Listen to this Post

Introduction: A Breach That Never Really Ended
When LastPass disclosed a serious security breach in 2022, many users assumed the damage was limited to that moment in time. Password resets were encouraged, headlines faded, and attention moved on. But new investigations reveal a far more troubling reality: the consequences of that breach have been unfolding quietly for years. According to blockchain intelligence firm TRM Labs, millions of dollars in cryptocurrency stolen between 2024 and 2025 can be directly traced back to encrypted password vaults taken during the 2022 LastPass incident. This is not a story of instant exploitation, but of patience, cryptography, and attackers who waited until the conditions were right.
Summary of the Original Report
The Origin of the LastPass Breach
In 2022, LastPass confirmed that attackers had compromised a developer environment, gaining access to portions of the company’s source code and proprietary technical information. While serious, this initial disclosure did not fully capture the scale of the incident.
The GoTo Cloud Storage Incident
In a related follow-up breach, threat actors used previously stolen credentials to access GoTo, a cloud storage provider used by LastPass. From there, they exfiltrated backups of customer password vaults stored in the cloud.
What Was Inside the Vaults
For many users, LastPass vaults contained more than login credentials. Some stored cryptocurrency wallet private keys, recovery seed phrases, and other sensitive data that effectively granted full control over digital assets.
Encryption Was Not Enough
Although the vaults were encrypted, they were only as strong as the users’ master passwords. Weak, reused, or short passwords allowed attackers to perform offline brute-force cracking over long periods of time.
Long-Term Decryption Efforts
Rather than rushing to exploit the data, attackers appear to have methodically decrypted vaults over months and years. This slow approach reduced detection and allowed them to strike long after the original breach faded from memory.
Official Warnings From LastPass
At the time, LastPass warned users that password strength and iteration counts mattered greatly, advising some customers to reset their master passwords depending on configuration and complexity.
Confirmation From U.S. Authorities
The U.S. Secret Service later corroborated the link between the breach and crypto theft. In 2025, it seized more than $23 million in cryptocurrency tied to stolen private keys decrypted from password manager vaults.
No Evidence of Malware or Phishing
Court filings revealed no signs of device compromise through malware or phishing. Investigators concluded that decrypted vault data was the primary attack vector.
TRM Labs Connects the Dots
In a report released last week, TRM Labs stated that ongoing cryptocurrency thefts could be traced to the abuse of the stolen LastPass vaults from 2022.
Delayed Wallet Drains Raise Red Flags
Instead of immediate thefts, wallets were drained in waves months or even years later. This pattern strongly suggested pre-existing possession of private keys rather than new intrusions.
Identical Transaction Behavior
The stolen funds were moved using similar transaction structures, indicating a single coordinated campaign rather than unrelated attacks.
User Reports and Chainabuse Data
TRM’s investigation began with a small number of victim reports, including submissions to Chainabuse where users explicitly identified the LastPass breach as the source of their losses.
Expanding the Blockchain Analysis
Researchers expanded their scope, analyzing transaction behavior across multiple incidents to identify shared characteristics linked to the same breach.
Wasabi Wallet and CoinJoin Mixing
After draining wallets, attackers converted assets into Bitcoin and laundered them using Wasabi Wallet’s CoinJoin feature, a privacy technique designed to obscure transaction trails.
CoinJoin’s Intended Privacy Model
CoinJoin works by combining multiple users’ transactions into a single batch, making it difficult to associate inputs with outputs and complicating forensic analysis.
TRM’s “Demixing” Breakthrough
Despite CoinJoin’s privacy protections, TRM analysts were able to demix the transactions by studying timing, transaction structures, and wallet configuration patterns.
Campaign-Level Analysis
Instead of examining individual thefts, TRM treated the activity as a coordinated campaign, clustering deposits and withdrawals over extended periods.
Russian Operational Links
Blockchain fingerprints before and after mixing consistently pointed to operational control linked to the Russian cybercrime ecosystem.
Matching Deposits and Withdrawals
Using proprietary techniques, TRM matched Wasabi deposits with withdrawal clusters whose timing and value alignment were statistically unlikely to be coincidental.
Early Withdrawals Signal Same Actors
Quick withdrawals following wallet drains further suggested that the same threat actors were responsible for both theft and laundering.
