{"investigation":{"slug":"lastpass","entity_name":"LastPass","trust_score":12,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"LastPass is a widely used password manager that suffered a catastrophic two-stage data breach in 2022, resulting in the theft of encrypted customer password vaults containing cryptocurrency seed phrases and private keys. Threat actors subsequently cracked these vaults offline over the following years, draining crypto wallets in waves totaling more than $438 million across hundreds of victims by late 2025. The breach has led to a £1.2 million UK ICO regulatory fine, a $24.45 million US class action settlement, US federal seizures, and on-chain attribution by TRM Labs and blockchain researcher ZachXBT to Russian cybercriminal infrastructure.","sections":[{"content":"LastPass suffered a two-phase intrusion in 2022. In the first phase, between August 8–11, 2022, an attacker compromised a software developer's corporate laptop and exfiltrated 14 source code repositories along with proprietary technical documentation. LastPass disclosed this incident on August 25, 2022, initially asserting no customer data had been accessed. In the second phase, between September 8–22, 2022, attackers used credentials stolen from one of four senior DevOps engineers to access AWS S3 cloud storage. They exfiltrated a backup of customer vault data containing both unencrypted metadata (website URLs, usernames, email addresses, phone numbers) and AES-256 encrypted fields (passwords, secure notes, seed phrases, private keys). LastPass publicly disclosed the full scope of the second breach on November 30, 2022. The UK Information Commissioner's Office (ICO) later determined that the attacker implanted malware on a senior employee's personal laptop and captured that employee's master password, enabling decryption of the corporate vault and subsequent access to the backup database. The ICO concluded that LastPass's permissive personal device usage policy and the linking of personal and business accounts were material contributing factors.","heading":"The 2022 Data Breach","sources":[],"severity":"medium"},{"content":"The theft of encrypted vault backups enabled a prolonged, multi-year campaign of cryptocurrency theft as attackers cracked weak master passwords offline using brute force. Any vault protected by a master password that did not meet strong entropy requirements could eventually be decrypted, giving attackers full access to stored seed phrases and private keys. Security researcher ZachXBT was among the first to publicly link these thefts to the LastPass breach, documenting multiple distinct theft waves. In October 2023, approximately $4.4 million was stolen. In February 2024, a further $6.2 million was drained. On December 16–17, 2024, ZachXBT reported that attackers drained more than $5.4 million from over 40 victim addresses, with stolen funds swapped for Ethereum and then converted to Bitcoin via instant exchanges. Around the same period, ZachXBT documented a separate incident in which more than $12.38 million was stolen from over 100 wallet addresses within hours. TRM Labs, in a December 2025 analysis, concluded total documented losses attributable to the breach exceeded $438 million, with the firm noting this figure likely represents only a fraction of the full impact. Bleeping Computer and other outlets corroborated losses exceeding $250 million by mid-2024.","heading":"Cryptocurrency Theft: Multi-Year Wave Attacks","sources":[],"severity":"medium"},{"content":"On January 30, 2024, approximately 283 million XRP — worth roughly $150 million at the time — was stolen from wallets belonging to Chris Larsen, co-founder of Ripple. ZachXBT was the first to publicly attribute this theft to the LastPass breach, posting his findings to Telegram. A subsequently unsealed US Department of Justice forfeiture complaint confirmed the attribution: US Secret Service agents investigating the case concluded that the theft 'was the result of storing private keys in LastPass (password manager which was hacked in 2022).' The complaint noted that Larsen had stored his private keys in LastPass's Secure Notes feature prior to the breach. Law enforcement traced approximately $23.6 million of the stolen XRP across multiple exchanges including OKX, Kraken (Payward Interactive), WhiteBIT, AscendEX, FixedFloat, SwapSpace, and CoinRabbit. On March 6, 2025, federal prosecutors in the Northern District of California seized approximately $23–24 million in cryptocurrency linked to the theft. The FBI and US Secret Service jointly investigated the case.","heading":"Chris Larsen / Ripple XRP Theft ($150 Million)","sources":[],"severity":"medium"},{"content":"TRM Labs conducted an extensive on-chain investigation published in December 2025, tracing the laundering pipelines used by the attackers. TRM identified a consistent on-chain