TRM Labs has linked the ongoing cryptocurrency thefts to the LastPass breach that occurred in 2022.TRM Labs has linked the ongoing cryptocurrency thefts to the LastPass breach that occurred in 2022.

Crypto theft attacks linked to 2022 LastPass data breach

Blockchain investigation firm TRM Labs has linked the ongoing cryptocurrency thefts to the LastPass breach that occurred in 2022. According to reports, the attackers have been draining wallets years after encrypted vaults were stolen and laundering the digital assets through Russian exchanges.

In 2022, LastPass confirmed that attackers had breached its systems by compromising a developer environment. The platform added that the criminals stole portions of the company’s source code and proprietary technical information. In another related incident, the hackers used the stolen credentials to breach the GoTo cloud storage firm, stealing LastPass database backups stored on the platform. For some users, the vault contained both stored credentials and cryptocurrency wallet private keys and seed phrases.

Cryptocurrency theft attacks linked to LastPass breach

During the breach, LastPass claimed that its vaults were encrypted. However, users with weak or reused master passwords were vulnerable to offline cracking, which TRM Labs believes has been ongoing since the breach occurred. “Depending on the length and complexity of your master password and iteration count setting, you may want to reset your master password,” warned LastPass when they disclosed the breach.

The link between the LastPass breaches and the cryptocurrency thefts was also confirmed by the United States Secret Service last year after the agency seized more than $23 million in crypto and said the attackers had obtained the private keys of their victims by decrypting vault data stolen in a password manager breach. Court filings also mentioned that there was no evidence that the victims’ devices had been compromised through malware or phishing.

In its report, TRM Labs connected the ongoing crypto theft to the abuse of the encrypted LastPass vaults stolen in 2022. Rather than the hackers moving swiftly to drain the entire wallets after the breach, the thefts have been carried out in waves, months or years after the incident occurred. It also shows that attackers have been gradually decrypting vaults and extracting stored credentials. In addition, the wallets were drained using similar transaction methods.

TRM Labs also mentioned that the method used during the breach showed that the hackers possessed the private keys before the thefts. “The linkage in the report is not based on direct attribution to individual LastPass accounts, but on correlating downstream on-chain activity with the known impact pattern of the 2022 breach,” TRM said. The platform noted that it created a scenario in which the wallet occurs in the future, rather than immediately after the breach happened.

TRM Labs highlights the use of Wasabi’s CoinJoin feature

The platform also mentioned that its research was initially based on a small number of reports, including several submissions made to Chainabuse, where users identified the LastPass breach as the method the hackers used to steal their wallets. The researchers increased their investigation, identifying cryptocurrency transaction behavior across other cases, eventually linking it to the data theft campaign.

TRM also added that it was able to trace funds even after the attackers mixed them using Wasabi wallet’s CoinJoin feature. CoinJoin is a Bitcoin privacy technique that includes all transactions from multiple users into a single transaction, making it harder to determine which input corresponds to which output. The feature obfuscates transactions without using a traditional mixing service.

After draining wallets, the hackers usually convert stolen assets to Bitcoin, route them through Wasabi Wallet, and attempt to hide their tracks using the feature. However, TRM mentioned that it was able to demix the Bitcoin sent using the CoinJoin feature by analyzing behavioral characteristics, such as transaction structure, timing, and wallet configuration choices. It was also able to match deposits with withdrawal patterns that matched the crypto theft.

Want your project in front of crypto’s top minds? Feature it in our next industry report, where data meets impact.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
Pastor Involved in High-Stakes Crypto Fraud

Pastor Involved in High-Stakes Crypto Fraud

A gripping tale of deception has captured the media’s spotlight, especially in foreign outlets, centering on a cryptocurrency fraud case from Denver, Colorado. Eli Regalado, a pastor, alongside his wife Kaitlyn, was convicted, but what makes this case particularly intriguing is their unconventional defense.Continue Reading:Pastor Involved in High-Stakes Crypto Fraud
Share
Coinstats2025/09/18 00:38
Nexus Traps Tightening Nationwide

Nexus Traps Tightening Nationwide

Digital marketplaces and remote services have transformed how technology businesses operate across borders, but they’ve also intensified sales tax compliance challenges
Share
Techbullion2026/01/16 13:41