📈 Get daily crypto insights that make you smarter about your money

LastPass Breach Fallout: How Storing Seed Phrases in Password Managers Puts Your Crypto at Risk

A chilling pattern of cryptocurrency thefts that has been unfolding since December 2022 came into sharp focus in early September 2023 when security researchers confirmed that a breach of the popular password manager LastPass was directly linked to the theft of more than $35 million in cryptocurrency from over 150 victims. The findings, first reported by KrebsOnSecurity and corroborated by MetaMask lead product manager Taylor Monahan, reveal a fundamental vulnerability in how security-conscious cryptocurrency users protect their digital assets.

The Threat Landscape

The LastPass breach, which was initially disclosed in November 2022, involved the theft of encrypted password vaults containing both encrypted and plaintext data for more than 25 million users. While LastPass assured users that vault data was encrypted and therefore safe, the reality proved far more troubling for cryptocurrency holders who had stored their seed phrases within the password manager.

A seed phrase, typically consisting of 12 or 24 words, is the master key to a cryptocurrency wallet. Anyone who possesses this phrase has complete and irreversible access to all funds associated with that wallet. Taylor Monahan, who has been investigating the thefts since late 2022, discovered a highly reliable set of clues connecting the robberies of more than 150 individuals. The victims collectively lost over $35 million worth of cryptocurrency, with roughly two to five high-dollar heists occurring each month since December 2022.

What makes this threat particularly insidious is the profile of the victims. According to Monahan, virtually all of the affected individuals were longtime cryptocurrency investors and security-minded people. Many were employees of reputable crypto organizations, venture capitalists, DeFi protocol developers, smart contract deployers, and full node operators. None appeared to have suffered the typical precursor attacks, such as email or phone compromises, that usually precede high-value crypto thefts.

Core Principles

The core principle violated in this case is straightforward: your seed phrase should never exist in a digital format that is connected to the internet, even within an encrypted container. While storing seed phrases in a password manager has long been considered a reasonable security practice by many cybersecurity enthusiasts, the LastPass breach demonstrates that this approach carries catastrophic risk.

Nick Bax, director of analytics at cryptocurrency wallet recovery company Unciphered, conducted an independent analysis of the theft data and reached the same conclusion as Monahan. He described the investigation as one of the broadest and most complex cryptocurrency investigations he had ever encountered. The threat actor moved stolen funds from multiple victims to the same blockchain addresses, creating a clear link between victims that would not exist if these were independent attacks.

The researchers identified a unique signature connecting all the thefts, including dramatic similarities in how victim funds were stolen and laundered through specific cryptocurrency exchanges. The attackers frequently grouped victims by sending their stolen cryptocurrencies to the same destination wallet, suggesting a single organized operation rather than multiple independent actors.

Tooling and Setup

For cryptocurrency users looking to properly secure their seed phrases, the gold standard remains offline storage. Hardware wallets such as those from Ledger or Trezor generate and store seed phrases entirely within the device’s secure element, never exposing them to the computer or internet. These devices typically cost between $60 and $200 and provide the highest level of security for everyday cryptocurrency users.

For those who must store seed phrases in physical form, the best practice is to write them on durable material, such as metal backup plates, and store them in a secure physical location like a safe or safety deposit box. Paper backups, while common, are vulnerable to fire, water damage, and physical deterioration over time. Several companies now offer specialized metal backup solutions that can withstand extreme conditions.

For users who have previously stored their seed phrases in LastPass or any other cloud-connected service, the immediate recommendation is to transfer all funds from wallets whose seed phrases were ever stored digitally to new wallets with freshly generated seed phrases that have never been exposed to any digital system. With Bitcoin trading around $25,753 and Ethereum at $1,632 in September 2023, even modest holdings could represent significant losses if compromised.

Ongoing Vigilance

The LastPass breach illustrates a broader principle: security is only as strong as its weakest link. As the cryptocurrency ecosystem matures and the value of digital assets continues to grow, attackers are increasingly targeting the infrastructure and services that surround blockchain networks rather than the networks themselves. Password managers, cloud storage services, email providers, and even browser extensions all represent potential vectors for seed phrase theft.

The researchers involved in this investigation have chosen not to publish the specific blockchain signature linking the thefts, as doing so could cause the attackers to alter their methods and become harder to track. However, they have published findings about the laundering techniques used, which frequently involve routing stolen funds through specific cryptocurrency exchanges.