signature across the theft waves: non-Bitcoin assets were rapidly converted to Bitcoin via instant swap services; funds were then transferred to single-use addresses and deposited into Wasabi Wallet using the CoinJoin protocol to obfuscate the money trail. TRM employed proprietary demixing techniques to re-identify withdrawal clusters from Wasabi Wallet whose aggregate value and timing statistically matched attacker inflows. In an earlier laundering phase, stolen funds were routed through the now-defunct Cryptomixer.io and off-ramped via Cryptex, a Russia-based cryptocurrency exchange sanctioned by the US Treasury's OFAC in 2024 for facilitating ransomware payments. In a September 2025 wave, approximately $7 million in additional stolen assets was traced through Wasabi Wallet to Audi6, a Russian exchange also associated with cybercriminal activity. TRM estimated that more than $28 million was laundered through Wasabi Wallet between late 2024 and early 2025 alone. The on-chain indicators — including SegWit transaction formatting, Replace-by-Fee usage, and exchange off-ramp patterns — led TRM to conclude with moderate-to-high confidence that Russian cybercriminals were responsible for at least a significant portion of the thefts.","heading":"On-Chain Attribution: Russian Cybercriminal Infrastructure","sources":[],"severity":"medium"},{"content":"On November 20, 2025, the UK Information Commissioner's Office (ICO) issued a £1.23 million monetary penalty to LastPass UK Ltd for violations of Article 5(1)(f) and Article 32(1) of the UK GDPR arising from the 2022 breach. The ICO found that LastPass had failed to implement sufficiently robust technical and organizational security measures. Specific findings included: the company's permissive policy allowing employees to link personal and business accounts in the password manager; inadequate restrictions on personal device usage for corporate access; and the failure to require separate master passwords for personal and business vaults. The ICO determined that approximately 1.6 million UK customers had their personal information compromised, including names, email addresses, phone numbers, and billing information. The fine was widely criticized by security researchers as disproportionately small relative to the scale of downstream cryptocurrency losses ($438 million) attributable to the breach.","heading":"UK ICO Regulatory Fine","sources":[],"severity":"medium"},{"content":"LastPass faced multiple class action lawsuits in the United States following the 2022 breach. LastPass US LP agreed to a settlement of up to $24,450,000 to resolve consumer claims related to the breach. The settlement received preliminary court approval on February 2, 2026. Under the settlement terms, victims of identity theft can claim up to $10,000 in documented losses; victims with documented cryptocurrency losses can access payouts from a separate $16.25 million fund; California residents are entitled to a $100 statutory payment; and all class members may claim a $25 flat payment. The claims deadline is July 2, 2026, with a final approval hearing scheduled for July 14, 2026 and disbursement expected in September–October 2026. Separate class action proceedings were also initiated in Canada. Bloomberg Law reported the settlement agreement in November 2025.","heading":"Class Action Lawsuits and Settlement","sources":[],"severity":"medium"},{"content":"Blockchain researcher ZachXBT played a pivotal investigative role in publicly linking multiple waves of cryptocurrency theft to the LastPass breach. ZachXBT was the first to publicly identify Chris Larsen as the victim of the $150 million XRP theft and to attribute it to the LastPass breach via on-chain analysis posted to Telegram. He documented the October 2023 ($4.4 million), February 2024 ($6.2 million), and December 2024 ($5.4 million from 40+ addresses; $12.38 million from 100+ addresses) theft waves. ZachXBT shared lists of affected wallet addresses — spanning Bitcoin, Ethereum, and Avalanche — with his Telegram followers, enabling victims to self-identify exposure. His findings preceded formal law enforcement actions and corroborated subsequent federal forfeiture complaints. AVOID.NET has flagged LastPass based on ZachXBT's repeated documented attribution of ongoing crypto theft to this entity's security failures.","heading":"ZachXBT Investigations and Flagging","sources":[],"severity":"medium"}],"timeline":[{"date":"2022-08-08","event":"First intrusion: attacker compromises LastPass developer's corporate laptop, exfiltrates source code and technical documentation over four days.