The post TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure appeared on BitcoinEthereumNews.com. TRM Labs traces $28 million in stolen crypto fromThe post TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure appeared on BitcoinEthereumNews.com. TRM Labs traces $28 million in stolen crypto from

TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure

  • TRM Labs traces $28 million in stolen crypto from 2022 LastPass breach to mixers.
  • On-chain analysis points to Russian cybercriminal infrastructure and exchanges.
  • Demixing techniques reveal stolen Bitcoin flowed through Cryptex and Audi6.

A report from TRM Labs reveals blockchain intelligence analysts have traced stolen cryptocurrency linked to the 2022 LastPass password manager breach. The analysis identifies on-chain patterns that suggest Russian cybercriminal involvement in laundering operations spanning 2024 and 2025.

Hackers breached LastPass in 2022, exposing encrypted backups of roughly 30 million customer vaults containing digital credentials, crypto private keys, and seed phrases. While the vaults required master passwords to decrypt, attackers downloaded them in bulk. This created a multi-year window for cracking weak passwords offline and draining assets over time.

Blockchain analysis reveals coordinated laundering campaign

TRM analysts identified wallet drains continuing throughout 2024 and 2025, extending the breach’s impact far beyond initial disclosure. By analyzing recent theft clusters, researchers traced stolen funds through mixing services to two high-risk Russian exchanges used by cybercriminals as fiat off-ramps.

The analysis reveals consistent on-chain signatures across thefts. Stolen Bitcoin keys were imported into identical wallet software, producing shared transaction characteristics including SegWit usage and Replace-by-Fee features. Non-Bitcoin assets were quickly converted to Bitcoin through instant swap services, then transferred to single-use addresses and deposited into Wasabi Wallet.

Flow of funds by LastPass hackers

TRM estimates more than $28 million in cryptocurrency was stolen, converted to Bitcoin, and laundered through Wasabi in late 2024 and early 2025. Rather than analyzing individual thefts separately, TRM researchers examined the activity as a coordinated campaign. Using proprietary demixing techniques, analysts matched hacker deposits to withdrawal clusters whose aggregate value and timing aligned closely with inflows.

Russian exchange infrastructure serves as fiat off-ramp

Analysis of LastPass-linked laundering activity reveals two distinct phases converging on Russian exchanges. An earlier phase routed stolen funds through the now-defunct Cryptomixer.io and off-ramped via Cryptex, a Russia-based exchange sanctioned by OFAC in 2024.

A subsequent wave identified in September 2025 saw TRM analysts trace approximately $7 million in stolen funds through Wasabi Wallet. Withdrawals flowed to Audi6, another Russian exchange associated with cybercriminal activity. One of these exchanges received LastPass-linked funds as recently as October 2025.

Blockchain fingerprints observed before mixing, combined with intelligence associated with wallets after the mixing process, consistently pointed to Russia-based operational control. Early Wasabi withdrawals occurred within days of initial wallet drains. This suggests that attackers themselves executed the CoinJoin activity.  

Related: Coinbase Arrests Former Indian Employee in Major Data Breach Case

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/trm-traces-28m-stolen-in-lastpass-breach-to-russian-exchanges-via-demixing-analysis/

Market Opportunity
SEED Logo
SEED Price(SEED)
$0.0004789
$0.0004789$0.0004789
-0.14%
USD
SEED (SEED) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
Fed Decides On Interest Rates Today—Here’s What To Watch For

Fed Decides On Interest Rates Today—Here’s What To Watch For

The post Fed Decides On Interest Rates Today—Here’s What To Watch For appeared on BitcoinEthereumNews.com. Topline The Federal Reserve on Wednesday will conclude a two-day policymaking meeting and release a decision on whether to lower interest rates—following months of pressure and criticism from President Donald Trump—and potentially signal whether additional cuts are on the way. President Donald Trump has urged the central bank to “CUT INTEREST RATES, NOW, AND BIGGER” than they might plan to. Getty Images Key Facts The central bank is poised to cut interest rates by at least a quarter-point, down from the 4.25% to 4.5% range where they have been held since December to between 4% and 4.25%, as Wall Street has placed 100% odds of a rate cut, according to CME’s FedWatch, with higher odds (94%) on a quarter-point cut than a half-point (6%) reduction. Fed governors Christopher Waller and Michelle Bowman, both Trump appointees, voted in July for a quarter-point reduction to rates, and they may dissent again in favor of a large cut alongside Stephen Miran, Trump’s Council of Economic Advisers’ chair, who was sworn in at the meeting’s start on Tuesday. It’s unclear whether other policymakers, including Kansas City Fed President Jeffrey Schmid and St. Louis Fed President Alberto Musalem, will favor larger cuts or opt for no reduction. Fed Chair Jerome Powell said in his Jackson Hole, Wyoming, address last month the central bank would likely consider a looser monetary policy, noting the “shifting balance of risks” on the U.S. economy “may warrant adjusting our policy stance.” David Mericle, an economist for Goldman Sachs, wrote in a note the “key question” for the Fed’s meeting is whether policymakers signal “this is likely the first in a series of consecutive cuts” as the central bank is anticipated to “acknowledge the softening in the labor market,” though they may not “nod to an October cut.” Mericle said he…
Share
BitcoinEthereumNews2025/09/18 00:23