Blockchain detective Zachxbt has uncovered a massive cryptocurrency drain tied to the infamous 2022 Lastpass data breach, with over 100 victim wallets losing a staggering $12.38 million. This marks the latest escalation in a series of attacks that have exploited compromised credentials from the password manager incident.
How the Attack Unfolded
According to Zachxbt's investigation, the hackers first swapped the stolen crypto assets for Ether (ETH) before routing them through various instant exchanges to convert into Bitcoin (BTC). This multi-step laundering technique is designed to obfuscate the trail. The total amount stolen now stands at $12.38 million, affecting more than 100 distinct wallet addresses. Zachxbt disclosed the findings in his Telegram channel 'Investigations by Zachxbt,' urging users to remain vigilant.
A History of Successive Attacks
This is not the first time the Lastpass breach has led to crypto theft. In October 2023, Zachxbt identified a first wave that drained $4.4 million. A second wave in February 2024 resulted in losses exceeding $6.2 million. The current third wave is significantly larger, indicating that hackers are still exploiting the vault of stolen private keys and seed phrases obtained during the 2022 intrusion. The attackers broke into Lastpass's encrypted vaults, extracting master passwords, API tokens, and wallet keys, which have been systematically used to empty crypto wallets.
Urgent Security Recommendations
In light of this ongoing threat, Zachxbt and other cybersecurity experts strongly advise any user who may have stored cryptocurrency seed phrases or private keys in Lastpass to immediately transfer their assets to a cold wallet or a decentralized password manager. Centralized password managers present a single point of failure: if the service is compromised, all stored secrets are exposed. The crypto community is increasingly urging holders to adopt self-custody solutions, such as hardware wallets or multi-signature setups, to mitigate the risk of future thefts.
This case serves as a stark reminder that in the blockchain ecosystem, private key sovereignty is paramount. The convenience of cloud-based key storage can lead to catastrophic financial losses, as demonstrated by the escalating Lastpass-linked heists.

