Blockchain Detective Zachxbt Ties $12.38M Crypto Drain to Lastpass Breach, Over 100 Wallets Victimized

Blockchain Detective Zachxbt Ties $12.38M Crypto Drain to Lastpass Breach, Over 100 Wallets Victimized

N
News Editor 01
2026-07-08 16:24:14
Blockchain sleuth Zachxbt reveals hackers linked to the 2022 Lastpass breach have drained $12.38 million in crypto from over 100 wallets, with stolen funds converted through instant exchanges.
Lastpass breachcrypto securitycryptocurrency theftZachxbtblockchain detective

Blockchain investigator Zachxbt has dropped a bombshell update: hackers tied to the infamous 2022 Lastpass password manager breach have drained a staggering $12.38 million in cryptocurrency from over 100 victimized wallets, marking a significant escalation in the ongoing security saga.

Attack Methodology and Fund Flow

According to Zachxbt's Telegram group 'Investigations by Zachxbt', the cunning thieves swapped the stolen crypto for ether (ETH) and then converted it into bitcoin (BTC) via various instant exchange platforms. 'Stolen funds were swapped for ETH and transferred to various instant exchanges from Ethereum to Bitcoin,' he revealed. This intricate laundering chain makes asset recovery extremely challenging.

Historical Context: Three Waves of Attacks

This latest heist is a continuation of the fallout from the 2022 Lastpass security incident, where attackers infiltrated encrypted vaults, customer keys, and API tokens. Zachxbt had previously identified two waves: one in October 2023 with $4.4 million stolen, and another in February 2024 with victims losing over $6.2 million. The new wave brings total losses tied to the breach to over $22.8 million.

Critical Warning: Never Store Keys in Centralized Password Managers

The series of attacks underscores the acute danger of storing seed phrases or wallet keys in Lastpass accounts. In response, crypto proponents have urgently advised users to act if they suspect their credentials were stored in Lastpass. This breach serves as a stark reminder of the perils of centralized password management tools. Security experts recommend moving assets to offline hardware wallets, utilizing multi-signature setups, and enabling two-factor authentication. As attacks continue to mount, crypto holders are urged to prioritize decentralized security solutions to avoid further losses.

Even though Lastpass has patched the initial vulnerability, the leaked legacy data remains a ticking time bomb. Users who have ever used Lastpass should immediately migrate their crypto assets and monitor security researcher updates to stay ahead of emerging threats.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.