Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Short answer: In December 2024, blockchain investigator ZachXBT reported that more than 40 cryptocurrency addresses lost approximately $5.36 million in a theft wave he associated with the “LastPass threat actor.” The connection is plausible because attackers stole LastPass vault backups and related data in 2022, but it is not a conclusively proven finding accepted by LastPass. LastPass said it had found no conclusive evidence directly connecting the later thefts to its incidents.

What happened in the 2022 LastPass breach?

The incident unfolded in two related stages, rather than as one event in which every password was dumped in plaintext.

  1. August 2022: an attacker accessed part of LastPass’s development environment through a compromised developer account and stole source code and proprietary technical information. LastPass initially said it had found no evidence that customer data or encrypted vaults had been accessed. See LastPass’s incident notice.
  2. November–December 2022: information from the first intrusion was reportedly used to target an employee and obtain credentials and keys for cloud-based storage containing production backups. On December 22, LastPass confirmed that customer data and vault backups had been copied.

The stolen material included customer names, company information, email and billing addresses, telephone numbers, IP addresses, unencrypted website URLs and other metadata, plus encrypted vault fields such as usernames, passwords, secure notes and form-filled data. LastPass said those sensitive fields were protected with AES-256 encryption and keys derived from each customer’s master password. Its March 2023 update also described exposed system configuration data, API secrets, third-party integration secrets, repositories, scripts, certificates and other backup information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That distinction matters: there is no public evidence that all LastPass passwords were decrypted. However, a stolen encrypted vault can be attacked offline, especially when a master password is short, reused or predictable. Metadata and separately stored secrets may not receive the same protection as encrypted password fields.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

How the later crypto thefts were connected

ZachXBT traced wallet movements, transaction timing and recurring attack patterns and labeled the cluster the “LastPass threat actor.” In the December 16–18, 2024 wave, funds from more than 40 addresses were reportedly converted into Ether and routed through instant-exchange services, with movements between Ethereum and Bitcoin. His analysis associated approximately $5.36 million with that wave.

“Linked to LastPass” should therefore be read as an investigator’s attribution, not as proof that LastPass directly caused every loss. LastPass said in reporting covered by The Block that it was not aware of conclusive evidence directly connecting the cryptocurrency thefts to the 2022 incidents. No public, court-tested forensic finding establishes that every reported victim stored a wallet secret in LastPass or that every theft came from one actor.

Reported theft waves

Period Reported amount How to interpret it
October 2023 About $4.4 million A ZachXBT-attributed batch of identified on-chain thefts
February 2024 More than $6.2 million A separate reported wave attributed to the same cluster
December 2024 About $5.36 million More than 40 addresses in the newly reported wave

These figures should not be presented as a single verified grand total. They are attributed or estimated losses from separate investigations and may not include every victim. “Millionaire crypto heist” describes a multi-million-dollar theft; it does not necessarily mean one millionaire was robbed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why crypto secrets create a different kind of risk

A password can be changed. A wallet’s recovery phrase generally cannot. Anyone who obtains a seed phrase or private key can control the associated funds, regardless of whether the original LastPass entry was later deleted.

Treat the following as potentially exposed if they were ever stored in an affected vault:

  • Wallet seed phrases and private keys
  • Hardware-wallet recovery phrases
  • Exchange API keys, especially trading or withdrawal-enabled keys
  • Browser-wallet passwords and multisignature signer material
  • Email credentials used for exchange recovery
  • Authenticator seeds and two-factor backup codes
  • Cloud backups containing wallet credentials

A hardware wallet does not solve this problem if its recovery phrase was typed into or saved in LastPass. The phrase—not the device—is the root of control.

Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

Who faces the greatest risk?

