Russian Hackers Linked to $35M Cryptocurrency Theft Following LastPass Breach
Blockchain intelligence firm TRM Labs has traced approximately $35 million in cryptocurrency stolen from LastPass password manager users to Russian cybercriminal infrastructure. The analysis reveals how attackers weaponized the 2022 LastPass vault breach—which exposed encrypted credentials belonging to roughly 30 million users—into a sustained cryptocurrency theft campaign spanning 2024 and 2025. New waves of wallet drains confirmed that attackers successfully decrypted vault contents using weak master passwords and systematically drained cryptocurrency holdings, demonstrating how single credential breaches create persistent multi-year exploitation windows enabling continuous asset theft.