OAK — OnChain Attack Knowledge

Worked example · 2022-12

LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort — multi-chain — 2022-12 (breach) / 2023-2025 (drains)

Loss
at least ~$35M aggregated across ~150+ individual victims tracked by ZachXBT, Taylor Monahan (MetaMask), and TRM Labs through 2023–2025; the single largest documented victim is Ripple co-founder Chris Larsen, ~$150M (January 2024, federally tied to the LastPass breach in a March 2025 U.S. forfeiture filing). TRM Labs traced over ~$28M converted to BTC and laundered through Wasabi Wallet's CoinJoin in late-2024 / early-2025 plus a further ~$7M wave in September 2025; the public ZachXBT cohort by late-2023 had reached ~$35M across ~150 victims; Krebs / public-source aggregation of the Larsen forfeiture brings the federally-attested portion to ~$150M+. The realised cumulative loss across the multi-year cohort is strongly understated by these public figures — TRM's December 2025 disclosure characterises $35M as "likely a fraction of the full picture." The cohort's structural feature is a single off-chain root cause (the December 2022 LastPass encrypted-vault exfiltration) chaining into a multi-year, multi-victim drain campaign as attackers brute-forced master passwords and harvested the seed phrases that LastPass users had stored in the password manager's "Secure Notes" feature.
Recovery
partial federal seizure: U.S. federal prosecutors in the Northern District of California seized approximately ~$24M in cryptocurrency (March 2025 forfeiture filing in the Larsen case) of the ~$150M Larsen heist; the remainder of the cohort's ~$35M+ aggregate loss is largely unrecovered — proceeds were laundered through Wasabi Wallet CoinJoin, the now-defunct Cryptomixer.io, and off-ramped via Russian exchanges including Cryptex (OFAC-sanctioned 2024) and Audi6. No civil-recovery action has been filed against LastPass / GoTo at v0.1 reporting horizon; LastPass / GoTo has publicly disputed the causal link from the breach to the crypto thefts despite the multi-source forensic record. Affected individuals have largely had to absorb the loss; victim-side recovery is limited to the federal seizure portion of the Larsen heist.
OAK Techniques observed
OAK-T11.006 (Cold-storage Seed-phrase Exfiltration at Rest), OAK-T11.006.001 (User-Initiated Plaintext-Equivalent Seed Storage) — canonical anchor case. The case does not fit any of the prior v0.1 T11 sub-Techniques: T11.001 covers signing-vendor UI compromise (Bybit / Safe{Wallet} pattern, organisational-customer victim shape); T11.002 covers wallet-software distribution compromise (Atomic Wallet pattern, vendor-side build-pipeline / update-channel surface); T11.003 covers in-use multisig contract manipulation (WazirX pattern). The LastPass cohort's failure surface is a third-party password-manager service holding plaintext-equivalent seed-phrase material at rest — neither a signing-vendor UI nor a wallet-binary distribution surface, and neither a contract-modification nor a phishing-driven authority grant. OAK-T7.001 (Mixer-Routed Hop) chains downstream as a load-bearing laundering rail — Wasabi Wallet's built-in CoinJoin is the dominant T7.001 surface for the cohort. OAK-T7.002 (CEX Deposit-Address Layering) chains downstream — the Russian-exchange off-ramp via Cryptex (OFAC-sanctioned) and Audi6 is the canonical OAK-G03-adjacent CEX-layering surface for this cohort.
Attribution
inferred-strong at the cohort level — the multi-source forensic chain (ZachXBT cohort tracking from late-2023, Taylor Monahan / MetaMask researcher analysis, Brian Krebs investigative reporting from September 2023, TRM Labs December 2025 demixing analysis, U.S. federal forfeiture filing in the Larsen case) converges on a coherent operator-cluster-level attribution to Russian-cybercriminal infrastructure (OAK-G03-adjacent; on-chain off-ramps include Cryptex which is OFAC-sanctioned for ransomware-related laundering). The attribution does not rise to confirmed under OAK convention at v0.1 because there is no DOJ named-individual indictment naming a specific operator behind the broader cohort drains — the federal action to date is the forfeiture in the Larsen heist, which establishes the federal record but does not name the perpetrator. LastPass / GoTo continues to publicly dispute the causal link from the breach to the crypto thefts despite the forensic chain. ZachXBT and Taylor Monahan's per-victim cohort analysis converges on the LastPass commonality through a process-of-elimination methodology (victims had not been SIM-swapped, email-compromised, mobile-phone-compromised; the singular commonality is that each had stored seed phrases in LastPass Secure Notes prior to the December 2022 vault exfiltration). Connection between the broader cohort drains and the Scattered Spider attribution chain (Scattered Spider members later admitted in DOJ filings to launching the SMS-phishing attacks that produced the LastPass vault exfiltration) anchors the off-chain entry-vector attribution; the on-chain drainer-cluster operator(s) remain pseudonymous at the named-individual level.
Key teaching point
a third-party password-manager service that user-side stores plaintext-equivalent seed-phrase material at rest is structurally indistinguishable from custodial storage of the underlying assets, and the December 2022 LastPass encrypted-vault exfiltration produced a multi-year, multi-victim drain campaign because (a) the vault encryption was master-password-bound and (b) master-password strength varied across the user base such that a fraction of vaults were brute-forceable offline by attackers with sufficient compute. The structural OAK lesson is that seed-phrase-at-rest in a third-party storage service is a custody surface the user did not realise they had created — the user's mental model is "I'm self-custodial because I hold my own keys" but the third-party password-manager is custodial of the credential that controls the keys. The defender lesson is that seed-phrase storage hygiene (cold storage on physical media, no third-party-service storage, no auto-synced cloud-storage including iCloud / Google Drive / OneDrive) is the load-bearing user-side T11 mitigation surface, structurally distinct from the wallet-software-side mitigations that dominate T11.002 worked examples. The case is also the canonical example of attack-vector-time-shift in the T11 family: the exfiltration event was December 2022 but the realised drains span 2023–2025 because brute-forcing weak master passwords offline takes time, and the cohort's losses continue to accumulate at v0.1 reporting horizon. Defender practice for any user with non-trivial crypto exposure should include immediate seed-phrase rotation if seed material was ever stored in a third-party password manager whose vaults have been exfiltrated, regardless of how strong the master password was thought to be at the time of storage.

Summary

LastPass is a major password-manager service operated by GoTo (formerly LogMeIn) with approximately 30 million users. LastPass users can store arbitrary text in a "Secure Notes" field protected by the same vault encryption as stored passwords; through the mid-2010s and 2020s, a non-trivial fraction of crypto-holding LastPass users used this Secure Notes feature to store cryptocurrency wallet seed phrases (12 / 18 / 24-word BIP39 mnemonics) and private keys. The vault encryption is master-password-bound — the master password is the user-side input that derives the vault decryption key — meaning that an exfiltrated vault can be brute-forced offline if the master password is weak.

In August 2022, attackers compromised a LastPass developer's workstation and gained access to LastPass internal systems. The intrusion expanded through November 2022; in December 2022, LastPass disclosed that backup copies of customer vaults — encrypted containers holding the credentials, Secure Notes, and other vault data of approximately 30 million customers — had been exfiltrated. The attribution chain to Scattered Spider was established later when Scattered Spider members admitted in DOJ proceedings to having launched the SMS-phishing attacks that produced intrusions at LastPass and several other technology companies in 2022.

Once the encrypted vaults were in attacker hands, the offline-brute-force window opened. Attackers with sufficient compute (and prioritisation logic favouring vaults whose Secure Notes contained crypto-related text — a heuristic discoverable from vault metadata patterns even before decryption) began systematically cracking weak master passwords. Throughout 2023–2025, the brute-forced vaults yielded seed phrases and private keys, which were then used to drain the corresponding on-chain wallets.

