Blockchain detective Zachxbt has dropped a bombshell update: hackers tied to the infamous 2022 Lastpass breach have drained a staggering $12.38 million in cryptocurrency from over 100 victimized wallets, marking a significant escalation in this ongoing security saga.
Lastpass Hackers Continue to Exploit Stolen Data
According to Zachxbt, the cunning thieves swapped the stolen crypto for ether (ETH) and then converted it into bitcoin (BTC) using multiple instant exchange platforms. “Stolen funds were swapped for ETH and transferred to various instant exchanges from Ethereum to Bitcoin,” Zachxbt revealed in his Telegram group ‘Investigations by Zachxbt.’
This latest heist is a continuation of the fallout from the 2022 Lastpass security incident. During the breach, attackers infiltrated encrypted vaults, customer keys, and API tokens, compromising users’ private information. That data has now been exploited in multiple waves of cryptocurrency theft.
Two Previous Waves Already Cost Millions
Zachxbt had previously identified two waves of attacks linked to the Lastpass breach: the first in October 2023, where $4.4 million was stolen, and another in February 2024, with victims losing over $6.2 million. This latest development shows just how vulnerable users are when they store seed phrases or wallet keys in Lastpass accounts. The total cumulative loss has now reached $12.38 million, and the attacks show no sign of stopping.
Urgent Call to Action for Users
In light of this update, many crypto proponents have urgently advised users to act if they suspect their wallet credentials were stored in Lastpass. This breach serves as a stark reminder of the perils of using centralized password management tools. As the attacks continue to mount, crypto holders are urged to secure their assets with offline storage and decentralized solutions to avoid further losses.
Blockchain security firms have tried to track the stolen funds, but the use of instant exchanges and mixers makes recovery extremely difficult. Zachxbt’s ongoing investigation highlights the importance of proactive security measures. He recommends that anyone who ever used Lastpass to store cryptocurrency-related information should immediately migrate to a hardware wallet or a self-custody solution.
The Lastpass incident has become a cautionary tale in the crypto community. Despite repeated warnings, many users remain unaware of the risks. This latest drain serves as a wake-up call: centralized password managers can become single points of failure in the world of decentralized finance.

