Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
    Cryptocurrency

    LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

    December 25, 20253 Mins Read


    Dec 25, 2025Ravie LakshmananData Breach / Financial Crime

    The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025, according to new findings from TRM Labs.

    The blockchain intelligence firm said evidence points to the involvement of Russian cybercriminal actors in the activity, with one of the Russian exchanges receiving LastPass-linked funds as recently as October.

    This assessment is “based on the totality of on-chain evidence – including repeated interaction with Russia-associated infrastructure, continuity of control across pre-and post-mix activity, and the consistent use of high-risk Russian exchanges as off-ramps,” it added.

    LastPass suffered a major hack in 2022 that enabled attackers to access personal information belonging to its customers, including their encrypted password vaults containing credentials, such as cryptocurrency private keys and seed phrases.

    Cybersecurity

    Earlier this month, the password management service was fined $1.6 million by the U.K. Information Commissioner’s Office (ICO) for failing to implement sufficiently robust technical and security measures to prevent the incident.

    The breach also prompted the company to issue a warning at the time, stating bad actors may use brute-force techniques to guess the master passwords and decrypt the stolen vault data. The latest findings from TRM Labs show that the cybercriminals have done just that.

    “Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” the company said.

    “As users failed to rotate passwords or improve vault security, attackers continued to crack weak master passwords years later – leading to wallet drains as recently as late 2025.”

    The Russian links to the stolen cryptocurrency from the 2022 LastPass breach stem from two primary factors: The use of exchanges commonly associated with the Russian cybercriminal ecosystem in the laundering pipeline and operational connections gleaned from wallets interacting with mixers both before and after the mixing and laundering process.

    More $35 million in siphoned digital assets have been traced, out of which $28 million was converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025. Another $7 million has been linked to a subsequent wave detected in September 2025.

    The stolen funds have been found to be routed through Cryptomixer.io and off-ramped via Cryptex and Audia6, two Russian exchanges associated with illicit activity. It’s worth mentioning here that Cryptex was sanctioned by the U.S. Treasury Department in September 2024 for receiving over $51.2 million in illicit funds derived from ransomware attacks.

    Cybersecurity

    TRM Labs said it was able to demix the activity despite the use of CoinJoin techniques to make it harder to trace the flow of funds to external observers, uncovering clustered withdrawals and peeling chains that funneled mixed Bitcoin into the two exchanges.

    “This is a clear example of how a single breach can evolve into a multi-year theft campaign,” said Ari Redbord, global head of policy at TRM Labs. “Even when mixers are used, operational patterns, infrastructure reuse, and off-ramp behavior can still reveal who’s really behind the activity.”

    “Russian high-risk exchanges continue to serve as critical off-ramps for global cybercrime. This case shows why demixing and ecosystem-level analysis are now essential tools for attribution and enforcement.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Minnesota Attorney General’s Office seeks public input on cryptocurrency ATMs – Twin Cities

    Cryptocurrency

    A British Criminal Network Moved Money to Russia Using Cryptocurrencies — Here’s How

    Cryptocurrency

    AG Ellison releases cryptocurrency ATM survey – ABC 6 News

    Cryptocurrency

    SLU adds cryptocurrency as a donation option | Livingston/Tangipahoa

    Cryptocurrency

    Top 10 Cryptocurrencies Of December 23, 2025 – Forbes Advisor

    Cryptocurrency

    Central bank digital currencies will change how money works, says Mark Mobius

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Stock Market

    Should You Buy This Biotech Stock That Just Gained 5% in 1 Day?

    Stock Market

    Utilities Flat as Traders Seek Out Risk — Utilities Roundup

    Chenavari AM annonce que son fonds Chenavari Real Estate Decarbonisation Fund

    Editors Picks

    Trump Begins Selling New Meme Coin Days Ahead of Inauguration – The New York Times

    January 18, 2025

    Mobile mining revolution or crypto hype?

    February 21, 2025

    3 Things All Retired Couples Should Know

    October 27, 2024

    11 Low PE High Dividend Stocks to Buy According to Analysts

    October 14, 2025
    What's Hot

    Best Cryptocurrency Stocks To Add to Your Watchlist – March 29th

    March 30, 2025

    Innocap accélère son expansion mondiale

    January 22, 2025

    Nafed to launch e-auction portal for selling agri-commodities – Industry News

    November 4, 2025
    Our Picks

    Avio USA and ACMI Properties Partner to Design a New Solid

    October 29, 2024

    Dow, S&P 500, Nasdaq bounce after 3-day slide, but end week lower

    September 26, 2025

    Berks County real estate transactions for July 14

    July 14, 2024
    Weekly Top

    Overtakes Apple and Google in Global Market Value

    December 24, 2025

    EU agricultural productivity surges by 9.2 per cent in 2025 estimates

    December 24, 2025

    My children, 8 and 11, are getting premium bonds, shares and savings for Christmas

    December 24, 2025
    Editor's Pick

    Nike Air Max Waffle Sera De Retour à L’automne 2025 Dans Un Coloris « Navy/Silver »

    June 18, 2025

    Milei’s fall from grace: Argentina’s stock market becomes the world’s worst performer in 2025 | Economy and Business

    September 19, 2025

    Former West Ham captain and manager Billy Bonds dies at the age of 79 – The Irish News

    November 30, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.