The drain campaign exhibits three characteristic phases:

  • Late 2023 (the ZachXBT cohort): from approximately October 2023 onward, ZachXBT and Taylor Monahan (MetaMask) began publicly tracking a cohort of crypto-theft victims who had no other commonality (no SIM-swap, no email compromise, no mobile-phone malware, no phishing) other than having stored seed phrases in LastPass Secure Notes. By late 2023, ZachXBT had publicly tracked ~$35M across ~150 victims linked to the LastPass commonality; Brian Krebs (Krebs on Security) published an investigative summary in September 2023 establishing the public-record link from the cohort to the LastPass breach.
  • January 2024 (the Larsen heist): ~$150M in XRP was stolen from Ripple co-founder Chris Larsen on January 30, 2024. ZachXBT was the first to publicly identify the heist; in March 2025, U.S. federal prosecutors filed a forfeiture action in the Northern District of California establishing the federal-record link from the Larsen heist to the LastPass breach and seizing approximately ~$24M of the proceeds. The Larsen heist is the largest single victim in the LastPass cohort and is the case that took the cohort attribution from inferred-strong (industry-forensic) to confirmed-at-the-federal-record level for that specific incident — the broader cohort's attribution remains inferred-strong because the federal action covers the Larsen heist, not the broader cohort.
  • Late 2024 / 2025 (the TRM Labs reconciliation): in December 2025, TRM Labs published demixing analysis of the cohort's laundering chain. The analysis traced ~$28M of the cohort's stolen funds converted to BTC and laundered through Wasabi Wallet's built-in CoinJoin in late-2024 / early-2025, plus a further ~$7M wave detected in September 2025 (also Wasabi-routed, off-ramped to Audi6). The pre-Wasabi-CoinJoin laundering rail used Cryptomixer.io (now defunct) and the Russian exchange Cryptex (OFAC-sanctioned September 2024). The TRM analysis identified Russian-cybercriminal infrastructure as the dominant operator-cluster fingerprint across the cohort.

Throughout the multi-year campaign, LastPass / GoTo has publicly disputed the causal link from the breach to the crypto thefts. The dispute is structurally weak — the multi-source forensic chain (ZachXBT cohort process-of-elimination, the Larsen federal forfeiture filing, TRM's demixing of the laundering rail to Russian-cybercriminal infrastructure, the per-victim consistency of the LastPass-Secure-Notes commonality) converges on the breach as the proximate root cause. As of v0.1 reporting horizon, no civil-recovery action has been filed against LastPass / GoTo by the affected cohort; victim-side recovery is limited to the federal seizure portion of the Larsen heist.

For OAK's purposes, the LastPass cohort is the canonical worked example for OAK-T11.006 sub-pattern T11.006.001 (user-initiated plaintext-equivalent storage). The case structurally extended the T11 framework — the v0.1-freeze T11 worked examples (Bybit / Safe{Wallet} for T11.001, Atomic Wallet for T11.002, WazirX for T11.003) all share an organisational-customer-or-vendor-side compromise shape, while the LastPass cohort anchors the third-party storage-service-at-rest failure surface that is structurally distinct and that the prior T11.001 / T11.002 / T11.003 sub-Techniques do not cover. The case is the headline anchor for T11.006 (Cold-storage Seed-phrase Exfiltration at Rest), promoted from TAXONOMY-GAPS to canonical emerging-maturity Technique at v0.x.

Timeline (UTC)