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/cryptocurrency-theft-attacks-traced-to-2022-lastpass-breach/"},{"date":"2022-08-25","event":"LastPass CEO Karim Toubba publicly discloses the August breach, claiming no customer data was accessed.","source":"","source_url":"https://blog.lastpass.com/posts/notice-of-recent-security-incident"},{"date":"2022-09-08","event":"Second intrusion begins: attackers use stolen credentials from a senior DevOps engineer to access AWS S3 cloud storage.","source":"","source_url":"https://en.wikipedia.org/wiki/2022_LastPass_data_breach"},{"date":"2022-09-22","event":"Second intrusion ends; attackers have exfiltrated a backup of customer vault data including encrypted seed phrases and private keys.","source":"","source_url":"https://en.wikipedia.org/wiki/2022_LastPass_data_breach"},{"date":"2022-11-30","event":"LastPass publicly discloses the full scope of the breach, acknowledging that encrypted customer password vaults were stolen.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/cryptocurrency-theft-attacks-traced-to-2022-lastpass-breach/"},{"date":"2023-09-15","event":"KrebsOnSecurity publishes security researcher findings concluding that a series of six-figure crypto heists across dozens of victims resulted from cracked LastPass master passwords.","source":"","source_url":"https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/"},{"date":"2023-10","event":"ZachXBT documents approximately $4.4 million stolen from LastPass breach victims in October 2023.","source":"","source_url":"https://www.bankinfosecurity.com/crypto-roundup-lastpass-breach-linked-to-54m-crypto-theft-a-27109","date_original":"2023-10-01"},{"date":"2024-01-30","event":"Ripple co-founder Chris Larsen has approximately 283 million XRP (~$150 million) stolen from wallets whose private keys were stored in LastPass.","source":"","source_url":"https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/"},{"date":"2024-02","event":"ZachXBT is first to publicly attribute the Larsen XRP theft to the LastPass breach via Telegram. ZachXBT documents a separate $6.2 million theft wave in February 2024.","source":"","source_url":"https://www.theblock.co/post/345212/ripple-co-founder-chris-larsen-losing-over-100-million-of-xrp-tied-to-lastpass-hack-says-zachxbt","date_original":"2024-02-01"},{"date":"2024-06","event":"Law enforcement begins tracing $23.6 million of Larsen's stolen XRP across OKX, Kraken, WhiteBIT, AscendEX, FixedFloat, SwapSpace, and CoinRabbit.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/","date_original":"2024-06-01"},{"date":"2024-12-16","event":"ZachXBT reports $5.4 million stolen from over 40 victim addresses on December 16–17; funds swapped for ETH then converted to Bitcoin via instant exchanges.","source":"","source_url":"https://www.theblock.co/post/331118/lastpass-threat-actor-drains-5-4-million-in-crypto-from-over-40-victim-addresses-zachxbt"},{"date":"2024-12-17","event":"ZachXBT reports a separate theft of $12.38 million from more than 100 wallet addresses (Bitcoin, Ethereum, Avalanche) within hours.","source":"","source_url":"https://bitcoinethereumnews.com/crypto/zachxbt-ties-12-38-million-crypto-drain-to-lastpass-breach-100-victimized-wallets/"},{"date":"2025-03-06","event":"US federal prosecutors in the Northern District of California seize approximately $23–24 million in cryptocurrency linked to the Larsen XRP theft. DOJ forfeiture complaint unsealed confirms LastPass breach as root cause.","source":"","source_url":"https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/"},{"date":"2025-09","event":"TRM Labs identifies a new September 2025 wave of approximately $7 million in additional thefts laundered through Wasabi Wallet to Russian exchange Audi6.","source":"","source_url":"https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement","date_original":"2025-09-01"},{"date":"2025-11-20","event":"UK ICO issues £1.23 million monetary penalty against LastPass UK Ltd for UK GDPR violations arising from the 2022 breach, citing inadequate technical security measures affecting 1.6 million UK users.","source":"","source_url":"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/password-manager-provider-fined/"},{"date":"2025-12","event":"TRM Labs publishes comprehensive on-chain investigation concluding total cryptocurrency losses attributable to the LastPass breach exceed $438 million, with laundering traced to Russian exchanges Cryptex (OFAC-sanctioned) and Audi6 via Wasabi Wallet CoinJoin.","source":"","source_url":"https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement","date_original":"2025-12-01"},{"date":"2026-02-02","event":"US court grants preliminary approval to $24.45 million class action settlement covering LastPass breach victims, with a $16.25 million sub-fund for cryptocurrency loss claims.","source":"","source_url":"https://www.classaction.org/news/8.2m-lastpass-settlement-ends-class-action-lawsuit-over-2022-data-breach"}],"sources_used":[],"source_tags":["etherscan","zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:56.939665+00:00","updated_at":"2026-08-29T01:35:55.029+00:00"}}