By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
Computing

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

News Room
Last updated: 2025/12/25 at 8:07 AM
News Room Published 25 December 2025
Share
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
SHARE

Dec 25, 2025Ravie LakshmananData Breach / Financial Crime

The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025, according to new findings from TRM Labs.

The blockchain intelligence firm said evidence points to the involvement of Russian cybercriminal actors in the activity, with one of the Russian exchanges receiving LastPass-linked funds as recently as October.

This assessment is “based on the totality of on-chain evidence – including repeated interaction with Russia-associated infrastructure, continuity of control across pre-and post-mix activity, and the consistent use of high-risk Russian exchanges as off-ramps,” it added.

LastPass suffered a major hack in 2022 that enabled attackers to access personal information belonging to its customers, including their encrypted password vaults containing credentials, such as cryptocurrency private keys and seed phrases.

Cybersecurity

Earlier this month, the password management service was fined $1.6 million by the U.K. Information Commissioner’s Office (ICO) for failing to implement sufficiently robust technical and security measures to prevent the incident.

The breach also prompted the company to issue a warning at the time, stating bad actors may use brute-force techniques to guess the master passwords and decrypt the stolen vault data. The latest findings from TRM Labs show that the cybercriminals have done just that.

“Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” the company said.

“As users failed to rotate passwords or improve vault security, attackers continued to crack weak master passwords years later – leading to wallet drains as recently as late 2025.”

The Russian links to the stolen cryptocurrency from the 2022 LastPass breach stem from two primary factors: The use of exchanges commonly associated with the Russian cybercriminal ecosystem in the laundering pipeline and operational connections gleaned from wallets interacting with mixers both before and after the mixing and laundering process.

More $35 million in siphoned digital assets have been traced, out of which $28 million was converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025. Another $7 million has been linked to a subsequent wave detected in September 2025.

The stolen funds have been found to be routed through Cryptomixer.io and off-ramped via Cryptex and Audia6, two Russian exchanges associated with illicit activity. It’s worth mentioning here that Cryptex was sanctioned by the U.S. Treasury Department in September 2024 for receiving over $51.2 million in illicit funds derived from ransomware attacks.

Cybersecurity

TRM Labs said it was able to demix the activity despite the use of CoinJoin techniques to make it harder to trace the flow of funds to external observers, uncovering clustered withdrawals and peeling chains that funneled mixed Bitcoin into the two exchanges.

“This is a clear example of how a single breach can evolve into a multi-year theft campaign,” said Ari Redbord, global head of policy at TRM Labs. “Even when mixers are used, operational patterns, infrastructure reuse, and off-ramp behavior can still reveal who’s really behind the activity.”

“Russian high-risk exchanges continue to serve as critical off-ramps for global cybercrime. This case shows why demixing and ecosystem-level analysis are now essential tools for attribution and enforcement.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Tricks make your TV look way better for Christmas & the setting Hollywood hates Tricks make your TV look way better for Christmas & the setting Hollywood hates
Next Article 35 best Boxing Day sales live from £9 at Amazon, Argos, Currys and more 35 best Boxing Day sales live from £9 at Amazon, Argos, Currys and more
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

5 iOS 26.3 Features You Can Look Forward To In Early 2026 – BGR
5 iOS 26.3 Features You Can Look Forward To In Early 2026 – BGR
News
20+ Content Creation Tools for Creators & Influencers in 2025
20+ Content Creation Tools for Creators & Influencers in 2025
Computing
The 15 Boxing Day sale tech deals I’d buy as Sun expert for £100s off top brands
The 15 Boxing Day sale tech deals I’d buy as Sun expert for £100s off top brands
News
How Technology is Transforming Gold Trading | HackerNoon
How Technology is Transforming Gold Trading | HackerNoon
Computing

You Might also Like

20+ Content Creation Tools for Creators & Influencers in 2025
Computing

20+ Content Creation Tools for Creators & Influencers in 2025

4 Min Read
How Technology is Transforming Gold Trading | HackerNoon
Computing

How Technology is Transforming Gold Trading | HackerNoon

8 Min Read
Final Benchmarks Of AMDVLK vs. RADV AMD Radeon Vulkan Drivers
Computing

Final Benchmarks Of AMDVLK vs. RADV AMD Radeon Vulkan Drivers

2 Min Read
Tencent tests Yuanbao AI assistant within WeChat, expanding its role beyond chat · TechNode
Computing

Tencent tests Yuanbao AI assistant within WeChat, expanding its role beyond chat · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?