LastPass vaults cracked; $35M stolen, Russians implicated…

Weak master passwords from LastPass’s 2022 breach enabled attackers to steal and launder over $35M—much converted to Bitcoin via Wasabi Wallet and funneled through Russian exchanges—with wallet drains continuing into late 2025.

  • Encrypted vault backups taken in the 2022 breach of LastPass were cracked using weak master passwords, leading to wallet drains as recently as late 2025.
  • TRM Labs traced more than $35 million in stolen assets, with about $28 million converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025 and another $7 million linked to activity in September 2025.
  • Funds were routed through mixers and off‑ramped at high‑risk Russian exchanges, including Cryptex and Audia6, supporting an assessment of Russian cybercriminal involvement.
  • Mixing techniques such as CoinJoin and structured transfers called peeling chains were used, but investigators were able to demix flows and find clustered withdrawals.

TRM Labs [https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement] says actors exploited weak master passwords from the 2022 LastPass breach to decrypt vaults and steal crypto through late 2025. The firm cites repeated interactions with Russia‑associated infrastructure and the use of Russian exchanges as off‑ramps, linking the activity to Russian cybercriminal networks.

- Advertisement -

The breach exposed encrypted password vaults that contained credentials, private keys, and seed phrases. The company warned at the time that attackers could use brute‑force methods to guess master passwords and decrypt vaults offline; investigators report those techniques were applied over multiple years.

TRM traced more than $35 million in stolen assets. About $28 million was converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025, and roughly $7 million was tied to a wave seen in September 2025. Funds flowed through services including Cryptomixer.io and were off‑ramped via Cryptex and Audia6. The U.S. Treasury sanctioned Cryptex in September 2024 for handling illicit proceeds.

Investigators reported they demixed CoinJoin transactions to reveal clustered withdrawals and peeling chains that funneled mixed Bitcoin into exchanges. Define: CoinJoin — a transaction technique that combines payments from multiple users to obscure origins. Define: Peeling chain — a sequence of small transfers used to siphon funds.

“Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” the firm said. “As users failed to rotate passwords or improve vault security, attackers continued to crack weak master passwords years later – leading to wallet drains as recently as late 2025.”

- Advertisement -

Regulators fined LastPass $1.6 million earlier in December for insufficient security measures. The report highlights the role of operational patterns, infrastructure reuse, and high‑risk exchanges in linking the thefts to known criminal networks and enabling enforcement.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Tesla shares slip as Q4 deliveries deemed largely neutral US

Tesla delivered 418,227 vehicles in Q4, slightly below the 422,850 company-polled consensus and last...

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...

EU Debates Digital Euro Privacy, Holding Limits: Compromises

The EU Council has endorsed the European Central Bank design for a digital euro...

Iran Military Export Center Accepts Crypto Payments for Arms

Mindex is accepting cryptocurrency for sales of advanced weapons systems.Buyers can pay with crypto,...

BRICS Accelerates De-Dollarization: Unit, CBDCs, Payments…

India assumed the BRICS presidency and is steering a 2026 push to reduce reliance...
- Advertisement -

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Bitcoin (BTC) $ 90,474.00 2.54%
Ethereum (ETH) $ 3,125.56 4.58%
XRP (XRP) $ 1.99 6.30%
Bittensor (TAO) $ 243.96 7.84%
Polkadot (DOT) $ 2.05 5.93%
Cardano (ADA) $ 0.388063 10.24%
Chainlink (LINK) $ 13.25 6.68%
Hyperliquid (HYPE) $ 24.50 0.19%
Monero (XMR) $ 422.34 0.40%
Hedera (HBAR) $ 0.11991 7.68%
Toncoin (TON) $ 1.90 12.82%