Final Takeaway

The $35 million and counting stolen from LastPass users who stored their seed phrases in the password manager serves as a harsh but necessary lesson for the entire cryptocurrency community. No cloud-connected service, regardless of its encryption standards or security reputation, should be considered safe for storing the keys to your digital wealth. The gap between a password breach and total cryptocurrency loss can be measured in hours, not days. If your seed phrase has ever existed in a digital format connected to the internet, consider your funds at risk and take immediate action to secure them with a fresh, purely offline wallet setup.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “LastPass Breach Fallout: How Storing Seed Phrases in Password Managers Puts Your Crypto at Risk”

  1. krebs and taylor monahan both confirming 150+ victims and 35m stolen. when two independent researchers reach the same conclusion you know the real number is probably way higher

    1. krebson_fan_ the real number is definitely higher. most victims dont know they got drained from LastPass yet. the lag between breach and theft was months

  2. A 12 or 24 word seed phrase gives complete irreversible access. There is no customer support to call, no chargeback to file. Once someone has those words your funds are gone forever.

    1. no chargeback to file is the part most newcomers dont grasp. you lose your keys the funds are gone forever. no help desk no ticket nothing

    2. exactly this. 150+ victims and $35M gone because people trusted a password manager with their seed phrase. metal plates exist for a reason

      1. metal plates are great until your house floods or catches fire. seed phrase storage needs a whole backup strategy not just one method

        1. vault_op_ metal plates plus a secondary backup in a different location. single point of failure is single point of failure regardless of material

          1. engraved_steel_ the secondary backup point is critical. one house fire and your steel plate is gone too. split locations or nothing

        2. air_gapped_andy

          vault_op_ metal plate in a bank deposit box plus a encrypted USB backup with a family member. redundancy not material is what matters

          1. air_gapped_andy the metal plate plus encrypted usb approach is solid but most people just screenshot their seed phrase and store it in icloud photos. thats the reality

          2. Ingrid M. the screenshot thing is real. seen three people in my group lose funds because they photographed their seed phrase and it synced to iCloud

          3. Erez B. people screenshotting seed phrases that auto-sync to iCloud is why immersive security education matters. the technical solution exists, human behavior is the gap

  3. lastpass told 25 million users their data was encrypted and safe. months later people are still losing everything. class action when

    1. class action wont recover stolen BTC. the damage is permanent and irreversible. this is why seed phrases should never touch cloud storage

  4. 25 million vaults stolen and LastPass still operates. brand trust in crypto circles is gone but mainstream users probably still use it

    1. Margit H. LastPass still operating is wild. any crypto project with that track record would be dead and buried

      1. maja d. 25 million encrypted vaults stolen and lastpass still sells the same product. any crypto project with that track record would be cancelled overnight

  5. 150 victims and $35M stolen and LastPass sent a generic email about enhanced security. no personalized outreach, no compensation. just PR

    1. vault_refugee_ LastPass sent a generic security email to 25 million compromised users. no compensation, no personalized outreach. imagine a crypto exchange doing that

    2. engrave_and_pray_

      vault_refugee_ LastPass sending a generic email after 35M stolen is peak corporate arrogance. they should have been sued into oblivion

  6. metal plate plus encrypted USB backup with a family member is the only real answer. LastPass proved that cloud-based seed storage is just a hosted vulnerability

  7. 35 million stolen across 150+ victims and krebs says thats probably a fraction. most lastpass users dont even know their vault was compromised let alone their seed phrase

    1. pass_drift_ 35M across 150 victims and Krebs says thats a fraction. most LastPass users still dont know their vault was part of the breach. the real number is probably 5x

      1. opsec_rat_ 5x the reported number is realistic. Krebs said 150 victims but most LastPass users never connected the dots between their drained wallet and a vault breach from 2022

  8. 25 million vaults stolen and LastPass is still operating. imagine any other security company surviving that

  9. metal plates in a bank deposit box is the only serious answer. if your seed phrase has ever touched the internet its already compromised

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,198.000.0%ETH$2,519.35+0.3%SOL$101.70+0.0%BNB$726.61-1.0%XRP$1.360.0%ADA$0.2072-0.4%DOGE$0.0847+0.4%DOT$1.01-4.1%AVAX$7.40-0.7%LINK$11.49-0.1%UNI$6.38+3.6%ATOM$1.60-2.7%LTC$53.81+0.3%ARB$0.1414+0.2%NEAR$2.35+0.1%FIL$0.8152+1.8%SUI$0.7228-0.1%BTC$77,198.000.0%ETH$2,519.35+0.3%SOL$101.70+0.0%BNB$726.61-1.0%XRP$1.360.0%ADA$0.2072-0.4%DOGE$0.0847+0.4%DOT$1.01-4.1%AVAX$7.40-0.7%LINK$11.49-0.1%UNI$6.38+3.6%ATOM$1.60-2.7%LTC$53.81+0.3%ARB$0.1414+0.2%NEAR$2.35+0.1%FIL$0.8152+1.8%SUI$0.7228-0.1%
Scroll to Top