The post TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure appeared on BitcoinEthereumNews.com. TRM Labs traces $28 million in stolen crypto fromThe post TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure appeared on BitcoinEthereumNews.com. TRM Labs traces $28 million in stolen crypto from

TRM Links LastPass Stolen Crypto to Russian Exchange Infrastructure

  • TRM Labs traces $28 million in stolen crypto from 2022 LastPass breach to mixers.
  • On-chain analysis points to Russian cybercriminal infrastructure and exchanges.
  • Demixing techniques reveal stolen Bitcoin flowed through Cryptex and Audi6.

A report from TRM Labs reveals blockchain intelligence analysts have traced stolen cryptocurrency linked to the 2022 LastPass password manager breach. The analysis identifies on-chain patterns that suggest Russian cybercriminal involvement in laundering operations spanning 2024 and 2025.

Hackers breached LastPass in 2022, exposing encrypted backups of roughly 30 million customer vaults containing digital credentials, crypto private keys, and seed phrases. While the vaults required master passwords to decrypt, attackers downloaded them in bulk. This created a multi-year window for cracking weak passwords offline and draining assets over time.

Blockchain analysis reveals coordinated laundering campaign

TRM analysts identified wallet drains continuing throughout 2024 and 2025, extending the breach’s impact far beyond initial disclosure. By analyzing recent theft clusters, researchers traced stolen funds through mixing services to two high-risk Russian exchanges used by cybercriminals as fiat off-ramps.

The analysis reveals consistent on-chain signatures across thefts. Stolen Bitcoin keys were imported into identical wallet software, producing shared transaction characteristics including SegWit usage and Replace-by-Fee features. Non-Bitcoin assets were quickly converted to Bitcoin through instant swap services, then transferred to single-use addresses and deposited into Wasabi Wallet.

Flow of funds by LastPass hackers

TRM estimates more than $28 million in cryptocurrency was stolen, converted to Bitcoin, and laundered through Wasabi in late 2024 and early 2025. Rather than analyzing individual thefts separately, TRM researchers examined the activity as a coordinated campaign. Using proprietary demixing techniques, analysts matched hacker deposits to withdrawal clusters whose aggregate value and timing aligned closely with inflows.

Russian exchange infrastructure serves as fiat off-ramp

Analysis of LastPass-linked laundering activity reveals two distinct phases converging on Russian exchanges. An earlier phase routed stolen funds through the now-defunct Cryptomixer.io and off-ramped via Cryptex, a Russia-based exchange sanctioned by OFAC in 2024.

A subsequent wave identified in September 2025 saw TRM analysts trace approximately $7 million in stolen funds through Wasabi Wallet. Withdrawals flowed to Audi6, another Russian exchange associated with cybercriminal activity. One of these exchanges received LastPass-linked funds as recently as October 2025.

Blockchain fingerprints observed before mixing, combined with intelligence associated with wallets after the mixing process, consistently pointed to Russia-based operational control. Early Wasabi withdrawals occurred within days of initial wallet drains. This suggests that attackers themselves executed the CoinJoin activity.  

Related: Coinbase Arrests Former Indian Employee in Major Data Breach Case

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/trm-traces-28m-stolen-in-lastpass-breach-to-russian-exchanges-via-demixing-analysis/

Market Opportunity
SEED Logo
SEED Price(SEED)
$0,0004802
$0,0004802$0,0004802
+%0,12
USD
SEED (SEED) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight

The post American Bitcoin’s $5B Nasdaq Debut Puts Trump-Backed Miner in Crypto Spotlight appeared on BitcoinEthereumNews.com. Key Takeaways: American Bitcoin (ABTC) surged nearly 85% on its Nasdaq debut, briefly reaching a $5B valuation. The Trump family, alongside Hut 8 Mining, controls 98% of the newly merged crypto-mining entity. Eric Trump called Bitcoin “modern-day gold,” predicting it could reach $1 million per coin. American Bitcoin, a fast-rising crypto mining firm with strong political and institutional backing, has officially entered Wall Street. After merging with Gryphon Digital Mining, the company made its Nasdaq debut under the ticker ABTC, instantly drawing global attention to both its stock performance and its bold vision for Bitcoin’s future. Read More: Trump-Backed Crypto Firm Eyes Asia for Bold Bitcoin Expansion Nasdaq Debut: An Explosive First Day ABTC’s first day of trading proved as dramatic as expected. Shares surged almost 85% at the open, touching a peak of $14 before settling at lower levels by the close. That initial spike valued the company around $5 billion, positioning it as one of 2025’s most-watched listings. At the last session, ABTC has been trading at $7.28 per share, which is a small positive 2.97% per day. Although the price has decelerated since opening highs, analysts note that the company has been off to a strong start and early investor activity is a hard-to-find feat in a newly-launched crypto mining business. According to market watchers, the listing comes at a time of new momentum in the digital asset markets. With Bitcoin trading above $110,000 this quarter, American Bitcoin’s entry comes at a time when both institutional investors and retail traders are showing heightened interest in exposure to Bitcoin-linked equities. Ownership Structure: Trump Family and Hut 8 at the Helm Its management and ownership set up has increased the visibility of the company. The Trump family and the Canadian mining giant Hut 8 Mining jointly own 98 percent…
Share
BitcoinEthereumNews2025/09/18 01:33
Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50