1. Home
  2. Lastpass

Lastpass

Zachxbt Ties $12.38 Million Crypto Drain to Lastpass Breach; 100 Victimized Wallets

Zachxbt Ties .38 Million Crypto Drain to Lastpass Breach; 100 Victimized WalletsA blockchain detective has dropped a bombshell update: hackers linked to the infamous 2022 Lastpass breach have drained a staggering $12.38 million in cryptocurrency from over 100 victimized wallets, marking a significant escalation in this ongoing security saga. Blockchain Sleuth Uncovers Millions in Crypto Stolen Post-Lastpass Hack According to blockchain investigator Zachxbt, the total theft […]

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy

LastPass threat actor steals $5.4M from victims just a week before Xmas

White hat organization Security Alliance (SEAL) urged users to transfer crypto funds from LastPass if their private keys have been stored there since December 2022 or earlier.

The notorious LastPass hackers may have just ruined Christmas for another 40 victims by stealing $5.36 million from LastPass users — just eight days before the holiday. 

LastPass fell victim to a data breach in December 2022, when the hackers were able to copy a backup of customer vault data from encrypted storage.

As of September, more than $35 million worth of crypto had been stolen — but factoring in the $5.36 million and a $4.4 million incident from Oct. 25 would bring that figure closer to $45 million.

Read more

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy

$4,500,000 in Crypto Stolen From Victims of LassPass Hack in One Day Alone: On-Chain Data

,500,000 in Crypto Stolen From Victims of LassPass Hack in One Day Alone: On-Chain Data

An on-chain sleuth says that users of the LastPass password manager application have lost millions of dollars in crypto to threat actors. The on-chain researcher pseudonymously known as ZachXBT tells his 449,400 followers on the X social media platform that dozens of crypto users were compromised on a single day last week following the LastPass […]

The post $4,500,000 in Crypto Stolen From Victims of LassPass Hack in One Day Alone: On-Chain Data appeared first on The Daily Hodl.

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy

Crypto thief steals $4.4M in a day as toll rises from LastPass breach

Estimates in September revealed that at least $35 million in crypto has been stolen from victims of the LastPass breach since 2022, with the latest hack adding to the toll.

At least 25 people have reportedly seen $4.4 million in crypto drained from across 80 wallets due to a 2022 data breach that impacted password storage software LastPass.

In an Oct. 27 X (Twitter) post, pseudonymous on-chain researcher ZachXBT said they and MetaMask developer Taylor Monahan tracked the fund movements of at least 80 wallets compromised on Oct. 25.

“Most, if not all, of the victims are longtime LastPass users and/or confirm having stored their [crypto wallet] keys/seeds in LastPass,” Monahan said in an accompanying Chainabuse report.

In December 2022, LastPass disclosed an attacker leveraged information previously stolen in a breach that August to target a LastPass employee, snagging their credentials and decrypting stored customer information.

Also stolen was a backup of encrypted customer vault data which LastPass warned could be decrypted if the attacker brute force guesses the account’s master password.

Related: Blockchain congestion and transaction queues actually deter ‘nefarious actors’: Study

In a September blog post, cybersecurity journalist Brian Krebs reported some of the LastPass customer vaults had seemingly been cracked and over $35 million worth of crypto had been stolen from around 150 victims.

In January, LastPass was hit with a class-action suit from individuals claiming the August 2022 breach resulted in the theft of around $53,000 worth of Bitcoin (BTC).

In his latest X post, ZachXBT advised anyone who ever stored a wallet seed or private key in LastPass to “migrate your crypto assets immediately.”

Magazine: Deposit risk: What do crypto exchanges really do with your money?

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy

LastPass data breach led to $53K in Bitcoin stolen, lawsuit alleges

A class action is seeking damages from the password manager following a data breach in August 2022.

A class action lawsuit has been filed against password management service LastPass following a data breach from Aug. 2022.

The class action was filed with the U.S. district court of Massachusetts on Jan. 3, by an unnamed plaintiff known only as “John Doe” and on behalf of others similarly situated.

It alleges that the data breach of LastPass has resulted in the theft of around $53,000 worth of Bitcoin.

The plaintiff claimed he began accruing BTC in Jul. 2022 and updated his master password to more than 12 characters using a password generator, as recommended by the LastPass “best practices.”

This was done to enable the storage of private keys in the seemingly secure LastPass customer vault.

When news of the data breach broke, the plaintiff deleted his private information from his customer vault. LastPass was hacked in Aug. 2022, with the attacker stealing encrypted passwords and other data, according to a December statement from the company.

Despite the quick action to delete the data, it appeared to be too late for the plaintiff. The lawsuit read:

“However, on or around Thanksgiving weekend of 2022, Plaintiff’s Bitcoin was stolen using the private keys he stored with Defendant [LastPass].”

“The LastPass Data Breach has, through no fault of his own, exposed him to the theft of his Bitcoin and exposed him to continued risk,” it added.

The suit claims that victims have been put at increased substantial risk of future fraud and misuse of their private information, which may take years to manifest, discover, and detect.

LastPass is being accused of negligence, breach of contract, unjust enrichment, and breach of fiduciary duty, however, the figure sought in damages was not specified.

Related: 'Third-party incident' impacted Gemini with 5.7 million emails leaked

According to cybersecurity researcher Graham Cluley, the stolen data includes unencrypted information including company names, user names, billing addresses, telephone numbers, email addresses, IP addresses, and website URLs from password vaults.

In December, LastPass admitted that if customers had weak Master Passwords, the attackers may be able to use brute force to guess this password, allowing them to decrypt the vaults.

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy

Lastpass Data Breach Frightens Users, Some Say Hack ‘May Be Worse Than They Are Letting on’

Lastpass Data Breach Frightens Users, Some Say Hack ‘May Be Worse Than They Are Letting on’People involved in financial tech, software programming, cyber security, and cryptocurrencies have been talking about the Lastpass data breach that was disclosed two days ago. The password management company detailed that a breach, committed earlier this year, allowed hackers to obtain a “backup of customer vault data.” Lastpass Reveals ‘Threat Actor Was Also Able to […]

BRICS Unmoved by Trump’s 100% Tariff Threats, Says Russian Envoy