BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

LastPass vaults cracked; $35M stolen, Russians implicated…

Weak master passwords from LastPass’s 2022 breach enabled attackers to steal and launder over $35M—much converted to Bitcoin via Wasabi Wallet and funneled through Russian exchanges—with wallet drains continuing into late 2025.

  • Encrypted vault backups taken in the 2022 breach of LastPass were cracked using weak master passwords, leading to wallet drains as recently as late 2025.
  • TRM Labs traced more than $35 million in stolen assets, with about $28 million converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025 and another $7 million linked to activity in September 2025.
  • Funds were routed through mixers and off‑ramped at high‑risk Russian exchanges, including Cryptex and Audia6, supporting an assessment of Russian cybercriminal involvement.
  • Mixing techniques such as CoinJoin and structured transfers called peeling chains were used, but investigators were able to demix flows and find clustered withdrawals.

TRM Labs [https://www.trmlabs.com/resources/blog/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement] says actors exploited weak master passwords from the 2022 LastPass breach to decrypt vaults and steal crypto through late 2025. The firm cites repeated interactions with Russia‑associated infrastructure and the use of Russian exchanges as off‑ramps, linking the activity to Russian cybercriminal networks.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The breach exposed encrypted password vaults that contained credentials, private keys, and seed phrases. The company warned at the time that attackers could use brute‑force methods to guess master passwords and decrypt vaults offline; investigators report those techniques were applied over multiple years.

TRM traced more than $35 million in stolen assets. About $28 million was converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025, and roughly $7 million was tied to a wave seen in September 2025. Funds flowed through services including Cryptomixer.io and were off‑ramped via Cryptex and Audia6. The U.S. Treasury sanctioned Cryptex in September 2024 for handling illicit proceeds.

Investigators reported they demixed CoinJoin transactions to reveal clustered withdrawals and peeling chains that funneled mixed Bitcoin into exchanges. Define: CoinJoin — a transaction technique that combines payments from multiple users to obscure origins. Define: Peeling chain — a sequence of small transfers used to siphon funds.

“Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” the firm said. “As users failed to rotate passwords or improve vault security, attackers continued to crack weak master passwords years later – leading to wallet drains as recently as late 2025.”

- Advertisement -

Regulators fined LastPass $1.6 million earlier in December for insufficient security measures. The report highlights the role of operational patterns, infrastructure reuse, and high‑risk exchanges in linking the thefts to known criminal networks and enabling enforcement.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Google Sets 2029 Deadline for Quantum Crypto Switch

Google has declared a 2029 deadline to migrate its products to post-quantum cryptography, citing...

Crypto Developer Loses Bid for Lawsuit Protection

A federal judge dismissed a lawsuit from crypto developer Michael Lewellen seeking pre-approval for...

RBA: Tokenization Is “How, Not If” for Australia

The Reserve Bank of Australia (RBA) states that asset tokenization's future is now a...

Circle Wrongly Froze 16 Wallets: ZachXBT

Onchain investigator ZachXBT claims stablecoin issuer Circle incorrectly froze 16 USDC wallets linked to...

Google Targets 2029 Quantum Crypto Deadline, Bitcoin at Risk

Google has set a 2029 deadline to transition its systems to post-quantum cryptography, warning...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading