Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Wisconsin joins prediction market fight, suing Kalshi, Coinbase, Polymarket, Robinhood and Crypto.com

April 25, 2026

Trillions of dollars in crypto liquidity is concentrating inside the venues US regulators fear most

April 25, 2026

Chainlink and ELYSIA Lead Social Surge as Real-World Asset (RWA) Tokenization Gains Market Momentum

April 25, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Experts Trace $35m in Stolen Crypto to LastPass Breach
Experts Trace $35m in Stolen Crypto to LastPass Breach
Security and Privacy

Experts Trace $35m in Stolen Crypto to LastPass Breach

January 5, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A major data breach at a leading password management provider in 2022 has enabled hackers to drain victims’ digital wallets of millions in crypto, according to TRM Labs.

The blockchain analytics company said it traced several waves of cryptocurrency theft in the months and years following the LastPass breach, attributing the efforts to Russian cybercriminals.

Backups of around 30 million customer password vaults were exposed in the incident, creating what TRM Labs described as a “long-tail risk” for more than 25 million users.

“Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” it warned.

Read more on LastPass breach: LastPass Hackers Stole Source Code

Although it admitted this was likely “only a fraction” of the full amount stolen, TRM claimed to have traced $28m stolen from 2024 to early 2025, and then a further $7m taken in September 2025.

Both phases converged on Russian cryptocurrency exchanges and infrastructure.

“In an earlier phase following the initial exploitation, stolen funds were routed through the now defunct Cryptomixer.io and off-ramped via Cryptex, a Russia-based exchange sanctioned by OFAC in 2024,” TRM explained.

“In a subsequent wave identified in September 2025, TRM analysts traced approximately $7m in additional stolen funds through Wasabi Wallet, with withdrawals ultimately flowing to Audi6, another Russian exchange associated with cybercriminal activity.”

Funds were being converted to fiat currency and withdrawn via the exchange as recently as October 2025, the firm added.

Although the actors responsible used anonymization service CoinJoin to obfuscate the money trail, TRM was able to pick up the scent using demixing.

See also  Former CFO Indicted After Allegedly Losing $35,000,000 of His Employer’s Cash on Secret Crypto Investment

“Using proprietary demixing techniques, analysts matched the hackers’ deposits to a specific withdrawal cluster whose aggregate value and timing closely aligned with the inflows, an alignment statistically unlikely to be coincidental,” it said.

“Blockchain fingerprints observed prior to mixing, combined with intelligence associated with wallets after the mixing process, consistently pointed to Russia-based operational control.”

Lessons Learned

For digital wallet users, the incident is another reminder of the need for multi-factor authentication (MFA) and swift action following any potential password compromise.

“Slow-drip wallet draining” over the past three years was enabled by brute-forcing of password vaults, because LastPass users failed to change their master passwords.

The incident also underscores the persistent threats posed by Russian cybercrime actors.

In December 2025, LastPass was fined £1.2m ($1.6m) by the UK’s Information Commissioner’s Office (ICO) for security failings that led to the breach, which impacted an estimated 1.6 million UK users.

At the time, the regulator said that master passwords were stored locally on customer devices, limiting the potential for threat actors to decrypt customer credentials.

Image credit: Maor_Winetrob / Shutterstock.com

Source link

35m Breach Crypto Experts LastPass stolen Trace
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Trillions of dollars in crypto liquidity is concentrating inside the venues US regulators fear most

April 25, 2026

Mike Tyson, Tether CEO, Cathie Wood are among speakers at Trump’s ‘most exclusive’ crypto conference

April 25, 2026

Crypto is legal in Russia now, but not free to use – Why?

April 25, 2026

Ripple’s SEC Victory Gave Crypto the Legal Clarity You Now Benefit From

April 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Sugartown: A Glimpse into Zynga’s Vision for Web3 Gaming

August 15, 2023

75 US Lawmakers Now Support CBDC Anti-Surveillance Bill

January 2, 2024

Blockticity Mints Hemp and Cannabis Certifications on Avalanche

October 8, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Wisconsin joins prediction market fight, suing Kalshi, Coinbase, Polymarket, Robinhood and Crypto.com

April 25, 2026

Trillions of dollars in crypto liquidity is concentrating inside the venues US regulators fear most

April 25, 2026

Chainlink and ELYSIA Lead Social Surge as Real-World Asset (RWA) Tokenization Gains Market Momentum

April 25, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,334.00-0.33%
  • ethereumEthereum(ETH)$2,312.55-0.32%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.42-1.15%
  • binancecoinBNB(BNB)$629.06-1.32%
  • usd-coinUSDC(USDC)$1.00-0.03%
  • solanaSolana(SOL)$85.79-0.68%
  • tronTRON(TRX)$0.323990-0.05%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.66%
  • dogecoinDogecoin(DOGE)$0.097800-0.48%