Exposure depends on whether a person used LastPass during the affected period, whether their vault was included in the copied backups, the strength and uniqueness of the master password, and what was stored in the vault. A strong, unique master password makes offline decryption harder, but it does not erase risks from unencrypted metadata, reused credentials, phishing, API keys, MFA material or secrets exposed elsewhere.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two-factor authentication protects sign-in to a LastPass account; it does not recall a vault backup that an attacker already copied. Deleting an account or uninstalling the app likewise does not erase stolen copies.

What cryptocurrency holders should do now

  1. Assume the wallet is compromised if its seed phrase or private key was ever stored in LastPass.
  2. Generate a completely new wallet and seed phrase in a trusted environment. Do not photograph, type or cloud-store the new phrase.
  3. Transfer assets to the new wallet. Do not reuse the old phrase or merely move funds between addresses controlled by it.
  4. Revoke token approvals and review smart-contract permissions where appropriate.
  5. Revoke and regenerate exchange API keys, prioritizing keys with trading or withdrawal permissions.
  6. Review wallet and exchange histories for unauthorized activity and preserve addresses, transaction hashes, timestamps and screenshots.
  7. Contact the relevant exchange, wallet provider and law-enforcement or reporting channel quickly if funds are moving. Blockchain transfers are usually irreversible.

ZachXBT specifically advised people who may have stored seed phrases or keys in LastPass to migrate their assets. Asset migration is more urgent than deciding which password-manager subscription to buy.

What other LastPass users should rotate

  1. Change the LastPass master password if the account remains active, using a long, unique passphrase.
  2. Rotate credentials in this order: primary email, banks and financial services, crypto exchanges, cloud storage, domain registrars, social accounts, work and administrator accounts.
  3. Replace every reused password, not just the one used for LastPass.
  4. Revoke and regenerate API tokens, SSH keys, app passwords, recovery codes and authenticator seeds.
  5. Prefer authenticator apps or FIDO2 hardware keys over SMS where supported, and register a securely stored backup key.
  6. Review active sessions, login alerts and account-recovery settings.
  7. Expect targeted phishing using exposed email addresses, company names, URLs or service information from vault metadata.

Should you leave LastPass?

Migrating can be reasonable: copied vaults create a long-term offline-attack risk, and some readers may prefer a provider with different encryption, audit and recovery designs. But deleting LastPass first is not remediation. You could lose access to credentials before inventorying and rotating them, while stolen backups remain outside the service.

Use a controlled sequence: export or inventory what you need, move crypto and rotate high-value credentials, verify access, then close or retain the account according to your risk assessment. LastPass’s current incident information is collected in its Trust Center.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate a replacement

Compare services on client-side or end-to-end encryption, whether the provider holds decryption material, key-stretching and authentication design, independent audits, breach disclosure, passkey and hardware-key support, emergency recovery, offline access, export controls and whether sensitive notes, URLs and file names are encrypted. Cost and interface matter, but they should follow security architecture and a migration plan.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Services such as 1Password, Bitwarden and Proton Pass publish different security and feature approaches. Check official pages for current plans and capabilities. A Yubico security key can strengthen supported account logins, but it does not replace wallet migration. Hardware-wallet users should consult the security guidance from Ledger or Trezor and protect the new recovery phrase offline.

What remains uncertain

  • Whether every reported victim stored a crypto secret in LastPass
  • Whether all reported thefts came from one attacker
  • Whether the $5.36 million estimate captures the full December loss
  • Whether additional thefts are ongoing
  • Whether law enforcement has publicly confirmed ZachXBT’s attribution

The evidence supports a serious, plausible connection between stolen LastPass data and later wallet drains. It does not support saying that LastPass admitted responsibility or that all users’ funds were stolen.

The Bottom Line

Bottom line: If a seed phrase or private key was ever stored in LastPass, create a new wallet and move the assets. If you stored only ordinary passwords, rotate high-value and reused credentials, regenerate recovery factors and monitor for phishing. The reported crypto thefts are substantial, but their LastPass connection remains an investigator’s attribution rather than a conclusively proven liability finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.