1. Home
  2. Drained

Drained

Crypto thief steals $4.4M in a day as toll rises from LastPass breach

Estimates in September revealed that at least $35 million in crypto has been stolen from victims of the LastPass breach since 2022, with the latest hack adding to the toll.

At least 25 people have reportedly seen $4.4 million in crypto drained from across 80 wallets due to a 2022 data breach that impacted password storage software LastPass.

In an Oct. 27 X (Twitter) post, pseudonymous on-chain researcher ZachXBT said they and MetaMask developer Taylor Monahan tracked the fund movements of at least 80 wallets compromised on Oct. 25.

“Most, if not all, of the victims are longtime LastPass users and/or confirm having stored their [crypto wallet] keys/seeds in LastPass,” Monahan said in an accompanying Chainabuse report.

In December 2022, LastPass disclosed an attacker leveraged information previously stolen in a breach that August to target a LastPass employee, snagging their credentials and decrypting stored customer information.

Also stolen was a backup of encrypted customer vault data which LastPass warned could be decrypted if the attacker brute force guesses the account’s master password.

Related: Blockchain congestion and transaction queues actually deter ‘nefarious actors’: Study

In a September blog post, cybersecurity journalist Brian Krebs reported some of the LastPass customer vaults had seemingly been cracked and over $35 million worth of crypto had been stolen from around 150 victims.

In January, LastPass was hit with a class-action suit from individuals claiming the August 2022 breach resulted in the theft of around $53,000 worth of Bitcoin (BTC).

In his latest X post, ZachXBT advised anyone who ever stored a wallet seed or private key in LastPass to “migrate your crypto assets immediately.”

Magazine: Deposit risk: What do crypto exchanges really do with your money?

Ripple CEO Sounds Alarm on SEC Chair Selection Amid Warnings of Oversight Risks

Hacker Steals $6.9 Million From Arbitrum-Based Defi Protocol Lodestar Finance

Hacker Steals .9 Million From Arbitrum-Based Defi Protocol Lodestar FinanceArbitrum-based lending platform Lodestar Finance was exploited on Dec. 10, 2022, according to a tweet from the project’s Twitter account on Saturday. Community reports detail that Lodestar lost roughly $6.9 million from the vulnerability. Lodestar Finance Loses $6.9 Million in an Exploit, TVL Drained, LODE Drops by 53% Another decentralized finance (defi) platform, Lodestar Finance […]

Ripple CEO Sounds Alarm on SEC Chair Selection Amid Warnings of Oversight Risks

BSC Defi Protocol Burgerswap Loses $7.2 Million from a Flash Loan Attack

BSC Defi Protocol Burgerswap Loses .2 Million from a Flash Loan AttackAnother Binance Smart Chain project has been hit with a flash loan attack according to a post mortem written by the Burgerswap team. The project’s official Twitter account said at around 3 a.m. on Friday, Burgerswap suffered from a flash loan attack with the hackers stealing $7.2 million in funds. Binance Smart Chain Defi Protocol […]

Ripple CEO Sounds Alarm on SEC Chair Selection Amid Warnings of Oversight Risks

Flash Loan Attacks Drain 2 Binance Smart Chain Defi Projects for $6 Million

Flash Loan Attacks Drain 2 Binance Smart Chain Defi Projects for  MillionThere have been two back-to-back flash loan attacks in a short period of time stemming from two unique Binance Smart Chain decentralized finance (defi) projects. Last Wednesday, the yield-farming platform Pancakebunny lost close to $3 million in a flash loan attack according to reports. The following Sunday, Bogged Finance saw $3 million exploited from a […]

Ripple CEO Sounds Alarm on SEC Chair Selection Amid Warnings of Oversight Risks