When Event OAK ref
Pre-2022 LastPass users (cohort fraction unknown but non-trivial) store crypto wallet seed phrases in LastPass "Secure Notes" feature; vault encryption is master-password-bound (latent surface — cold-storage-at-rest precondition)
2022-08 Attackers compromise a LastPass developer's workstation; intrusion begins (off-chain entry vector — Scattered Spider SMS-phishing attribution per later DOJ filings)
2022-11 Attackers access LastPass production backup; encrypted-vault exfiltration completed (T11.x cold-storage exfiltration event)
2022-12 LastPass discloses that backup copies of customer vaults were exfiltrated; ~30M customers affected (vendor-side disclosure)
2023-Q1 onward Attackers begin offline brute-force of weak master passwords; first wave of crypto drains begins T11.x cold-storage exfiltration at rest — drain phase begins
2023-09 Brian Krebs publishes investigative summary linking the crypto-theft cohort to the LastPass breach; ~$35M / ~150 victims at this point (public-record establishment of the cohort attribution)
2023-10-25 ~$4.4M drained in a single day across ~25 LastPass-cohort victims; ZachXBT and Taylor Monahan publicly tracking T11.x drain-cohort acceleration
2023-11 ZachXBT public on-chain analysis: ~$5.36M drained from ~40 victim addresses linked to the LastPass cohort (industry-forensic cohort tracking)
2024-01-30 ~$150M in XRP stolen from Ripple co-founder Chris Larsen T11.x — largest single LastPass-cohort victim
2024-late / 2025-early ~$28M of cohort proceeds laundered through Wasabi Wallet CoinJoin; pre-mix off-ramp via Cryptex (OFAC-sanctioned 2024-09) T7.001 (Wasabi CoinJoin) + T7.002 (Russian-CEX off-ramp)
2025-03 U.S. federal prosecutors (NDCA) file forfeiture action in the Larsen heist; ~$24M seized; federal-record link to LastPass breach established federal-record attribution (Larsen heist specific)
2025-09 Subsequent wave of ~$7M cohort proceeds detected; same Wasabi-routed laundering chain; off-ramp to Audi6 (Russian exchange) (cohort drain campaign continues)
2025-12 TRM Labs publishes demixing analysis of the cohort's laundering chain; Russian-cybercriminal infrastructure attribution (industry-forensic attribution-strength reinforcement)
Continuing Drain campaign continues at v0.1 reporting horizon (May 2026); cumulative loss ~$35M+ across ~150+ victims plus ~$150M Larsen heist; LastPass / GoTo continues to dispute the causal link (cohort drain-campaign open)

What defenders observed

  • The exfiltration-to-drain time window is multi-year, not multi-day, because brute-forcing weak master passwords offline takes time. The LastPass cohort's drain campaign began ~Q1 2023 (months after the December 2022 disclosure) and continues at v0.1 reporting horizon (May 2026). This is the structural distinguishing feature of the cold-storage-at-rest exfiltration sub-class versus the more familiar T11.001 / T11.002 patterns where the off-chain compromise produces extraction within hours or days. Defender practice for any user whose seed-phrase material was ever stored in a third-party service whose vaults were exfiltrated should treat the seed phrase as permanently compromised regardless of how strong the master password / encryption was at the time of storage — the brute-force window is unbounded once the encrypted material is in attacker hands. Seed-phrase rotation is the only operational response.
  • The cohort attribution converges through process-of-elimination across per-victim forensics. ZachXBT and Taylor Monahan's methodology — interviewing each victim about non-LastPass attack vectors (SIM swap, email compromise, mobile-phone malware, phishing) and finding none — produced the LastPass-commonality observation independently of any vendor-side disclosure or breach-attribution. The defender / industry-forensic lesson is that per-victim cohort analysis can establish attribution even when the vendor disputes the causal link. This pattern recurs across the OAK corpus where vendor-side disclosure is constrained by litigation strategy or organisational-reputation considerations; the per-victim cohort methodology is the cleanest forensic surface in those cases.
  • The laundering chain converges on Russian-cybercriminal infrastructure (OAK-G03-adjacent), not on OAK-G01. The LastPass cohort's laundering rail is structurally distinct from the dominant 2024–2025 OAK-G01 (Lazarus) laundering rail (THORChain T7.003 + restaking T7.x). The LastPass cohort uses Wasabi Wallet CoinJoin (T7.001) plus Russian-CEX off-ramps (Cryptex, Audi6) — a 2022–2024-era OAK-G03 pattern. The defender / attribution lesson is that not all large multi-victim crypto-theft cohorts are OAK-G01-attributable; the laundering-chain fingerprint is one of the cleanest signals for cluster-level attribution, and the LastPass cohort's fingerprint points to OAK-G03-adjacent Russian-cybercriminal infrastructure. Contributors writing future T11 worked examples should preserve the laundering-chain-as-attribution-signal dimension explicitly.
  • The federal-record establishment lags the industry-forensic attribution by 18+ months. ZachXBT's public-record link from the cohort to LastPass landed in late 2023; the federal forfeiture filing in the Larsen heist landed in March 2025 — ~16 months later. The defender / framework-credibility lesson is that federal-record attribution is a meaningful but slow signal, and the OAK convention's confirmed threshold (DOJ named-actor / regulator action) is structurally biased against fast-moving cohorts where the industry-forensic record is complete months-to-years before federal action lands. Contributors writing future T11 worked examples should preserve the federal-record-vs-industry-forensic timing dimension explicitly and should not under-weight industry-forensic attribution at the inferred-strong level when the federal record has not yet caught up.
  • LastPass / GoTo's continued public denial of the causal link is structurally weak but operationally meaningful. The vendor's public position constrains civil-recovery options for the affected cohort; absent vendor-side acknowledgment of causation, the affected cohort's recovery surface is limited to (a) the federal seizure portion of cases that reach federal forfeiture (the Larsen heist), and (b) potential class-action litigation that is slow and uncertain. The defender / contributor lesson is that vendor-side denial of causation is a recurring T11 pattern (see also Atomic Wallet's constrained post-mortem disclosure under litigation pressure); the OAK worked-example layer should document this pattern as a structural feature of the T11 family rather than as anomalous to any single case.

