{"id":10490,"date":"2026-01-06T10:58:54","date_gmt":"2026-01-06T10:58:54","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10490"},"modified":"2026-01-06T10:58:54","modified_gmt":"2026-01-06T10:58:54","slug":"hackers-steal-35m-in-cryptocurrency-following-lastpass-breach","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10490","title":{"rendered":"Hackers Steal $35M in Cryptocurrency Following LastPass Breach"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Russian cybercriminals have laundered over $35 million in stolen cryptocurrency linked to the devastating 2022 LastPass breach, in keeping with new forensic evaluation by blockchain intelligence agency TRM Labs.<\/p>\n<p>The 2022 assault uncovered encrypted <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/signal-app-clone-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">password <\/a>vaults belonging to roughly 30 million prospects worldwide. <\/p>\n<p>Whereas the vaults had been initially protected by encryption, attackers who downloaded them may crack weaker grasp passwords offline, making a multi-year window to steal belongings. <\/p>\n<p>New waves of theft all through 2024 and 2025 have weaponized these compromised credentials, notably focusing on customers holding cryptocurrency.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement\">TRM\u2019s a<\/a><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">n<\/a><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.trmlabs.com\/resources\/blog\/trm-traces-stolen-crypto-from-2022-lastpass-breach-on-chain-indicators-suggest-russian-cybercriminal-involvement\">alysis<\/a> traced roughly $28 million in stolen Bitcoin by Wasabi Pockets, a cryptocurrency mixer designed to obscure transaction trails, and recognized one other $7 million transferring by comparable laundering pathways. <\/p>\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-1024x536.png\" alt=\"attack flow\" class=\"wp-image-173759\" srcset=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-1024x536.png 1024w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-300x157.png 300w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-768x402.png 768w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-1536x804.png 1536w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-2048x1072.png 2048w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-803x420.png 803w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-150x79.png 150w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-696x364.png 696w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-1068x559.png 1068w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-10-1920x1005.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"\/><figcaption class=\"wp-element-caption\">assault circulate<\/figcaption><\/figure>\n<p>The stolen funds in the end converged at two high-risk Russian exchanges: Cryptex (sanctioned by OFAC in 2024) and Audi6, each traditionally linked to cybercriminal exercise.<\/p>\n<p>\u201cThe attackers used a constant operational signature,\u201d TRM researchers defined. Stolen Bitcoin keys had been imported into an identical pockets software program, producing recognizable transaction patterns. <\/p>\n<p>Non-Bitcoin belongings had been quickly transformed to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/bitcoin-depot-breach-exposes-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">Bitcoin <\/a>through swap providers earlier than being deposited into mixing providers, a method that, in principle, ought to obscure criminals\u2019 identities.<\/p>\n<p>But TRM\u2019s proprietary \u201cdemixing\u201d strategies revealed what mixers can&#8217;t cover: behavioral fingerprints that linked exercise earlier than and after mixing to the identical actors. <\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"536\" src=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-1024x536.png\" alt=\"TRM analysts traced approximately USD 7 million in additional stolen funds through Wasabi Wallet\" class=\"wp-image-173760\" srcset=\"https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-1024x536.png 1024w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-300x157.png 300w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-768x402.png 768w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-1536x804.png 1536w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-2048x1072.png 2048w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-803x420.png 803w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-150x79.png 150w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-696x364.png 696w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-1068x559.png 1068w, https:\/\/gbhackers.com\/wp-content\/uploads\/2026\/01\/image-11-1920x1005.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><figcaption class=\"wp-element-caption\">TRM analysts traced roughly USD 7 million in extra stolen funds by Wasabi Pockets<\/figcaption><\/figure>\n<p>Regardless of CoinJoin obfuscation, researchers recognized clustering patterns, withdrawal timing, and pockets interactions that pointed to coordinated Russian cybercrime infrastructure.<\/p>\n<p>The findings underscore two crucial insights. First, mixing providers have gotten much less dependable as menace actors keep constant infrastructure over time. <\/p>\n<p>Second, Russian exchanges proceed functioning as systemic enablers of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/lucid-phaas-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener\">international cybercrime<\/a>, facilitating thousands and thousands in illicit fund transfers regardless of worldwide enforcement strain.<\/p>\n<p>Early Wasabi withdrawals occurred inside days of pockets drains, suggesting that attackers themselves orchestrated the laundering quite than reselling stolen keys to different criminals. <\/p>\n<p>This operational continuity strengthens confidence in attribution of the unique 2022 intrusion to Russian-based actors. Nevertheless, definitive attribution of the unique 2022 intrusion stays unconfirmed.<\/p>\n<p>The LastPass case demonstrates how single credential breaches cascade throughout years, and the way cybercriminal ecosystems exploit geographic monetary infrastructure to monetize stolen knowledge at scale. <\/p>\n<p>For the 25 million affected customers, the menace stays lively a stark reminder that breached credentials symbolize persistent, long-tail threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Observe us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Immediate Updates and Set GBH as a Most popular Supply in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a>.<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Russian cybercriminals have laundered over $35 million in stolen cryptocurrency linked to the devastating 2022 LastPass breach, in keeping with new forensic evaluation by blockchain intelligence agency TRM Labs. The 2022 assault uncovered encrypted password vaults belonging to roughly 30 million prospects worldwide. Whereas the vaults had been initially protected by encryption, attackers who downloaded [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[7273,641,1627,554,7274,1443],"class_list":["post-10490","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-35m","tag-breach","tag-cryptocurrency","tag-hackers","tag-lastpass","tag-steal"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10490"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10490\/revisions"}],"predecessor-version":[{"id":10491,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10490\/revisions\/10491"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10492"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:23:47 UTC -->