Experts trace ongoing crypto thefts back to long-running LastPass breach fallout Blockchain analysis reveals coordinated laundering tied to compromised LastPas Experts trace ongoing crypto thefts back to long-running LastPass breach fallout Blockchain analysis reveals coordinated laundering tied to compromised LastPas

Experts Link Ongoing Crypto Theft to LastPass Breach Years After the Hack

2025/12/29 23:04
  • Experts trace ongoing crypto thefts back to long-running LastPass breach fallout
  • Blockchain analysis reveals coordinated laundering tied to compromised LastPass password vaults
  • Stolen crypto continues moving through Russian exchanges years after LastPass hack

Blockchain security experts have renewed attention on the LastPass breach after uncovering evidence of continued crypto theft tied to the incident. TRM Labs reported that stolen assets linked to compromised password vaults are still being drained years after the original hack. Notably, the breach exposed encrypted backups of nearly 30 million customer vaults containing sensitive data, including private keys and recovery phrases tied to cryptocurrency wallets.


TRM Labs explained that attackers avoided immediate exploitation after accessing the data. Instead, they downloaded vaults in bulk and cracked weak master passwords offline over time. As a result, wallet drains continued through 2024 and 2025. This slow approach reduced visibility while allowing steady asset extraction. Meanwhile, blockchain analysts identified theft clusters sharing nearly identical transaction behavior. These similarities suggest a coordinated operation rather than random criminal activity.


Also Read: Anthony Scaramucci Says Solana Could Flip Ethereum as Usage and Adoption Surge


Coordinated laundering activity traced across blockchains

Significantly, experts observed that stolen Bitcoin followed repeatable transaction patterns as attackers imported private keys into identical wallet software. This process produced consistent SegWit and Replace-by-Fee features across transactions. Additionally, non-Bitcoin assets were quickly converted into Bitcoin using instant swap services. Funds then moved into new addresses before entering Wasabi Wallet for mixing.


More than $28 million in cryptocurrency followed this laundering path in late 2024 and early 2025, based on TRM Labs’ estimates. Analysts reviewed the activity as a unified campaign instead of isolated events. Consequently, proprietary demixing techniques linked deposits with withdrawal clusters that matched closely in timing and aggregate value.


Further investigation revealed two laundering phases connected to Russian exchange infrastructure. An earlier phase routed funds through Cryptomixer.io before off-ramping via Cryptex, a Russian exchange sanctioned in 2024. Later activity showed a shift in methods. About $7 million moved through Wasabi Wallet before reaching Audi6, another Russian exchange linked to cybercriminal use.


Indicators point to sustained operational control

Importantly, one exchange received LastPass-linked funds as recently as October 2025. This detail confirms the breach continues to generate revenue years after disclosure. Early Wasabi withdrawals occurred within days of wallet drains, indicating attackers executed the CoinJoin activity themselves.


Moreover, blockchain fingerprints observed before mixing matched intelligence gathered after withdrawals. These indicators consistently pointed toward Russia-based operational control. The findings show how compromised encrypted data can drive prolonged crypto theft. TRM Labs noted that long-term blockchain monitoring remains essential as stolen vault data continues to surface.


Also Read: Here’s What Will Drive XRP Price Appreciation – Crypto Researcher Shares Document


The post Experts Link Ongoing Crypto Theft to LastPass Breach Years After the Hack appeared first on 36Crypto.

Piyasa Fırsatı
Chainlink Logosu
Chainlink Fiyatı(LINK)
$12.37
$12.37$12.37
-1.27%
USD
Chainlink (LINK) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

CME Group to launch options on XRP and SOL futures

CME Group to launch options on XRP and SOL futures

The post CME Group to launch options on XRP and SOL futures appeared on BitcoinEthereumNews.com. CME Group will offer options based on the derivative markets on Solana (SOL) and XRP. The new markets will open on October 13, after regulatory approval.  CME Group will expand its crypto products with options on the futures markets of Solana (SOL) and XRP. The futures market will start on October 13, after regulatory review and approval.  The options will allow the trading of MicroSol, XRP, and MicroXRP futures, with expiry dates available every business day, monthly, and quarterly. The new products will be added to the existing BTC and ETH options markets. ‘The launch of these options contracts builds on the significant growth and increasing liquidity we have seen across our suite of Solana and XRP futures,’ said Giovanni Vicioso, CME Group Global Head of Cryptocurrency Products. The options contracts will have two main sizes, tracking the futures contracts. The new market will be suitable for sophisticated institutional traders, as well as active individual traders. The addition of options markets singles out XRP and SOL as liquid enough to offer the potential to bet on a market direction.  The options on futures arrive a few months after the launch of SOL futures. Both SOL and XRP had peak volumes in August, though XRP activity has slowed down in September. XRP and SOL options to tap both institutions and active traders Crypto options are one of the indicators of market attitudes, with XRP and SOL receiving a new way to gauge sentiment. The contracts will be supported by the Cumberland team.  ‘As one of the biggest liquidity providers in the ecosystem, the Cumberland team is excited to support CME Group’s continued expansion of crypto offerings,’ said Roman Makarov, Head of Cumberland Options Trading at DRW. ‘The launch of options on Solana and XRP futures is the latest example of the…
Paylaş
BitcoinEthereumNews2025/09/18 00:56
Vlna BitcoinFi boomu sa začína s HYPER

Vlna BitcoinFi boomu sa začína s HYPER

The post Vlna BitcoinFi boomu sa začína s HYPER appeared on BitcoinEthereumNews.com. Bitcoin Hyper získava 16 miliónov USD: Vlna BitcoinFi boomu sa začína s HYPER Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Với hơn 5 năm làm việc trong lĩnh vực phân tích thị trường tiền điện tử, Khang luôn hướng tới mục tiêu đem lại các kiến thức bổ ích về crypto cho bạn đọc. Anh có rất nhiều bài viết chất lượng phân tích xu hướng blockchain, DeFi và các dự án presale coin tiềm năng mới. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/bitcoin-hyper-raises-16m-bitcoinfi-boom-with-hyper-vn/
Paylaş
BitcoinEthereumNews2025/09/18 10:00
With Fusaka in the rear-view, Ethereum 2026 upgrade comes into focus

With Fusaka in the rear-view, Ethereum 2026 upgrade comes into focus

A version of this article appeared in our The Decentralised newsletter on December 30. Sign up here.With Ethereum’s Fusaka upgrade in the rearview mirror, developers
Paylaş
Coinstats2025/12/31 01:20