Zachxbt Ties $12.38 Million Crypto Drain to Lastpass Breach; Over 100 Victimized Wallets

Zachxbt Ties $12.38 Million Crypto Drain to Lastpass Breach; Over 100 Victimized Wallets

N
News Editor 01
2026-07-08 16:22:14
Blockchain investigator Zachxbt reveals that hackers exploiting the 2022 Lastpass breach have drained $12.38 million in crypto from over 100 wallets, marking a third major wave of attacks.
Lastpasscrypto securityblockchain investigatorZachxbtwallet drain

Blockchain detective Zachxbt has dropped a bombshell update: hackers linked to the infamous 2022 Lastpass breach have drained a staggering $12.38 million in cryptocurrency from over 100 victimized wallets, marking a significant escalation in this ongoing security saga.

The Attack Chain: From ETH to Bitcoin

According to Zachxbt’s investigation, the cunning thieves swapped the stolen crypto for ether (ETH), then converted it into bitcoin (BTC) using various instant exchange platforms. “Stolen funds were swapped for ETH and transferred to various instant exchanges from Ethereum to Bitcoin,” Zachxbt revealed in his Telegram group ‘Investigations by Zachxbt.’

This multi-step conversion complicates tracking and demonstrates the attackers’ sophisticated understanding of blockchain forensics.

Three Waves of Attacks Exceeding $23 Million

The 2022 Lastpass security incident allowed attackers to infiltrate encrypted vaults, customer keys, and API tokens, compromising users’ private information. Zachxbt had previously identified two waves of attacks associated with the breach: October 2023, where $4.4 million was stolen, and February 2024, with victims losing over $6.2 million. The latest development—December 2024—adds $12.38 million, bringing the cumulative total to over $23 million.

These attacks show the persistent vulnerability of users who stored seed phrases or wallet keys in Lastpass accounts. The hackers exploit leaked credentials to directly access crypto wallets, with increasing efficiency.

Urgent Warnings for Crypto Users

In light of this update, many crypto proponents have urgently advised users to act if they suspect their wallet credentials were stored in Lastpass. This breach serves as a stark reminder of the perils of using centralized password management tools. As the attacks continue to mount, crypto holders are urged to secure their assets with offline storage and decentralized solutions to avoid further losses.

Blockchain security experts recommend immediate steps: transfer assets to hardware wallets, reset all passwords, and monitor wallet activity for unauthorized transactions. The data from the Lastpass vaults may remain in circulation on the dark web, meaning more victims could emerge in the future.

Lastpass has not yet commented on this latest wave of attacks, but the security community continues to raise alarms. The incident underscores the critical importance of self-custody in the cryptocurrency ecosystem.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.