CryptoReal
CASE FILE — Oct 31, 2023

How a 2022 LastPass Breach Turned Into a Year-Long, $37M Wallet-Draining Campaign

A slow-moving campaign of wallet drains, running since December of last year, has now hit hundreds of individual addresses — and this time, phishing isn't the vector.

The operation has been active for close to a year, but last week alone accounted for $4.4M in stolen funds in a single day, pushing the cumulative total to at least $37M.

The pattern echoes June's Atomic Wallet hack, in which over $100M was drained. As with that incident, researchers ZachXBT and Tayvano have spent recent months methodically tracing these thefts.

Their conclusion: the losses trace back to seed phrases that victims had stored in LastPass, the password manager breached the previous year.

01The LastPass breaches behind it

The underlying cause is believed to be security incidents LastPass disclosed the prior year: an initial direct intrusion in August, followed by the compromise of a third-party cloud storage provider that came to light in November.

LastPass's original statement in August had reassured customers:

we have seen no evidence that this incident involved any access to customer data or encrypted password vaults

That changed in the December update, which disclosed:

The threat actor was also able to copy a backup of customer vault data

—along with a stark warning:

The threat actor may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.

Sums referenced in this case file

Yet many victims reportedly used unusually strong master passwords, which, per Tayvano, leaves only two possibilities:

someone has compromised hundreds of users' vaults one-by-one via a still undetected method or…

LastPass has still not shared some critical details about their security posture and the stuff that was compromised by the attackers.

02Timeline and victim profile

Documented thefts reportedly go back as far as mid-December 2022. The tracing effort was well underway by April, though the connection to LastPass wasn't made publicly known until August.

The perpetrators don't seem interested in small targets — the smallest reported loss was "well over $10k." Among the victims, one lost funds that had sat untouched for almost a decade. Many targets are described as seasoned crypto participants:

employees of reputable crypto orgs, VCs, people who build defi protocols, deploy contracts, run full nodes, and have ENS names

03Attack signature

Beyond the shared LastPass exposure, the thefts follow a set of recurring behavioral patterns:

Primary theft txns are almost always between 10am–4pm UTC.

Except when stealing v large amounts, the attacker will swap your tokens for ETH inside your wallet before sending the ETH out.

The attacker will often miss staked positions, NFTs, or lesser known tokens. Successful rescue missions are COMMON.

Stolen assets are typically funneled through exchanges including FixedFloat, SimpleSwap, SideShift, ChangeNOW, and LetsExchange. The perpetrators also appear to favor operating on weekends — a detail that stands out given they've now moved over $37M.

04Aftermath

LastPass's initial August 2022 communications gave the impression there was little cause for concern, which may have led some users to lower their guard — only to be victimized later once the fuller picture emerged.

There may be legitimate reasons for caution around how much detail companies share publicly after a breach, but for individual users, the safest response when in doubt remains the same: migrate funds to a freshly generated seed phrase.

Convenience gained from centralized, third-party-managed key storage does not appear to be worth the risk exposure it creates.

LastPass
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.