Researchers say hackers stole $4.4M in crypto from 25+ victims on October 25 using private keys, credentials, and wallet passphrases from a 2022 LastPass breach
Why is anyone still using LastPass? I haven't even been trying to pay attention and I can think of 3 major hacks just off the top of my head. …
Context & Ripple Effects
This is a delayed-consequence chapter in LastPass's 2022 incident: the company disclosed that attackers obtained copies of encrypted and unencrypted vault data after access to cloud-storage keys, a vault-data theft that created lasting exposure beyond the initial intrusion.
Subsequent reporting tied the compromise to a third-party software flaw and a keylogger on a DevOps engineer's device, clarifying the path into the password-vault environment. The reported crypto losses make the downstream risk concrete for users whose vaults held high-value recovery material.
First-order effects
- The identified victims face immediate loss of crypto assets, while anyone whose vault stored private keys, wallet passphrases, or reused credentials has reason to treat those secrets as compromised and replace them where possible.
- LastPass must contend with evidence that stolen vault material can be monetized long after the original breach, rather than viewing the event solely as a historical disclosure.
Second-order effects
- Password-manager customers and security teams will place greater scrutiny on what is stored in vaults, especially irreversible or hard-to-rotate crypto recovery data, and on the breach-response guidance offered by providers.
- Competing credential-management services can use the episode to emphasize vault protection, incident transparency, and recovery controls; users may reassess provider trust and migration costs.
Third-order effects
- The case underscores that credential-vault breaches have a long tail: encrypted archives can remain valuable to attackers as they pursue individual users and high-value accounts over time.
- If such delayed losses recur, password-management products may face stronger expectations to distinguish ordinary credentials from nonrecoverable secrets and to design more explicit post-breach rotation paths.
The trend: This is part of a broader shift from measuring breaches by initial access alone to measuring the years-long monetization risk of stolen identity and credential stores.