• Login
Whats Current In
No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development
No Result
View All Result
Whats Current In
No Result
View All Result
Home Cyber Security

LastPass breach linked to theft of $4.4 million in crypto

Lawrence Abrams by Lawrence Abrams
October 31, 2023
Reading Time: 3 mins read
0
LastPass breach linked to theft of $4.4 million in crypto

Cryptocurrency falling

RELATED POSTS

HTC Global Services confirms cyberattack after data leaked online

Multiple NFT collections at risk by flaw in open-source library

Kali Linux 2023.4 released with GNOME 45 and 15 new tools

Hackers have stolen $4.4 million in cryptocurrency on October 25th using private keys and passphrases stored in stolen LastPass databases, according to research by crypto fraud researchers who have been researching similar incidents.

The news comes from ZachXBT and MetaMask developer Taylor Monahan, who have been tracking these crypto thefts.

“We regularly have people reach out via DM who have had their crypto assets stolen. We also approach victims we discover on-chain,” ZachXBT told BleepingComputer.

“We ask potential LastPass victims multiple questions and typically have found one commonality between them all being LastPass.”

According to a tweet by ZachXBT on X, the threat actors stole $4.4 million from 25+ victims due to a LastPass breach in 2022.

ZachXBT tweet

Buy JNews
ADVERTISEMENT

The LastPass breach

In 2022, LastPass suffered two breaches that ultimately allowed threat actors to steal source code, customer data, and production backups stored in cloud services that included encrypted password vaults.

At the time, LastPass CEO Karim Toubba said that while the encrypted vaults were stolen, only customers knew the master password required to decrypt them.

Therefore, if you were following password best practices recommended by LastPass, your vaults should be safe.

However, LastPass warned that for those using weaker passwords, it was advised to reset the master password.

“Depending on the length and complexity of your master password and iteration count setting, you may want to reset your master password,” reads a LastPass support bulletin about the cyberattack.

This suggestion was given because a weaker password can more easily be cracked using specialized programs that utilize a GPU to brute force easy-to-crack passwords.

According to research conducted by Monahan and ZachXBT, it is believed that the threat actors are cracking these stolen password vaults to gain access to stored cryptocurrency wallet passphrases, credentials, and private keys.

Once they gain access to this information, they can load the wallets onto their own devices and drain them of all funds.

According to a report by Brian Krebs on this research, Monahan and other researchers have generated a unique signature that links the theft of over $35 million to the same threat actors.

“At this point I’m also confident in saying that, in most of these cases, the compromised keys were stolen from LastPass,” tweeted Monahan in August.

“The number of victims who only had the specific group of seeds/keys that were drained stored in LastPass is simply too much to ignore.”

It is becoming increasingly clear that the threat actors behind the LastPass attack have successfully cracked the passwords for vaults and are using the stolen information to fuel their own attacks.

Therefore, if you are a LastPass user who had an account during the August and December 2022 breaches, it is strongly suggested that you reset all of your passwords, including your password.

Share54Tweet34Pin12
Lawrence Abrams

Lawrence Abrams

Related Posts

HTC Global Services confirms cyberattack after data leaked online
Cyber Security

HTC Global Services confirms cyberattack after data leaked online

December 5, 2023
Multiple NFT collections at risk by flaw in open-source library
Cyber Security

Multiple NFT collections at risk by flaw in open-source library

December 5, 2023
Kali Linux 2023.4 released with GNOME 45 and 15 new tools
Cyber Security

Kali Linux 2023.4 released with GNOME 45 and 15 new tools

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates
Cyber Security

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023

Recommended Stories

Maxine Waters Criticized for Praising SBF — Lawmaker Says ‘We Appreciate That You’ve Been Candid’

Maxine Waters Criticized for Praising SBF — Lawmaker Says ‘We Appreciate That You’ve Been Candid’

December 3, 2022
The US Securing Open Source Software Act of 2022 is a step in the right direction

Arrival is running out of cash — and fast

March 10, 2023
Microsoft to let Windows 10 home users buy Extended Security Updates

Microsoft to let Windows 10 home users buy Extended Security Updates

December 5, 2023

Popular Stories

  • Facts and myths about the warriors who raided Europe and explored the New World

    137 shares
    Share 55 Tweet 34
  • A Brief History of All the Women Who Have Won the Nobel Prize

    136 shares
    Share 54 Tweet 34
  • Will XRP make a comeback after the recent price decline? Data suggests…

    136 shares
    Share 54 Tweet 34
  • Gowalla returns to see if location-based networking is ready for its mainstream moment

    136 shares
    Share 54 Tweet 34
  • Saudi Arabia Seeks U.S. Security Pledges, Nuclear Help for Peace with Israel

    136 shares
    Share 54 Tweet 34
Whats Current In

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Visit our landing page to see all features & demos.

LEARN MORE »

Recent Posts

  • Ethereum spot ETF race heats up: This cohort takes an interest
  • Of SHIB’s surging burn rate and BONE’s role in it all
  • Should Blur investors be concerned about the dip in prices?

Categories

  • Apple Computer
  • Blockchain
  • Cyber Security
  • Tech News
  • Venture Capital

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Blockchain
  • Cyber Security
  • Gadgets & Hardware
  • Startups
    • Angel investing
    • Venture Capital
  • More Tech News
    • AI
    • App Development
    • Cloud & SaaS
    • Gaming
    • Web Development

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?