Worked example · 2022-12
LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort — multi-chain — 2022-12 (breach) / 2023-2025 (drains)
Summary
LastPass is a major password-manager service operated by GoTo (formerly LogMeIn) with approximately 30 million users. LastPass users can store arbitrary text in a "Secure Notes" field protected by the same vault encryption as stored passwords; through the mid-2010s and 2020s, a non-trivial fraction of crypto-holding LastPass users used this Secure Notes feature to store cryptocurrency wallet seed phrases (12 / 18 / 24-word BIP39 mnemonics) and private keys. The vault encryption is master-password-bound — the master password is the user-side input that derives the vault decryption key — meaning that an exfiltrated vault can be brute-forced offline if the master password is weak.
In August 2022, attackers compromised a LastPass developer's workstation and gained access to LastPass internal systems. The intrusion expanded through November 2022; in December 2022, LastPass disclosed that backup copies of customer vaults — encrypted containers holding the credentials, Secure Notes, and other vault data of approximately 30 million customers — had been exfiltrated. The attribution chain to Scattered Spider was established later when Scattered Spider members admitted in DOJ proceedings to having launched the SMS-phishing attacks that produced intrusions at LastPass and several other technology companies in 2022.
Once the encrypted vaults were in attacker hands, the offline-brute-force window opened. Attackers with sufficient compute (and prioritisation logic favouring vaults whose Secure Notes contained crypto-related text — a heuristic discoverable from vault metadata patterns even before decryption) began systematically cracking weak master passwords. Throughout 2023–2025, the brute-forced vaults yielded seed phrases and private keys, which were then used to drain the corresponding on-chain wallets.
The drain campaign exhibits three characteristic phases:
- Late 2023 (the ZachXBT cohort): from approximately October 2023 onward, ZachXBT and Taylor Monahan (MetaMask) began publicly tracking a cohort of crypto-theft victims who had no other commonality (no SIM-swap, no email compromise, no mobile-phone malware, no phishing) other than having stored seed phrases in LastPass Secure Notes. By late 2023, ZachXBT had publicly tracked ~$35M across ~150 victims linked to the LastPass commonality; Brian Krebs (Krebs on Security) published an investigative summary in September 2023 establishing the public-record link from the cohort to the LastPass breach.
- January 2024 (the Larsen heist): ~$150M in XRP was stolen from Ripple co-founder Chris Larsen on January 30, 2024. ZachXBT was the first to publicly identify the heist; in March 2025, U.S. federal prosecutors filed a forfeiture action in the Northern District of California establishing the federal-record link from the Larsen heist to the LastPass breach and seizing approximately ~$24M of the proceeds. The Larsen heist is the largest single victim in the LastPass cohort and is the case that took the cohort attribution from
inferred-strong(industry-forensic) toconfirmed-at-the-federal-record levelfor that specific incident — the broader cohort's attribution remainsinferred-strongbecause the federal action covers the Larsen heist, not the broader cohort. - Late 2024 / 2025 (the TRM Labs reconciliation): in December 2025, TRM Labs published demixing analysis of the cohort's laundering chain. The analysis traced ~$28M of the cohort's stolen funds converted to BTC and laundered through Wasabi Wallet's built-in CoinJoin in late-2024 / early-2025, plus a further ~$7M wave detected in September 2025 (also Wasabi-routed, off-ramped to Audi6). The pre-Wasabi-CoinJoin laundering rail used Cryptomixer.io (now defunct) and the Russian exchange Cryptex (OFAC-sanctioned September 2024). The TRM analysis identified Russian-cybercriminal infrastructure as the dominant operator-cluster fingerprint across the cohort.
Throughout the multi-year campaign, LastPass / GoTo has publicly disputed the causal link from the breach to the crypto thefts. The dispute is structurally weak — the multi-source forensic chain (ZachXBT cohort process-of-elimination, the Larsen federal forfeiture filing, TRM's demixing of the laundering rail to Russian-cybercriminal infrastructure, the per-victim consistency of the LastPass-Secure-Notes commonality) converges on the breach as the proximate root cause. As of v0.1 reporting horizon, no civil-recovery action has been filed against LastPass / GoTo by the affected cohort; victim-side recovery is limited to the federal seizure portion of the Larsen heist.
