Daily Mail PH

Monday, October 30, 2023

[New post] Use LastPass? Own Crypto? You Could Lose Everything If You Don’t Act Fast

Site logo image Crypto Breaking News posted: "Over the last 10 months, more than 100 seemingly secure crypto wallets—many held by high profile, tech-savvy members of the crypto community—have been drained of tens of millions of dollars' worth of cryptocurrency, without any clear indication how. Now, " Crypto Breaking News

Use LastPass? Own Crypto? You Could Lose Everything If You Don't Act Fast

Crypto Breaking News

Oct 30

Over the last 10 months, more than 100 seemingly secure crypto wallets—many held by high profile, tech-savvy members of the crypto community—have been drained of tens of millions of dollars' worth of cryptocurrency, without any clear indication how. Now, the answer is becoming clearer: The thefts appear to be due to a hack of LastPass, the password management company. 

For months, the seamless and consistently repeated attacks baffled security experts, who couldn't figure out how to stop the theft. Victims did not appear to be falling for scams, or doing anything online for that matter, that risked exposing their private information. 

Besides, it turned out, prioritizing wallet security.

On-chain researchers have since concluded—as the attacks continue to persist monthly—that the hacker in question is likely accessing victims' funds by using wallet passwords and seed phrases exposed during a hack, last winter, into password manager LastPass.

Since that hack, passwords obtained from the computer security service have reportedly led to the theft of at least $39 million worth of crypto, and counting. Just last week, the hacker made off with another $4.4 million in crypto, in what experts have identified as another attack that traces back to LastPass. 

Just on October 25, 2023 alone another ~$4.4M was drained from 25+ victims as a result of the LastPass hack.

Cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass migrate your crypto assets immediately. pic.twitter.com/26HsxrlnCb

— ZachXBT (@zachxbt) October 27, 2023

Taylor Monahan, a lead product manager at MetaMask, first promulgated theories about the mystery hacks' potential origins in April, back when the attacks had only netted about $10 million in stolen crypto. Since then, Monahan and other blockchain analysts have identified LastPass as the apparent common thread connecting victims of the hacks.

In the interim, however, the hacker has continued to drain supposedly secure wallets of millions upon millions of dollars' worth of crypto. 

The largest unanswered ? is whether the attackers stole these keys via the @LastPass hack or via some other mechanism / from each users individual device

If you recall, @LastPass was hacked in summer/fall 2022. @LastPass was slow to determine scope of compromise & release info

— Tay ๐Ÿ’– (@tayvano_) August 28, 2023

Monahan, along with other on-chain sleuths like the pseudonymous blockchain analyst ZachXBT, have implored crypto users to immediately migrate their assets if they ever, even for a brief period, used LastPass to store their wallet seed phrases or keys.

As the attacks continue with no end in sight, Monahan has publicly recounted the stories of numerous friends and associates who—upon news of the hacks—considered changing wallets but didn't move fast enough, only to be targeted by the hacker themselves. 

I know you want to not deal with it.

I know you think its fine bc you've been in this space for years & haven't been rekt.

I know you've been thinking abt migrating but haven't done so yet.

Please prioritize it NOW๐Ÿ™

I'm so tired & heartbroken by these. Please no more thefts. pic.twitter.com/mc3MrSl5yG

— Tay ๐Ÿ’– (@tayvano_) August 28, 2023

Of particular note in the unfolding controversy are statements made by LastPass regarding the severity of the hack that infiltrated the company's stores of private user data late last year.

At first, LastPass insisted that the hack did not expose users' stored passwords, but advised changing those passwords anyway out of an abundance of caution. The company eventually conceded that the hacker was able to access the LastPass corporate vault, which contains ample private user information—but maintained that these breaches still did not necessarily compromise users' master passwords or other keys. 

Analysts who researched the spate of recent crypto heists reportedly tied to the LastPass hack have taken particular issue with the company's handling of the situation, arguing that it has not been forthright with its users about the extent of damage incurred by the hack, and the degree to which LastPass users should have responded to it.

Stay on top of crypto news, get daily updates in your inbox.

"LastPass has still not shared some critical details about their security posture and the stuff that was compromised by the attackers," Monahan wrote. "I want to emphasize strongly that LastPass can and should be doing more here."

"They are a disgusting failure of a company," she added. 

Decrypt reached out to both LastPass and Monahan for this story, but did not immediately receive a response from either party. The mystery hacker's persistent crypto heists, meanwhile, appear to have no end in sight.

Edited by Andrew Hayward

Stay on top of crypto news, get daily updates in your inbox.

Source: Decrypt.co


Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://www.cryptobreaking.com/use-lastpass-own-crypto-you-could-lose-everything-if-you-dont-act-fast/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at October 30, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

CG BOSS Posts from Gargoyles Reboot thanks to creator kept it alive | CG BOSS Games for 04/26/2026

CG BOSS Blog Post Updates ...

  • [New post] 5 Key Technologies Streamlining the Crypto User Experience
    ...
  • Why is Ninoy Aquino Day important to you? Join Rappler’s chat on August 21!
    Hi daily! Who is Ninoy Aquino to you? What lessons from his life still spea...
  • What do you think about BBM’s 3rd year in office? Join the convos!
    Hi, daily! With the State of the Nation Address (SONA) coming up on July 28...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • April 2026 (1)
  • February 2026 (1)
  • January 2026 (7)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.