Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
LastPass-linked crypto theft climbs to over $250 million after latest $5.4 million hit

LastPass-linked crypto theft climbs to over $250 million after latest $5.4 million hit

CryptoSlateCryptoSlate2024/12/17 17:11
By:Oluwapelumi Adejumo

Crypto holders urged to act as attackers leverage 2-years old LastPass breach to drain millions despite strong encryption claims.

Blockchain investigator ZachXBT has revealed that malicious actors, identified as the “LastPass threat actor,” have siphoned off approximately $5.36 million in cryptocurrencies.

In a Dec. 17 post on his Telegram Channel, ZachXBT stated:

“Today an estimated $5.36M was drained by the LastPass threat actor from 40+ victim addresses. Stolen funds were swapped for ETH and transferred to various instant exchanges from Ethereum to Bitcoin.”

This exploit traces back to a December 2022 security breach, when LastPass disclosed that attackers accessed archived backups of encrypted vault data stored on a third-party cloud platform. At the time, LastPass, a popular password manager, warned that the breach exposed user vault data, including usernames, passwords, and secure notes.

However, LastPass assured users that brute-forcing master passwords would be extremely challenging due to strong encryption protocols.

Despite this claim, recent attacks have shown that the hackers have systematically targeted users who stored their private keys or seed phrases in their LastPass vaults.

Over $250 million now lost

The Security Alliance (SEAL), a team of cybersecurity experts, reported that crypto losses connected to the breach have now exceeded $250 million as of May 2024.

According to SEAL, these attacks could have been prevented as many victims—despite practicing caution—unknowingly placed their digital assets at risk by relying on centralized storage for private keys.

Considering the latest wave of attack, SEAL stated:

“Don’t be a part of the statistic. If you used LastPass in the past and think there’s a chance you stored your private key or seed phrase in your vault, take the time and move all your tokens  [and] transfer ownership of any contracts/multisigs/etc.”

Security experts noted that this incident highlights the dangers of trusting password managers with sensitive crypto-related data. To mitigate further losses, crypto holders must immediately safeguard their assets and reduce exposure to similar vulnerabilities.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!