Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov
  • Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK
  • EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations
  • What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate
  • Regulator tells property lender Kingscrown Finance to stop taking on new customers
  • South Asian show at carwright Hall draws new Bradford audiences
  • Walthamstow Art Trail to return in June for 20th anniversary
  • Finance minister highlights AI capacity building for developing nations at G7
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds
Cryptocurrency

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

December 25, 20253 Mins Read

[ad_1]

Dec 25, 2025Ravie LakshmananData Breach / Financial Crime

The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master passwords to crack them open and drain cryptocurrency assets as recently as late 2025, according to new findings from TRM Labs.

The blockchain intelligence firm said evidence points to the involvement of Russian cybercriminal actors in the activity, with one of the Russian exchanges receiving LastPass-linked funds as recently as October.

This assessment is “based on the totality of on-chain evidence – including repeated interaction with Russia-associated infrastructure, continuity of control across pre-and post-mix activity, and the consistent use of high-risk Russian exchanges as off-ramps,” it added.

LastPass suffered a major hack in 2022 that enabled attackers to access personal information belonging to its customers, including their encrypted password vaults containing credentials, such as cryptocurrency private keys and seed phrases.

Cybersecurity

Earlier this month, the password management service was fined $1.6 million by the U.K. Information Commissioner’s Office (ICO) for failing to implement sufficiently robust technical and security measures to prevent the incident.

The breach also prompted the company to issue a warning at the time, stating bad actors may use brute-force techniques to guess the master passwords and decrypt the stolen vault data. The latest findings from TRM Labs show that the cybercriminals have done just that.

“Any vault protected by a weak master password could eventually be decrypted offline, turning a single 2022 intrusion into a multi-year window for attackers to quietly crack passwords and drain assets over time,” the company said.

“As users failed to rotate passwords or improve vault security, attackers continued to crack weak master passwords years later – leading to wallet drains as recently as late 2025.”

The Russian links to the stolen cryptocurrency from the 2022 LastPass breach stem from two primary factors: The use of exchanges commonly associated with the Russian cybercriminal ecosystem in the laundering pipeline and operational connections gleaned from wallets interacting with mixers both before and after the mixing and laundering process.

More $35 million in siphoned digital assets have been traced, out of which $28 million was converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025. Another $7 million has been linked to a subsequent wave detected in September 2025.

The stolen funds have been found to be routed through Cryptomixer.io and off-ramped via Cryptex and Audia6, two Russian exchanges associated with illicit activity. It’s worth mentioning here that Cryptex was sanctioned by the U.S. Treasury Department in September 2024 for receiving over $51.2 million in illicit funds derived from ransomware attacks.

Cybersecurity

TRM Labs said it was able to demix the activity despite the use of CoinJoin techniques to make it harder to trace the flow of funds to external observers, uncovering clustered withdrawals and peeling chains that funneled mixed Bitcoin into the two exchanges.

“This is a clear example of how a single breach can evolve into a multi-year theft campaign,” said Ari Redbord, global head of policy at TRM Labs. “Even when mixers are used, operational patterns, infrastructure reuse, and off-ramp behavior can still reveal who’s really behind the activity.”

“Russian high-risk exchanges continue to serve as critical off-ramps for global cybercrime. This case shows why demixing and ecosystem-level analysis are now essential tools for attribution and enforcement.”

[ad_2]

Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026 Cryptocurrency

Bitcoin slumps to a two-week low as Iran war builds pressure on cryptocurrency

May 17, 2026 Cryptocurrency

Investors Flocking to Super-Anonymous Cryptocurrency Used for the Sketchiest Stuff Imaginable

May 17, 2026 Cryptocurrency

#CryptoCornerSeason2 | Crypto Corner powered by Binance Kea Credit's Jo DSilva To @CNBCTV18News – Real World Asset Tokenisation has hit $370 bn as of April 2026 – BCG is estimating assets worth $60-64 tn to come on chain by end of 2030 Manisha – LinkedIn

May 15, 2026 Cryptocurrency

Australia’s Capital Gains Tax Overhaul Set to Impact Cryptocurrency Investors

May 14, 2026 Cryptocurrency

T3 Financial Crime Unit Seizes Over $450M in Criminal Cryptocurrency Operations

May 14, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026 Investments 1 Min Read

[ad_1] During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting…

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

UK finance ministry presses supermarkets to cap food prices, sources say

May 19, 2026

Welsh painter and art teacher has enjoyed a successful 14 months in Shetland, before recently receiving the dream offer of opening her own gallery in Fife

May 19, 2026

ChatGPT Can Now Access Your Bank Account — As OpenAI Expands Into Personal Finance

May 19, 2026
Latest updates

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026
Weekly Updates

Best Canadian Crypto Trading Platforms for 2026

May 8, 2026

What’s the Next Big Cryptocurrency? Mallconomy’s Presale Begins. What Brands and Shoppers Need to Know

June 22, 2024

Rachel Cruze: 5 Things To Do With Your Investments Every Year

July 12, 2024
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.