Blockchain detective Zachxbt has dropped a bombshell update: hackers linked to the infamous 2022 Lastpass breach have drained a staggering $12.38 million in cryptocurrency from over 100 victimized wallets, marking a significant escalation in this ongoing security saga.
The Attack Chain: From ETH to Bitcoin
According to Zachxbt’s investigation, the cunning thieves swapped the stolen crypto for ether (ETH), then converted it into bitcoin (BTC) using various instant exchange platforms. “Stolen funds were swapped for ETH and transferred to various instant exchanges from Ethereum to Bitcoin,” Zachxbt revealed in his Telegram group ‘Investigations by Zachxbt.’
This multi-step conversion complicates tracking and demonstrates the attackers’ sophisticated understanding of blockchain forensics.
Three Waves of Attacks Exceeding $23 Million
The 2022 Lastpass security incident allowed attackers to infiltrate encrypted vaults, customer keys, and API tokens, compromising users’ private information. Zachxbt had previously identified two waves of attacks associated with the breach: October 2023, where $4.4 million was stolen, and February 2024, with victims losing over $6.2 million. The latest development—December 2024—adds $12.38 million, bringing the cumulative total to over $23 million.
These attacks show the persistent vulnerability of users who stored seed phrases or wallet keys in Lastpass accounts. The hackers exploit leaked credentials to directly access crypto wallets, with increasing efficiency.
Urgent Warnings for Crypto Users
In light of this update, many crypto proponents have urgently advised users to act if they suspect their wallet credentials were stored in Lastpass. This breach serves as a stark reminder of the perils of using centralized password management tools. As the attacks continue to mount, crypto holders are urged to secure their assets with offline storage and decentralized solutions to avoid further losses.
Blockchain security experts recommend immediate steps: transfer assets to hardware wallets, reset all passwords, and monitor wallet activity for unauthorized transactions. The data from the Lastpass vaults may remain in circulation on the dark web, meaning more victims could emerge in the future.
Lastpass has not yet commented on this latest wave of attacks, but the security community continues to raise alarms. The incident underscores the critical importance of self-custody in the cryptocurrency ecosystem.

