Crypto thief steals $4.4M in a day as toll rises from LastPass breach

At least 25 people have reportedly seen $4.4 million in crypto drained from across 80 wallets due to a 2022 data breach that impacted password storage software LastPass.

In an Oct. 27 X (Twitter) post, pseudonymous on-chain researcher ZachXBT said they and MetaMask developer Taylor Monahan tracked the fund movements of at least 80 wallets compromised on Oct. 25.

โ€œMost, if not all, of the victims are longtime LastPass users and/or confirm having stored their [crypto wallet] keys/seeds in LastPass,โ€ Monahan said in an accompanying Chainabuse report.

In December 2022, LastPass disclosed an attacker leveraged information previously stolen in a breach that August to target a LastPass employee, snagging their credentials and decrypting stored customer information.

Also stolen was a backup of encrypted customer vault data which LastPass warned could be decrypted if the attacker brute force guesses the accountโ€™s master password.

Related: Blockchain congestion and transaction queues actually deter โ€˜nefarious actorsโ€™: Study

In a September blog post, cybersecurity journalist Brian Krebs reported some of the LastPass customer vaults had seemingly been cracked and over $35 million worth of crypto had been stolen from around 150 victims.

In January, LastPass was hit with a class-action suit from individuals claiming the August 2022 breach resulted in the theft of around $53,000 worth of Bitcoin (BTC).

In his latest X post, ZachXBT advised anyone who ever stored a wallet seed or private key in LastPass to โ€œmigrate your crypto assets immediately.โ€

Magazine: Deposit risk: What do crypto exchanges really do with your money?