{"investigation":{"slug":"lastpass-threat-actor","entity_name":"LastPass threat actor","trust_score":0,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"An unidentified threat actor or group breached LastPass in August–November 2022, exfiltrating encrypted customer password vaults containing cryptocurrency seed phrases and private keys stored by an estimated 25–30 million users. Beginning in late 2022 and continuing at least through late 2025, the actors allegedly cracked weak master passwords offline and drained cryptocurrency wallets in coordinated waves, with documented losses exceeding $250 million across hundreds of victims and a single high-profile $150 million XRP theft attributed to Ripple co-founder Chris Larsen. TRM Labs on-chain analysis and law enforcement investigations link the laundering activity to Russian cybercriminal infrastructure, including OFAC-sanctioned exchange Cryptex.","sections":[{"content":"LastPass suffered two related intrusions in 2022. The first, occurring between August 8–11, 2022, saw a threat actor compromise the laptop of a software developer, downloading 14 source code repositories, technical documentation, and an encrypted AWS S3 SSE-C key.\n\nThe second, more consequential intrusion targeted one of four senior DevOps engineers who held decryption keys for the company's production database backups. The attacker gained initial access to the engineer's personal home computer by exploiting CVE-2020-5741, a remote code execution vulnerability in Plex Media Server that had been publicly disclosed in May 2020 but was never patched by the employee — approximately 75 software versions out of date. The attacker installed keylogger malware on the engineer's personal computer, capturing the master password after the employee authenticated via MFA.\n\nUsing the engineer's corporate vault credentials, the threat actor exported native vault entries and shared folder contents containing AWS S3 access and decryption keys. This enabled persistent access to LastPass cloud storage for over two months — from approximately August 12 to October 26, 2022 — during which encrypted customer vault backups, metadata (including unencrypted website URLs, usernames, and email addresses) belonging to an estimated 25–30 million users were exfiltrated. LastPass formally disclosed the full scope of the vault theft in December 2022.","heading":"The 2022 LastPass Breach","sources":[],"severity":"medium"},{"content":"The stolen customer vaults included cryptocurrency private keys and seed phrases stored by users in LastPass's 'Secure Notes' feature. Because the vaults were encrypted with each user's master password, the attacker could conduct offline brute-force or dictionary attacks against weak or reused master passwords without time pressure.\n\nBeginning in late December 2022, security researcher Taylor Monahan (lead product manager at MetaMask) began documenting an unusual pattern of cryptocurrency thefts. By August 28, 2023, after tracking more than 150 victims who collectively lost over $35 million, Monahan concluded that the common thread connecting nearly all victims was prior use of LastPass to store seed phrases. Victims were described as 'reasonably secure' individuals — crypto company employees, venture capitalists, and protocol developers — who showed none of the typical precursors to high-dollar crypto theft such as email compromise or SIM-swapping.\n\nZachXBT, an independent on-chain investigator, has reported on multiple distinct waves of theft linked to the breach:\n- **October 25, 2023**: Approximately $4.4 million drained from more than 25 victim addresses in a single day.\n- **February 2024**: Over $6.2 million stolen from LastPass users.\n- **January 30, 2024**: $150 million in XRP allegedly stolen from personal accounts of Ripple co-founder Chris Larsen (see separate section).\n- **December 2024**: Approximately $5.36 million drained from over 40 victim addresses, with stolen funds swapped to ETH and then converted to Bitcoin via instant exchange services.\n\nBy May 2024, estimated total losses linked to the breach exceeded $250 million. TRM Labs, in a December 2025 report, traced over $35 million through Wasabi Wallet alone, noting this was likely only a fraction of total losses.","heading":"Cryptocurrency Wallet Drain Campaign","sources":[],"severity":"medium"},{"content":"TRM Labs conducted detailed on-chain analysis of the theft campaign and identified a consistent laundering signature across multiple theft waves:\n\n1. **Wallet import**: Stolen Bitcoin private keys were imported into the same wallet software, producing shared transaction traits including SegWit usage and Replace-by-Fee signaling.\n2. **Asset consolidation**: Non-Bitcoin assets were converted to Bitcoin via instant swap services.\n3. **CoinJoin mixing via Wasabi Wallet**: Funds were deposited into single-use addresses before being routed through Wasabi Wallet, which uses CoinJoin — a Bitcoin privacy technique that combines multiple users' transactions to obscure the source-to-destination mapping.\n4. **Peeling chains**: Post-withdrawal, funds were further obfuscated through peeling chain transactions.\n5. **Russian exchange off-ramps**: Laundered Bitcoin converged at high-risk Russian exchanges.\n\nDespite the CoinJoin mixing, TRM was able to 'demix' transactions using cluster-based behavioral analysis — matching transaction structure, timing, wallet configuration, and amount patterns across coordinated campaigns rather than treating each theft in isolation.