What this example tells contributors writing future Technique pages

  • The T11 framework needs an explicit cold-storage-seed-phrase-exfiltration-at-rest sub-Technique. The LastPass cohort is the canonical worked example for this sub-class. The case does not fit T11.001 (signing-vendor UI compromise — organisational-customer victim shape, not third-party-storage-at-rest), T11.002 (wallet-software distribution compromise — vendor-side build-pipeline / update-channel surface, not third-party-storage), or T11.003 (multisig contract manipulation — contract-modification, not storage). Contributors writing the Mitigations layer should pre-position the seed-phrase-storage-hygiene mitigation surface (cold storage on physical media, no third-party-service storage, no auto-synced cloud-storage) as a first-class T11 control independently of wallet-software-side mitigations, with the LastPass cohort as the proximate-causal worked example.
  • Attack-vector-time-shift is a structural feature of the cold-storage-at-rest sub-class. The exfiltration event was December 2022; realised drains span 2023–2025 (and continue at v0.1 reporting horizon). Contributors writing future T11.x worked examples in this sub-class should preserve the multi-year drain-window dimension explicitly, and should not over-anchor on the exfiltration date as the "incident date." The OAK convention should treat such cases as cohort-window incidents with a documented exfiltration date and a documented (open or closed) drain window.
  • Per-victim cohort analysis is the canonical forensic methodology for this sub-class. The LastPass cohort's attribution converges through process-of-elimination across per-victim forensics by ZachXBT and Taylor Monahan. Contributors writing future T11.x worked examples should preserve the per-victim cohort methodology as a first-class attribution surface, and should not under-weight industry-forensic per-victim cohort tracking relative to vendor-side disclosure or federal-record establishment.
  • Vendor-side denial of causation is a recurring T11 pattern that contributors should document explicitly. LastPass / GoTo continues to dispute the causal link at v0.1 reporting horizon. The pattern recurs across the T11 family (Atomic Wallet's constrained post-mortem; broader vendor-litigation-strategy constraints). Contributors writing future T11 worked examples should treat vendor-side disclosure as a first-class observable (sometimes present, sometimes absent, sometimes actively disputed) rather than as a baseline assumption.
  • Laundering-chain fingerprint is a load-bearing cluster-attribution signal across the T11 family. The LastPass cohort's Wasabi-CoinJoin + Russian-CEX-off-ramp fingerprint anchors the OAK-G03-adjacent attribution. The dominant OAK-G01 fingerprint (THORChain T7.003 + restaking T7.x) is structurally distinct. Contributors writing future T11 worked examples should report the laundering-chain fingerprint explicitly as part of the attribution analysis, not as an afterthought.
  • The realised-loss-versus-cohort-size dimension matters and should be reported separately. The LastPass cohort's headline figure (~$35M-$150M+ depending on Larsen-included scope) understates structural systemic risk because the cohort size (~150+ victims) makes the per-victim distribution heavy-tailed (the Larsen heist alone is >$150M; the median per-victim loss is in the high-five-figure to low-six-figure range). Contributors writing future T11.x cohort worked examples should report (a) cumulative loss, (b) cohort size, (c) per-victim distribution shape (median, max, heavy-tail observation), and (d) the cohort-window dimension (exfiltration date, drain-window state).