For OAK's purposes, the LastPass cohort is the canonical worked example for OAK-T11.006 sub-pattern T11.006.001 (user-initiated plaintext-equivalent storage). The case structurally extended the T11 framework — the v0.1-freeze T11 worked examples (Bybit / Safe{Wallet} for T11.001, Atomic Wallet for T11.002, WazirX for T11.003) all share an organisational-customer-or-vendor-side compromise shape, while the LastPass cohort anchors the third-party storage-service-at-rest failure surface that is structurally distinct and that the prior T11.001 / T11.002 / T11.003 sub-Techniques do not cover. The case is the headline anchor for T11.006 (Cold-storage Seed-phrase Exfiltration at Rest), promoted from TAXONOMY-GAPS to canonical emerging-maturity Technique at v0.x.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-2022 | LastPass users (cohort fraction unknown but non-trivial) store crypto wallet seed phrases in LastPass "Secure Notes" feature; vault encryption is master-password-bound | (latent surface — cold-storage-at-rest precondition) |
| 2022-08 | Attackers compromise a LastPass developer's workstation; intrusion begins | (off-chain entry vector — Scattered Spider SMS-phishing attribution per later DOJ filings) |
| 2022-11 | Attackers access LastPass production backup; encrypted-vault exfiltration completed | (T11.x cold-storage exfiltration event) |
| 2022-12 | LastPass discloses that backup copies of customer vaults were exfiltrated; ~30M customers affected | (vendor-side disclosure) |
| 2023-Q1 onward | Attackers begin offline brute-force of weak master passwords; first wave of crypto drains begins | T11.x cold-storage exfiltration at rest — drain phase begins |
| 2023-09 | Brian Krebs publishes investigative summary linking the crypto-theft cohort to the LastPass breach; ~$35M / ~150 victims at this point | (public-record establishment of the cohort attribution) |
| 2023-10-25 | ~$4.4M drained in a single day across ~25 LastPass-cohort victims; ZachXBT and Taylor Monahan publicly tracking | T11.x drain-cohort acceleration |
| 2023-11 | ZachXBT public on-chain analysis: ~$5.36M drained from ~40 victim addresses linked to the LastPass cohort | (industry-forensic cohort tracking) |
| 2024-01-30 | ~$150M in XRP stolen from Ripple co-founder Chris Larsen | T11.x — largest single LastPass-cohort victim |
| 2024-late / 2025-early | ~$28M of cohort proceeds laundered through Wasabi Wallet CoinJoin; pre-mix off-ramp via Cryptex (OFAC-sanctioned 2024-09) | T7.001 (Wasabi CoinJoin) + T7.002 (Russian-CEX off-ramp) |
| 2025-03 | U.S. federal prosecutors (NDCA) file forfeiture action in the Larsen heist; ~$24M seized; federal-record link to LastPass breach established | federal-record attribution (Larsen heist specific) |
| 2025-09 | Subsequent wave of ~$7M cohort proceeds detected; same Wasabi-routed laundering chain; off-ramp to Audi6 (Russian exchange) | (cohort drain campaign continues) |
| 2025-12 | TRM Labs publishes demixing analysis of the cohort's laundering chain; Russian-cybercriminal infrastructure attribution | (industry-forensic attribution-strength reinforcement) |
| Continuing | Drain campaign continues at v0.1 reporting horizon (May 2026); cumulative loss ~$35M+ across ~150+ victims plus ~$150M Larsen heist; LastPass / GoTo continues to dispute the causal link | (cohort drain-campaign open) |
What defenders observed
- The exfiltration-to-drain time window is multi-year, not multi-day, because brute-forcing weak master passwords offline takes time. The LastPass cohort's drain campaign began ~Q1 2023 (months after the December 2022 disclosure) and continues at v0.1 reporting horizon (May 2026). This is the structural distinguishing feature of the cold-storage-at-rest exfiltration sub-class versus the more familiar T11.001 / T11.002 patterns where the off-chain compromise produces extraction within hours or days. Defender practice for any user whose seed-phrase material was ever stored in a third-party service whose vaults were exfiltrated should treat the seed phrase as permanently compromised regardless of how strong the master password / encryption was at the time of storage — the brute-force window is unbounded once the encrypted material is in attacker hands. Seed-phrase rotation is the only operational response.