\n\nIn an earlier phase of exploitation (2022–2023), stolen funds were routed through the now-defunct Cryptomixer.io and cashed out via Cryptex, a Russia-based exchange subsequently sanctioned by OFAC in 2024. In later 2024–2025 waves, funds were routed through Wasabi Wallet and off-ramped via Audi6, another Russian exchange associated with cybercriminal activity.\n\nThe DOJ forfeiture complaint (March 2025) identified the following exchanges as receiving traced stolen funds in the Larsen-linked theft: FixedFloat (Ftrader Ltd), OKX, Kraken, WhiteBIT, AscendEX, SwapSpace, and CoinRabbit.","heading":"On-Chain Laundering Methodology","sources":[],"severity":"medium"},{"content":"On January 30, 2024, approximately 283 million XRP — valued at approximately $150 million at the time — was stolen from personal cryptocurrency accounts belonging to Chris Larsen, co-founder of Ripple. ZachXBT initially flagged the theft on January 31, 2024.\n\nOn March 6, 2025, federal prosecutors in the Northern District of California unsealed a civil forfeiture complaint and announced the seizure of $23,604,815.09 in cryptocurrency. The complaint stated that attackers 'stole the cryptocurrency using private keys extracted by cracking the victim's password vault stolen in a 2022 breach,' and that 'no evidence that the victim's devices were hacked' was found — indicating the wallet was accessed solely through decrypted password manager credentials. The complaint further noted that 'the scale of a theft and rapid dissipation of funds would have required the efforts of multiple malicious actors,' consistent with a coordinated criminal group.\n\nLastPass has disputed the connection, stating it has 'seen no definitive proof — from federal investigators or others — that the cyberheists in question were linked to the LastPass breaches.' However, federal law enforcement documents have explicitly cited the password manager breach as the attack vector.\n\nTraced stolen funds were linked to exchanges including FixedFloat, OKX, Kraken, WhiteBIT, AscendEX, SwapSpace, and CoinRabbit.","heading":"Chris Larsen / Ripple XRP Theft and DOJ Seizure","sources":[],"severity":"medium"},{"content":"TRM Labs, in its December 2025 report, assessed that on-chain evidence is 'consistent with involvement by Russian cybercriminal actors.' The assessment is based on:\n\n- **Repeated interaction with Russia-associated exchange infrastructure**: Stolen funds repeatedly flowed to Cryptex (OFAC-sanctioned in 2024) and Audi6, both historically linked to Russian cybercriminal activity.\n- **Continuity of control**: TRM identified continuity of wallet control across pre- and post-mix activity, suggesting a single organized group rather than opportunistic thieves.\n- **Consistent off-ramp selection**: The same Russian exchange infrastructure was used across multiple theft waves spanning 2022–2025.\n- **Cryptomixer.io usage**: Funds were routed through Cryptomixer.io (now defunct) in early exploitation phases before pivoting to Wasabi Wallet.\n\nAs of the date of this report, no specific individuals have been publicly charged in connection with the breach or the resulting crypto theft campaign. Definitive attribution of the original 2022 intrusion remains unconfirmed by public law enforcement statements. The involvement of multiple actors, suggested by both the scale of theft and complexity of laundering operations, is consistent with an organized cybercriminal group rather than a lone actor.","heading":"Russian Cybercriminal Attribution","sources":[],"severity":"medium"},{"content":"**UK ICO Penalty (November 2025)**: The UK Information Commissioner's Office issued a £1,228,283 penalty to LastPass UK Limited on November 20, 2025, for violations of Article 5(1)(f) and Article 32(1) of the UK GDPR. The ICO found that LastPass had failed to implement appropriate technical and organizational security measures, specifically permitting senior employees with access to highly confidential corporate credentials to access their accounts from unmanaged personal devices.\n\n**US Civil Forfeiture (March 2025)**: Federal prosecutors in the Northern District of California seized $23,604,815.09 in cryptocurrency via civil forfeiture complaint linked to the Larsen theft, explicitly citing the 2022 LastPass breach as the attack vector.\n\n**Class Action Settlement**: LastPass agreed to pay up to $24,450,000 to resolve a US consumer class action lawsuit. The settlement includes an $8.2 million general cash fund and a separate $16.25 million fund for victims whose cryptocurrency was stolen using private keys stored in LastPass. Claims are open through July 2, 2026, with a final approval hearing scheduled for July 14, 2026. A Canadian class action settlement has also been approved by the Supreme Court of British Columbia.","heading":"Regulatory and Legal Actions","sources":[],"severity":"medium"},{"content":"The LastPass threat actor campaign is notable for its multi-year duration. Unlike typical exchange hacks where stolen funds are laundered quickly, this threat actor's strategy involved the patient offline decryption of stolen vaults, creating an extended window of exploitation that continued at least through late 2025 — more than three years after the initial breach.\n\nKey scope estimates:\n- **~25–30 million**: Estimated number of customer vaults exfiltrated.\n- **150+**: Minimum number of individual crypto theft victims identified by researcher Taylor Monahan through mid-2023.\n- **$250M+**: Estimated total crypto losses connected to the breach as of May 2024 (Taylor Monahan estimate).\n- **$35M+**: Amount traced by TRM Labs through Wasabi Wallet alone (December 2025).\n- **$150M**: Single largest documented theft, attributed to Ripple co-founder Chris Larsen (January 2024).\n- **$23.6M**: Amount seized by US federal authorities (March 2025).\n- **$438M+**: Figure cited in UK ICO penalty documentation as documented cryptocurrency devastation.\n\nAny user who stored cryptocurrency seed phrases or private keys in LastPass 'Secure Notes' prior to December 2022 and used a weak or reused master password should consider their stored keys compromised. The offline nature of vault cracking means exposure is ongoing for any vault not yet decrypted.","heading":"Scope and Ongoing Nature of Threat","sources":[],"severity":"medium"}],"timeline":[{"date":"2022-08-08","event":"Threat actor compromises LastPass developer laptop, exfiltrating 14 source code repositories, technical documentation, and an encrypted AWS S3 key.","source":"","source_url":"https://en.wikipedia.org/wiki/2022_LastPass_data_breach"},{"date":"2022-08-12","event":"Second intrusion begins: threat actor exploits unpatched Plex CVE-2020-5741 on DevOps engineer's home computer, installing keylogger malware to capture master password and gain access to corporate vault.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach/"},{"date":"2022-10-26","event":"LastPass detects and terminates threat actor's persistent cloud storage access, which had lasted approximately 75 days.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/lastpass-devops-engineer-hacked-to-steal-password-vault-data-in-2022-breach/"},{"date":"2022-12-22","event":"LastPass publicly discloses that encrypted customer password vaults and associated metadata were stolen in the August–November breach.","source":"","source_url":"https://en.wikipedia.org/wiki/2022_LastPass_data_breach"},{"date":"2023-03","event":"Taylor Monahan (MetaMask) begins tracking unusual cryptocurrency theft pattern affecting crypto-native individuals, later linked to LastPass.","source":"","source_url":"https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/","date_original":"2023-03-01"},{"date":"2023-08-28","event":"Taylor Monahan concludes that nearly all theft victims had stored cryptocurrency seed phrases in LastPass, publicly linking the theft campaign to the 2022 breach.","source":"","source_url":"https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/"},{"date":"2023-10-25","event":"Approximately $4.4 million drained from 25+ victim addresses in a single day, reported by ZachXBT.","source":"","source_url":"https://cointelegraph.com/news/lastpass-breach-hacker-steals-millions-crypto-wallets-zachxbt"},{"date":"2024-01-30","event":"$150 million in XRP stolen from personal cryptocurrency accounts of Ripple co-founder Chris Larsen, later attributed to LastPass breach.","source":"","source_url":"https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/"},{"date":"2024-02","event":"Over $6.2 million stolen from additional LastPass users in a new theft wave, tracked by ZachXBT.","source":"","source_url":"https://cryptoslate.com/hackers-steal-6-2-million-in-digital-assets-from-lastpass-users-investigators-track-stolen-funds/","date_original":"2024-02-01"},{"date":"2024-05","event":"Estimated total crypto losses linked to LastPass breach exceed $250 million, per researcher Taylor Monahan.","source":"","source_url":"https://cryptoslate.com/lastpass-linked-crypto-theft-climbs-to-over-250-million-after-latest-5-4-million-hit/","date_original":"2024-05-01"},{"date":"2024-09-26","event":"OFAC sanctions Cryptex, the Russia-based exchange used as an off-ramp for LastPass-linked stolen funds.","source":"","source_url":"https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement"},{"date":"2024-12-18","event":"ZachXBT reports $5.36 million drained from over 40 victim addresses, with funds swapped to ETH and converted to Bitcoin via instant exchange services.","source":"","source_url":"https://www.theblock.co/post/331118/lastpass-threat-actor-drains-5-4-million-in-crypto-from-over-40-victim-addresses-zachxbt"},{"date":"2025-03-06","event":"Federal prosecutors in Northern California seize $23,604,815 in cryptocurrency via civil forfeiture complaint, explicitly linking the Larsen theft to the 2022 LastPass breach.","source":"","source_url":"https://www.bleepingcomputer.com/news/security/us-seizes-23-million-in-crypto-stolen-via-password-manager-breach/"},{"date":"2025-11-20","event":"UK Information Commissioner's Office issues £1,228,283 penalty to LastPass UK Limited for GDPR violations stemming from the 2022 breach.","source":"","source_url":"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/12/password-manager-provider-fined/"},{"date":"2025-12","event":"TRM Labs publishes report tracing over $35 million through Wasabi Wallet laundering pipeline, with on-chain indicators suggesting Russian cybercriminal involvement. Theft activity traced as recently as October 2025.","source":"","source_url":"https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement","date_original":"2025-12-01"}],"sources_used":[],"source_tags":["etherscan","zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:04:57.32267+00:00","updated_at":"2026-08-29T01:35:55.335+00:00"}}