Public references

  • [krebslastpass2023] — Krebs on Security, "What's in a PR Statement: LastPass Breach Explained" / September 2023 cohort summary establishing the public-record link from ~$35M / ~150-victim cohort to the LastPass breach.
  • [krebslastpass2025] — Krebs on Security, "Feds Link $150M Cyberheist to 2022 LastPass Hacks" (March 2025); covers the Larsen-heist federal forfeiture filing and the ~$24M federal seizure.
  • [trmlabslastpass2025] — TRM Labs, "TRM Traces Stolen Crypto from 2022 LastPass Breach — On-chain Indicators Suggest Russian Cybercriminal Involvement" (December 2025); demixing analysis of the cohort's laundering chain through Wasabi CoinJoin and Russian exchanges.
  • [zachxbtlastpass2023] — ZachXBT public on-chain cohort tracking from October 2023 onward; per-victim cohort process-of-elimination analysis.
  • [theblocklastpass2023] — The Block, "LastPass threat actor drains $5.4 million in crypto from over 40 victim addresses: ZachXBT" (October 2023); industry-press summary of the cohort.
  • [bleepinglastpass2025] — BleepingComputer, "Cryptocurrency theft attacks traced to 2022 LastPass breach"; secondary forensic-coverage source.
  • [hackernewslastpass2025] — The Hacker News, "LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds" (December 2025); secondary coverage of the TRM analysis.
  • [infosecuritylastpass2023] — Infosecurity Magazine, "Experts Trace $35m in Stolen Crypto to LastPass Breach"; secondary coverage of the late-2023 cohort.
  • [cointelegraphlarsen2024] — Cointelegraph, "Ripple co-founder Larsen's $150M XRP theft linked to LastPass breach"; primary coverage of the Larsen heist.
  • [lastpassbreachdisclosure2022] — LastPass / GoTo official disclosure, December 2022 customer-vault exfiltration announcement.

Citations

Existing citation keys reused: none directly — this is the first OAK example in the cold-storage-seed-phrase-exfiltration-at-rest sub-class.

Proposed new BibTeX entries (added to citations.bib as part of this batch):

  • [krebslastpass2023] — Krebs on Security 2023 cohort summary; primary investigative-journalism source for the public-record cohort attribution.
  • [krebslastpass2025] — Krebs on Security 2025 federal-forfeiture-filing summary; primary source for the Larsen-heist federal-record link.
  • [trmlabslastpass2025] — TRM Labs December 2025 demixing analysis; primary source for the laundering-chain fingerprint and the Russian-cybercriminal cluster attribution.
  • [zachxbtlastpass2023] — ZachXBT public on-chain cohort tracking; primary source for the per-victim cohort process-of-elimination.
  • [theblocklastpass2023] — The Block, October 2023 cohort summary; primary press-coverage source.
  • [bleepinglastpass2025] — BleepingComputer; secondary forensic-coverage source.
  • [hackernewslastpass2025] — The Hacker News, December 2025 TRM-analysis coverage; secondary source.
  • [infosecuritylastpass2023] — Infosecurity Magazine; secondary coverage.
  • [cointelegraphlarsen2024] — Cointelegraph; primary coverage of the Larsen heist linkage.
  • [lastpassbreachdisclosure2022] — LastPass / GoTo official disclosure; primary vendor-side source for the December 2022 vault-exfiltration disclosure.

