Experts trace ongoing crypto thefts back to long-running LastPass breach fallout Blockchain analysis reveals coordinated laundering tied to compromised LastPas Experts trace ongoing crypto thefts back to long-running LastPass breach fallout Blockchain analysis reveals coordinated laundering tied to compromised LastPas

Experts Link Ongoing Crypto Theft to LastPass Breach Years After the Hack

  • Experts trace ongoing crypto thefts back to long-running LastPass breach fallout
  • Blockchain analysis reveals coordinated laundering tied to compromised LastPass password vaults
  • Stolen crypto continues moving through Russian exchanges years after LastPass hack

Blockchain security experts have renewed attention on the LastPass breach after uncovering evidence of continued crypto theft tied to the incident. TRM Labs reported that stolen assets linked to compromised password vaults are still being drained years after the original hack. Notably, the breach exposed encrypted backups of nearly 30 million customer vaults containing sensitive data, including private keys and recovery phrases tied to cryptocurrency wallets.


TRM Labs explained that attackers avoided immediate exploitation after accessing the data. Instead, they downloaded vaults in bulk and cracked weak master passwords offline over time. As a result, wallet drains continued through 2024 and 2025. This slow approach reduced visibility while allowing steady asset extraction. Meanwhile, blockchain analysts identified theft clusters sharing nearly identical transaction behavior. These similarities suggest a coordinated operation rather than random criminal activity.


Also Read: Anthony Scaramucci Says Solana Could Flip Ethereum as Usage and Adoption Surge


Coordinated laundering activity traced across blockchains

Significantly, experts observed that stolen Bitcoin followed repeatable transaction patterns as attackers imported private keys into identical wallet software. This process produced consistent SegWit and Replace-by-Fee features across transactions. Additionally, non-Bitcoin assets were quickly converted into Bitcoin using instant swap services. Funds then moved into new addresses before entering Wasabi Wallet for mixing.


More than $28 million in cryptocurrency followed this laundering path in late 2024 and early 2025, based on TRM Labs’ estimates. Analysts reviewed the activity as a unified campaign instead of isolated events. Consequently, proprietary demixing techniques linked deposits with withdrawal clusters that matched closely in timing and aggregate value.


Further investigation revealed two laundering phases connected to Russian exchange infrastructure. An earlier phase routed funds through Cryptomixer.io before off-ramping via Cryptex, a Russian exchange sanctioned in 2024. Later activity showed a shift in methods. About $7 million moved through Wasabi Wallet before reaching Audi6, another Russian exchange linked to cybercriminal use.


Indicators point to sustained operational control

Importantly, one exchange received LastPass-linked funds as recently as October 2025. This detail confirms the breach continues to generate revenue years after disclosure. Early Wasabi withdrawals occurred within days of wallet drains, indicating attackers executed the CoinJoin activity themselves.


Moreover, blockchain fingerprints observed before mixing matched intelligence gathered after withdrawals. These indicators consistently pointed toward Russia-based operational control. The findings show how compromised encrypted data can drive prolonged crypto theft. TRM Labs noted that long-term blockchain monitoring remains essential as stolen vault data continues to surface.


Also Read: Here’s What Will Drive XRP Price Appreciation – Crypto Researcher Shares Document


The post Experts Link Ongoing Crypto Theft to LastPass Breach Years After the Hack appeared first on 36Crypto.

Market Opportunity
Chainlink Logo
Chainlink Price(LINK)
$12.32
$12.32$12.32
-0.64%
USD
Chainlink (LINK) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Red Dog Pet Resort & Spa Selects MoeGo as Its Enterprise Operating System to Power Multi-State Expansion

Red Dog Pet Resort & Spa Selects MoeGo as Its Enterprise Operating System to Power Multi-State Expansion

MoeGo Becomes Enterprise Operating System for Red Dog Pet Resort & Spa to Standardize and Scale Nationwide Operations BOSTON, Dec. 29, 2025 /PRNewswire/ — Red Dog
Share
AI Journal2025/12/30 02:45
Russia’s Sberbank Issues First Crypto Loan Using Bitcoin as Collateral

Russia’s Sberbank Issues First Crypto Loan Using Bitcoin as Collateral

TLDR Sberbank issued a pilot crypto-backed loan to Bitcoin miner Intelion Data. Bitcoin mined by Intelion Data was used as collateral for the loan. The bank secured
Share
Coincentral2025/12/30 02:33