- The cohort attribution converges through process-of-elimination across per-victim forensics. ZachXBT and Taylor Monahan's methodology — interviewing each victim about non-LastPass attack vectors (SIM swap, email compromise, mobile-phone malware, phishing) and finding none — produced the LastPass-commonality observation independently of any vendor-side disclosure or breach-attribution. The defender / industry-forensic lesson is that per-victim cohort analysis can establish attribution even when the vendor disputes the causal link. This pattern recurs across the OAK corpus where vendor-side disclosure is constrained by litigation strategy or organisational-reputation considerations; the per-victim cohort methodology is the cleanest forensic surface in those cases.
- The laundering chain converges on Russian-cybercriminal infrastructure (OAK-G03-adjacent), not on OAK-G01. The LastPass cohort's laundering rail is structurally distinct from the dominant 2024–2025 OAK-G01 (Lazarus) laundering rail (THORChain T7.003 + restaking T7.x). The LastPass cohort uses Wasabi Wallet CoinJoin (T7.001) plus Russian-CEX off-ramps (Cryptex, Audi6) — a 2022–2024-era OAK-G03 pattern. The defender / attribution lesson is that not all large multi-victim crypto-theft cohorts are OAK-G01-attributable; the laundering-chain fingerprint is one of the cleanest signals for cluster-level attribution, and the LastPass cohort's fingerprint points to OAK-G03-adjacent Russian-cybercriminal infrastructure. Contributors writing future T11 worked examples should preserve the laundering-chain-as-attribution-signal dimension explicitly.
- The federal-record establishment lags the industry-forensic attribution by 18+ months. ZachXBT's public-record link from the cohort to LastPass landed in late 2023; the federal forfeiture filing in the Larsen heist landed in March 2025 — ~16 months later. The defender / framework-credibility lesson is that federal-record attribution is a meaningful but slow signal, and the OAK convention's
confirmedthreshold (DOJ named-actor / regulator action) is structurally biased against fast-moving cohorts where the industry-forensic record is complete months-to-years before federal action lands. Contributors writing future T11 worked examples should preserve the federal-record-vs-industry-forensic timing dimension explicitly and should not under-weight industry-forensic attribution at theinferred-stronglevel when the federal record has not yet caught up. - LastPass / GoTo's continued public denial of the causal link is structurally weak but operationally meaningful. The vendor's public position constrains civil-recovery options for the affected cohort; absent vendor-side acknowledgment of causation, the affected cohort's recovery surface is limited to (a) the federal seizure portion of cases that reach federal forfeiture (the Larsen heist), and (b) potential class-action litigation that is slow and uncertain. The defender / contributor lesson is that vendor-side denial of causation is a recurring T11 pattern (see also Atomic Wallet's constrained post-mortem disclosure under litigation pressure); the OAK worked-example layer should document this pattern as a structural feature of the T11 family rather than as anomalous to any single case.
What this example tells contributors writing future Technique pages
- The T11 framework needs an explicit cold-storage-seed-phrase-exfiltration-at-rest sub-Technique. The LastPass cohort is the canonical worked example for this sub-class. The case does not fit T11.001 (signing-vendor UI compromise — organisational-customer victim shape, not third-party-storage-at-rest), T11.002 (wallet-software distribution compromise — vendor-side build-pipeline / update-channel surface, not third-party-storage), or T11.003 (multisig contract manipulation — contract-modification, not storage). Contributors writing the Mitigations layer should pre-position the seed-phrase-storage-hygiene mitigation surface (cold storage on physical media, no third-party-service storage, no auto-synced cloud-storage) as a first-class T11 control independently of wallet-software-side mitigations, with the LastPass cohort as the proximate-causal worked example.