The Financial Scale of the Theft
TRM estimates that over $28 million in cryptocurrency was stolen and laundered in late 2024 and early 2025 alone.
A Second Wave in 2025
An additional $7 million was tied to a later wave of attacks in September 2025, showing the campaign was still active years after the original breach.
Repeated Use of Russian Exchanges
The laundered funds were repeatedly cashed out through the same Russian-linked exchanges, including Cryptex and Audi6.
A Single Threat Actor Profile
The repeated infrastructure, behavior patterns, and cash-out methods strongly indicate a single group or closely related actors.
A Breach With Long-Term Consequences
The report illustrates how encrypted data breaches can remain dangerous long after public disclosure, especially when attackers are patient.
Password Managers as High-Value Targets
By centralizing credentials and keys, password managers represent a uniquely valuable prize for attackers willing to invest time and resources.
The Lingering Risk to Users
For affected users, the threat did not end in 2022. In many cases, it was only beginning.
What Undercode Say:
A Case Study in Delayed Exploitation
The LastPass incident highlights a growing trend in cybercrime: delayed exploitation. Rather than immediate monetization, attackers are increasingly willing to wait years to maximize returns while minimizing attention.
Encryption Is Not a Silver Bullet
Encrypted vaults provide a false sense of security when user-controlled passwords are weak. Offline cracking removes rate limits and turns time into the attacker’s greatest advantage.
Crypto Keys Should Never Live in Password Managers
Storing wallet seed phrases in password managers creates a single catastrophic failure point. Once compromised, attackers gain irreversible control over funds.
The Myth of “Safe After Reset”
Many users assume that changing passwords after a breach eliminates risk. In cases involving stolen encrypted data, that assumption is dangerously wrong.
CoinJoin Is Not Crime-Proof
Privacy tools like CoinJoin complicate investigations but do not guarantee anonymity. Behavioral analysis and campaign-level correlation remain powerful forensic tools.
Blockchain Analytics Are Maturing Rapidly
TRM’s ability to demix CoinJoin transactions underscores how blockchain intelligence is evolving faster than many criminals anticipate.
Nation-Linked Crime Ecosystems Persist
The repeated appearance of Russian-linked exchanges and infrastructure points to entrenched cybercrime ecosystems that operate with relative impunity.
Patience as an Attack Strategy
This campaign demonstrates that patience itself has become a weapon. Attackers can wait until victims forget, monitoring quietly until the optimal moment to strike.
Password Manager Design Must Evolve
Future designs may need hardware-backed encryption, mandatory minimum password entropy, or vault segmentation to reduce blast radius.
Regulatory Attention Is Inevitable
As password managers become critical infrastructure for both individuals and enterprises, regulatory scrutiny around breach handling and disclosure is likely to increase.
A Warning Beyond LastPass
This is not just a LastPass story. Any service storing encrypted user secrets at scale faces the same long-tail risk.
User Education Remains the Weakest Link
Even the strongest cryptography fails when users reuse passwords or ignore security warnings.
Crypto Theft Is Becoming Forensic-Resistant, Not Forensic-Proof
Attackers are adapting, but so are investigators. The gap between crime and attribution is narrowing.
Breaches Should Be Treated as Permanent Events
Organizations and users must assume that stolen encrypted data will eventually be decrypted.
The Cost of Centralization
Convenience-driven centralization continues to create high-value targets that attract highly sophisticated adversaries.
Long-Term Monitoring Is Essential
Post-breach response should include years-long monitoring, not months, especially when encrypted data is involved.
Trust, Once Broken, Is Hard to Restore
Incidents like this erode trust not only in one company, but in the entire password manager ecosystem.
Security Debt Always Comes Due
The delayed thefts represent accumulated security debt finally being collected, with interest.
Fact Checker Results
✅ LastPass confirmed encrypted vaults were stolen during the 2022 breach.
✅ TRM Labs provided blockchain evidence linking later crypto thefts to those vaults.
❌ No evidence supports claims that victims’ devices were compromised via malware or phishing.
Prediction
🔮 More delayed crypto thefts linked to historical data breaches will surface as cracking techniques improve.
🔮 Password managers will face pressure to ban storage of cryptographic private keys by default.
🔮 Blockchain forensic firms will increasingly neutralize privacy tools once considered untraceable.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