Discussion

The LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort is OAK's canonical v0.1 worked example for the cold-storage seed-phrase exfiltration at rest sub-class within T11. The case is operationally instructive in five distinct dimensions: (a) the third-party-storage-service-at-rest failure surface is structurally distinct from the v0.1 T11.001 / T11.002 / T11.003 sub-Techniques; (b) the multi-year exfiltration-to-drain time window is a structural feature of the sub-class, not a peculiarity of this case; (c) the per-victim cohort attribution methodology (ZachXBT, Taylor Monahan) establishes attribution independently of vendor-side disclosure; (d) the laundering-chain fingerprint (Wasabi CoinJoin + Russian-CEX off-ramps) anchors the OAK-G03-adjacent operator-cluster attribution; (e) the vendor-side denial-of-causation is a recurring T11 pattern that constrains civil-recovery options for the affected cohort.

The structural significance for the broader T11 framework is the empirical demonstration that a third-party password-manager service that user-side stores plaintext-equivalent seed-phrase material at rest is a custody surface the user did not realise they had created. The user's mental model of self-custody — "I hold my own keys" — collapses when the seed-phrase material is stored in a third-party service whose security posture is outside the user's control. The structural OAK lesson generalises beyond LastPass: any third-party service that stores plaintext-equivalent seed-phrase material at rest (LastPass, 1Password, Bitwarden if Secure-Notes-equivalent is used, iCloud Notes / Drive, Google Drive, Dropbox, OneDrive, browser-saved passwords, screenshot in cloud-synced gallery, email drafts) is a custody surface that constrains the user's effective custody posture to the security posture of the third-party service. The defender / Mitigations-layer lesson is that seed-phrase storage hygiene (cold storage on physical media, no third-party-service storage, no auto-synced cloud-storage) is a first-class user-side T11 mitigation surface that the v0.1 T11 sub-Techniques do not currently cover.

The case is structurally distinct from the iCloud-backup MetaMask cohort (April 2022, ~$650K Dominic Iacovone case + cohort) at the third-party-storage-service shape layer: iCloud-backup-of-MetaMask-vault is auto-synced encrypted-at-rest cloud storage tied to the user's Apple ID security posture, while LastPass-Secure-Notes-storage-of-seed-phrase is user-initiated plaintext-equivalent storage tied to the user's master password. Both fall under the proposed T11.x cold-storage-seed-phrase-exfiltration-at-rest sub-class, but the per-incident shape differs (cloud-account compromise via SIM-swap or phishing for the iCloud cohort; vault exfiltration plus master-password brute-force for the LastPass cohort). Contributors writing future T11.x worked examples should preserve the per-incident-shape distinction explicitly.

For OAK's broader credibility, including the LastPass cohort in v0.1 closes a structural gap: T11 at v0.1 freeze covered organisational-customer / vendor-side compromise (T11.001), wallet-software distribution compromise (T11.002), and in-use multisig contract manipulation (T11.003), but did not cover the third-party-storage-service-at-rest failure surface that the LastPass cohort exhibits. The case operationalises the cold-storage-seed-phrase-exfiltration-at-rest sub-class into a live empirical anchor, anchors the architectural distinction between the third-party-storage shape and the vendor-side compromise shapes that dominate v0.1 T11, and provides contributors writing future T11.x worked examples with a tone-and-structure precedent for the cold-storage-at-rest sub-class.

The cohort is open at v0.1 reporting horizon. The brute-force window is unbounded once the encrypted vault material is in attacker hands; cohort drains continue to accumulate; further demixing analyses of the laundering chain will likely surface additional victims and additional realised loss. Contributors maintaining this worked example post-v0.1 should treat the cohort-window dimension as live and should update the cumulative-loss figure as further forensic analyses land.

Techniques demonstrated (4)