- Attack-vector-time-shift is a structural feature of the cold-storage-at-rest sub-class. The exfiltration event was December 2022; realised drains span 2023–2025 (and continue at v0.1 reporting horizon). Contributors writing future T11.x worked examples in this sub-class should preserve the multi-year drain-window dimension explicitly, and should not over-anchor on the exfiltration date as the "incident date." The OAK convention should treat such cases as cohort-window incidents with a documented exfiltration date and a documented (open or closed) drain window.
- Per-victim cohort analysis is the canonical forensic methodology for this sub-class. The LastPass cohort's attribution converges through process-of-elimination across per-victim forensics by ZachXBT and Taylor Monahan. Contributors writing future T11.x worked examples should preserve the per-victim cohort methodology as a first-class attribution surface, and should not under-weight industry-forensic per-victim cohort tracking relative to vendor-side disclosure or federal-record establishment.
- Vendor-side denial of causation is a recurring T11 pattern that contributors should document explicitly. LastPass / GoTo continues to dispute the causal link at v0.1 reporting horizon. The pattern recurs across the T11 family (Atomic Wallet's constrained post-mortem; broader vendor-litigation-strategy constraints). Contributors writing future T11 worked examples should treat vendor-side disclosure as a first-class observable (sometimes present, sometimes absent, sometimes actively disputed) rather than as a baseline assumption.
- Laundering-chain fingerprint is a load-bearing cluster-attribution signal across the T11 family. The LastPass cohort's Wasabi-CoinJoin + Russian-CEX-off-ramp fingerprint anchors the OAK-G03-adjacent attribution. The dominant OAK-G01 fingerprint (THORChain T7.003 + restaking T7.x) is structurally distinct. Contributors writing future T11 worked examples should report the laundering-chain fingerprint explicitly as part of the attribution analysis, not as an afterthought.
- The realised-loss-versus-cohort-size dimension matters and should be reported separately. The LastPass cohort's headline figure (~$35M-$150M+ depending on Larsen-included scope) understates structural systemic risk because the cohort size (~150+ victims) makes the per-victim distribution heavy-tailed (the Larsen heist alone is >$150M; the median per-victim loss is in the high-five-figure to low-six-figure range). Contributors writing future T11.x cohort worked examples should report (a) cumulative loss, (b) cohort size, (c) per-victim distribution shape (median, max, heavy-tail observation), and (d) the cohort-window dimension (exfiltration date, drain-window state).
Public references
[krebslastpass2023]— Krebs on Security, "What's in a PR Statement: LastPass Breach Explained" / September 2023 cohort summary establishing the public-record link from ~$35M / ~150-victim cohort to the LastPass breach.[krebslastpass2025]— Krebs on Security, "Feds Link $150M Cyberheist to 2022 LastPass Hacks" (March 2025); covers the Larsen-heist federal forfeiture filing and the ~$24M federal seizure.[trmlabslastpass2025]— TRM Labs, "TRM Traces Stolen Crypto from 2022 LastPass Breach — On-chain Indicators Suggest Russian Cybercriminal Involvement" (December 2025); demixing analysis of the cohort's laundering chain through Wasabi CoinJoin and Russian exchanges.[zachxbtlastpass2023]— ZachXBT public on-chain cohort tracking from October 2023 onward; per-victim cohort process-of-elimination analysis.[theblocklastpass2023]— The Block, "LastPass threat actor drains $5.4 million in crypto from over 40 victim addresses: ZachXBT" (October 2023); industry-press summary of the cohort.[bleepinglastpass2025]— BleepingComputer, "Cryptocurrency theft attacks traced to 2022 LastPass breach"; secondary forensic-coverage source.[hackernewslastpass2025]— The Hacker News, "LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds" (December 2025); secondary coverage of the TRM analysis.[infosecuritylastpass2023]— Infosecurity Magazine, "Experts Trace $35m in Stolen Crypto to LastPass Breach"; secondary coverage of the late-2023 cohort.[cointelegraphlarsen2024]— Cointelegraph, "Ripple co-founder Larsen's $150M XRP theft linked to LastPass breach"; primary coverage of the Larsen heist.[lastpassbreachdisclosure2022]— LastPass / GoTo official disclosure, December 2022 customer-vault exfiltration announcement.
