Hackers Steal $35M in Cryptocurrency Following LastPass Breach
Recent analysis by blockchain intelligence firm TRM Labs has revealed that Russian cybercriminals have laundered over $35 million in cryptocurrency stolen during the 2022 LastPass breach.
Recent analysis by blockchain intelligence firm TRM Labs has revealed that Russian cybercriminals have laundered over $35 million in cryptocurrency stolen during the 2022 LastPass breach.
The breach in 2022 exposed encrypted password vaults of approximately 30 million customers globally. Despite encryption, attackers managed to crack weaker master passwords offline, allowing them to steal assets over several years. This led to ongoing thefts in 2024 and 2025, targeting users with cryptocurrency holdings.
TRM Labs traced approximately $28 million in stolen Bitcoin through Wasabi Wallet, a cryptocurrency mixer used to obscure transaction trails. An additional $7 million was identified as moving through similar laundering channels.
Attack flow
The stolen funds were found to have converged at two high-risk Russian exchanges: Cryptex, sanctioned by OFAC in 2024, and Audi6, both of which have historical links to cybercriminal activities.
The breach in 2022 exposed encrypted password vaults of approximately 30 million customers globally.
TRM researchers noted a consistent operational signature, with stolen Bitcoin keys imported into identical wallet software, resulting in recognizable transaction patterns. Non-Bitcoin assets were quickly converted to Bitcoin via swap services before being deposited into mixing services.
TRM analysts traced approximately USD 7 million in additional stolen funds through Wasabi Wallet
Despite the use of CoinJoin obfuscation, researchers identified behavioral fingerprints linking activity before and after mixing to the same actors, suggesting a coordinated Russian cybercrime infrastructure.
Mixing services are becoming less effective as threat actors maintain consistent infrastructure. Russian exchanges play a significant role in enabling global cybercrime, facilitating illicit fund transfers despite international enforcement efforts.
The LastPass breach highlights the persistent risk of credential breaches and the ability of cybercriminal ecosystems to exploit financial infrastructures to monetize stolen data at scale, posing long-term risks to the affected 25 million users.
Based on reporting by GBHackers.
