeSecurityCrypto theft attacks linked to LastPass breach in 2022

Crypto theft attacks linked to LastPass breach in 2022

Blockchain research firm TRM Labs reports that ongoing cryptocurrency thefts have been linked to the 2022 LastPass breach, with attackers emptying wallets years after stealing encrypted vaults and laundering the cryptocurrencies through Russian exchanges.

See also: LastPass fined for 2022 data breach

LastPass

In 2022, LastPass revealed that attackers had breached its systems, breaching a development environment and stealing portions of the company's source code and proprietary technical information. In a later but related security incident, hackers breached cloud storage company GoTo using previously stolen credentials and stole backups of LastPass databases stored on the platform.

For some customers, these encrypted password vaults contained not only credentials but also cryptocurrency wallet private keys and seed phrases.

Although the vaults were encrypted, users with weak or reused master passwords were vulnerable to offline cracking, which is believed to continue since the breach. “Depending on the length and complexity of your master password and the number of attempts you have set, you may want to reset your master password,” LastPass warned when it disclosed the breach.

The connection between the LastPass breaches and cryptocurrency thefts was further confirmed by the U.S. Secret Service, which in 2025 seized more than $23 million in cryptocurrency and stated that the attackers had obtained the victims' private keys by decrypting vault data stolen in a password manager .

In court documents, agents said there was no evidence that the victims' devices had been compromised through phishing or malware and that they believed the theft was linked to the stolen password vaults.

See also: New Phishing attack with characters hidden in the subject line

Crypto theft attacks linked to LastPass breach in 2022

In a report published last week, TRM said that ongoing cryptocurrency theft attacks have been linked to the misuse of LastPass encrypted password vaults that were stolen in 2022. Rather than the wallet being emptied immediately after a breach, the thefts occurred in waves, months or years later, showing how attackers were gradually decrypting the vaults and extracting stored credentials.

The affected wallets were emptied using similar transaction methods, with no reports of a new attack, indicating that the attacker was in possession of the private keys prior to the thefts. “The link in the report is not based on a direct attribution to individual LastPass accounts, but rather on correlating on-chain activity with the known impact pattern of the 2022 breach,” TRM said.

TRM told BleepingComputer that its investigation was initially based on a small number of reports, including submissions to Chainabuse, in which users identified the LastPass breach as the method by which their wallets were stolen. The researchers expanded their investigation by tracking cryptocurrency trading behavior in other cases, linking the thefts to the LastPass data theft campaign.

TRM said the most important part of their research was the ability to detect stolen funds even after they were mixed using Wasabi Wallet ’s CoinJoin feature . CoinJoin is a Bitcoin privacy technique that combines transactions from multiple users into a single transaction, making it harder to determine which inputs correspond to which outputs.

Wasabi Wallet includes CoinJoin as a built-in feature, allowing users to automatically mix their Bitcoin with others to hide transactions without relying on a mixing service.

See also: 2025: Hackers stole 2.7 billion in crypto

Crypto theft attacks linked to LastPass breach in 2022

After emptying the wallets, the attackers converted the stolen cryptocurrencies into Bitcoin, funneled them through the Wasabi Wallet, and attempted to hide their tracks using CoinJoin transactions. However, TRM says it was able to “decrypt” the cryptocurrencies sent via CoinJoin transactions by analyzing behavioral characteristics such as transaction structure, timing, and wallet configuration options.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS