LastPass threat actor
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3NaYSH…hCrdSummary
An unidentified threat actor or group breached LastPass in August–November 2022, exfiltrating encrypted customer password vaults containing cryptocurrency seed phrases and private keys stored by an estimated 25–30 million users. Beginning in late 2022 and continuing at least through late 2025, the actors allegedly cracked weak master passwords offline and drained cryptocurrency wallets in coordinated waves, with documented losses exceeding $250 million across hundreds of victims and a single high-profile $150 million XRP theft attributed to Ripple co-founder Chris Larsen. TRM Labs on-chain analysis and law enforcement investigations link the laundering activity to Russian cybercriminal infrastructure, including OFAC-sanctioned exchange Cryptex.
Connected Entities
1 entities- + 5 more
Timeline(15 events)
8 August 2022
Threat actor compromises LastPass developer laptop, exfiltrating 14 source code repositories, technical documentation, and an encrypted AWS S3 key.
12 August 2022
Second intrusion begins: threat actor exploits unpatched Plex CVE-2020-5741 on DevOps engineer's home computer, installing keylogger malware to capture master password and gain access to corporate vault.
26 October 2022
LastPass detects and terminates threat actor's persistent cloud storage access, which had lasted approximately 75 days.
22 December 2022
LastPass publicly discloses that encrypted customer password vaults and associated metadata were stolen in the August–November breach.
March 2023
Taylor Monahan (MetaMask) begins tracking unusual cryptocurrency theft pattern affecting crypto-native individuals, later linked to LastPass.
28 August 2023
Taylor Monahan concludes that nearly all theft victims had stored cryptocurrency seed phrases in LastPass, publicly linking the theft campaign to the 2022 breach.
25 October 2023
Approximately $4.4 million drained from 25+ victim addresses in a single day, reported by ZachXBT.
30 January 2024
$150 million in XRP stolen from personal cryptocurrency accounts of Ripple co-founder Chris Larsen, later attributed to LastPass breach.
February 2024
Over $6.2 million stolen from additional LastPass users in a new theft wave, tracked by ZachXBT.
May 2024
Estimated total crypto losses linked to LastPass breach exceed $250 million, per researcher Taylor Monahan.
26 September 2024
OFAC sanctions Cryptex, the Russia-based exchange used as an off-ramp for LastPass-linked stolen funds.
18 December 2024
ZachXBT reports $5.36 million drained from over 40 victim addresses, with funds swapped to ETH and converted to Bitcoin via instant exchange services.
6 March 2025
Federal prosecutors in Northern California seize $23,604,815 in cryptocurrency via civil forfeiture complaint, explicitly linking the Larsen theft to the 2022 LastPass breach.
Decision Log
- hash: EvjMTe79Bm7cPSVkvuDVnJbpeej6Cqpam6Ut1AHwy6Ax
This investigation is cryptographically anchored to the Solana blockchain (1 event).
model: claude-sonnet
generated: 5/4/2026, 4:04:57 PM
last updated: 8/29/2026, 1:35:55 AM
avoid.net — verified advice for a post-truth world