#darkBLOG Your Darknet Guide

Home » $4.4 Million of Crypto Stolen with LastPass Hack

$4.4 Million of Crypto Stolen with LastPass Hack

by admin
109 views

Cyber security is constantly under threat with the rise of Darknet hackers and cyber-crime worldwide. In recent events, hackers targeted LastPass and managed to steal $4.4m worth of Crypto in one day. This hack forms part of a much larger attack that has stolen up to $35m worth of crypto assets and continues to do so. But how exactly did they get this right? Let’s take a closer look. 

The Hack

On October 25, 2023, LastPass was the victim of a massive hack which left at least 25 user accounts compromised. But this wasn’t the first time LastPass has been breached. In 2022, LastPass identified a breach which involved one of their employee’s credentials being stolen, giving the hackers access to stored customer data.

https://platform.twitter.com/embed/Tweet.html?dnt=true&embedId=twitter-widget-0&features=eyJ0ZndfdGltZWxpbmVfbGlzdCI6eyJidWNrZXQiOltdLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2ZvbGxvd2VyX2NvdW50X3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9iYWNrZW5kIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19yZWZzcmNfc2Vzc2lvbiI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfZm9zbnJfc29mdF9pbnRlcnZlbnRpb25zX2VuYWJsZWQiOnsiYnVja2V0Ijoib24iLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X21peGVkX21lZGlhXzE1ODk3Ijp7ImJ1Y2tldCI6InRyZWF0bWVudCIsInZlcnNpb24iOm51bGx9LCJ0ZndfZXhwZXJpbWVudHNfY29va2llX2V4cGlyYXRpb24iOnsiYnVja2V0IjoxMjA5NjAwLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3Nob3dfYmlyZHdhdGNoX3Bpdm90c19lbmFibGVkIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19kdXBsaWNhdGVfc2NyaWJlc190b19zZXR0aW5ncyI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdXNlX3Byb2ZpbGVfaW1hZ2Vfc2hhcGVfZW5hYmxlZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdmlkZW9faGxzX2R5bmFtaWNfbWFuaWZlc3RzXzE1MDgyIjp7ImJ1Y2tldCI6InRydWVfYml0cmF0ZSIsInZlcnNpb24iOm51bGx9LCJ0ZndfbGVnYWN5X3RpbWVsaW5lX3N1bnNldCI6eyJidWNrZXQiOnRydWUsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9mcm9udGVuZCI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9fQ%3D%3D&frame=false&hideCard=false&hideThread=false&id=1717901088521687330&lang=en&origin=https%3A%2F%2Flivedarknet.com%2Fp%2F4-4-million-of-crypto-stolen-with-lastpass-hack%2F&sessionId=310310700d460d8fc46cfba8258c1434ada6a05e&theme=light&widgetsVersion=01917f4d1d4cb%3A1696883169554&width=550px

With this latest breach, threat actors managed to gain access to 80+ addresses. They stole keys and key phrases to crypto assets and more. ZachXBT posted on X and said, “We cannot stress this enough, if you believe you may have ever stored your seed phrases or keys in LastPass migrate your crypto assets immediately.”

What Cryptocurrencies were affected:

According to ZachXBT and Taylor Monahan, the MetaMask developer, the blockchains that were hit are Bitcoin, Ethereum, BNB, Arbitrum and Solana. The total amount of currency taken from these accounts was estimated at around $4.4 million. The funds will probably go through several rounds of washing and possibly used on Darknet Markets to get it into cash eventually.

The on-going struggle 

Unfortunately, this isn’t a new experience for LastPass. While it was a significant amount stolen, this has been an ongoing struggle for them. LastPass has repeatedly been victim to theft over the last few years and it hasn’t always been because their systems were compromised. According to Monahn, there are more than 150 people connected to the thefts which add up to over $35 million worth of stolen crypto. 

LastPass has also faced legal action due to the breach they had in August 2022, where approximately $53,000 in Bitcoin was stolen. This breach also led to the theft of a backup of encrypted customer vault data. If decrypted, the hacker would have access to customers’ personal data. In the latest breach, the list of keys stolen was diverse and included 12-24 word seeds, Ethereum presale wallet jsons, wallet.dats. Private keys and more.

How to protect yourself against password hacks

Cybercriminals are constantly getting bolder which is all the more reason why we need to practice caution when it comes to protecting our crypto assets. Here are a few tips to protect yourself against being password hacked:

  1. Change your Password Regularly: Nowadays, devices and sites will warn you if your details have been in a potential leak. Change your password as soon you see this to avoid theft. 
  2. Make your passwords difficult: Choosing an easy password is just asking to get hacked. Ensure that your password is complicated. Use upper and lowercase letters and include numbers and special characters. 
  3. Make long passwords: Short passwords are more likely to be guessed or figured out. The optimal length for a password should be between 8-12 characters. 
  4. Use MFA: Multi-factor Authentication allows you to add multi-level security to your assets. This means to access your assets you’d need to use multiple passwords or verification methods to unlock them.
  5. Use a Password Manager: Password managers make saving and using multiple passwords easier, especially if you struggle to remember your passwords. Password managers generally have a robust security system to ensure your data is safe and free from risk.

You may also like

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00
Verified by MonsterInsights