Citations
Existing citation keys reused: none directly — this is the first OAK example in the cold-storage-seed-phrase-exfiltration-at-rest sub-class.
Proposed new BibTeX entries (added to citations.bib as part of this batch):
[krebslastpass2023]— Krebs on Security 2023 cohort summary; primary investigative-journalism source for the public-record cohort attribution.[krebslastpass2025]— Krebs on Security 2025 federal-forfeiture-filing summary; primary source for the Larsen-heist federal-record link.[trmlabslastpass2025]— TRM Labs December 2025 demixing analysis; primary source for the laundering-chain fingerprint and the Russian-cybercriminal cluster attribution.[zachxbtlastpass2023]— ZachXBT public on-chain cohort tracking; primary source for the per-victim cohort process-of-elimination.[theblocklastpass2023]— The Block, October 2023 cohort summary; primary press-coverage source.[bleepinglastpass2025]— BleepingComputer; secondary forensic-coverage source.[hackernewslastpass2025]— The Hacker News, December 2025 TRM-analysis coverage; secondary source.[infosecuritylastpass2023]— Infosecurity Magazine; secondary coverage.[cointelegraphlarsen2024]— Cointelegraph; primary coverage of the Larsen heist linkage.[lastpassbreachdisclosure2022]— LastPass / GoTo official disclosure; primary vendor-side source for the December 2022 vault-exfiltration disclosure.
Discussion
The LastPass encrypted-vault exfiltration → multi-year crypto-drain cohort is OAK's canonical v0.1 worked example for the cold-storage seed-phrase exfiltration at rest sub-class within T11. The case is operationally instructive in five distinct dimensions: (a) the third-party-storage-service-at-rest failure surface is structurally distinct from the v0.1 T11.001 / T11.002 / T11.003 sub-Techniques; (b) the multi-year exfiltration-to-drain time window is a structural feature of the sub-class, not a peculiarity of this case; (c) the per-victim cohort attribution methodology (ZachXBT, Taylor Monahan) establishes attribution independently of vendor-side disclosure; (d) the laundering-chain fingerprint (Wasabi CoinJoin + Russian-CEX off-ramps) anchors the OAK-G03-adjacent operator-cluster attribution; (e) the vendor-side denial-of-causation is a recurring T11 pattern that constrains civil-recovery options for the affected cohort.
The structural significance for the broader T11 framework is the empirical demonstration that a third-party password-manager service that user-side stores plaintext-equivalent seed-phrase material at rest is a custody surface the user did not realise they had created. The user's mental model of self-custody — "I hold my own keys" — collapses when the seed-phrase material is stored in a third-party service whose security posture is outside the user's control. The structural OAK lesson generalises beyond LastPass: any third-party service that stores plaintext-equivalent seed-phrase material at rest (LastPass, 1Password, Bitwarden if Secure-Notes-equivalent is used, iCloud Notes / Drive, Google Drive, Dropbox, OneDrive, browser-saved passwords, screenshot in cloud-synced gallery, email drafts) is a custody surface that constrains the user's effective custody posture to the security posture of the third-party service. The defender / Mitigations-layer lesson is that seed-phrase storage hygiene (cold storage on physical media, no third-party-service storage, no auto-synced cloud-storage) is a first-class user-side T11 mitigation surface that the v0.1 T11 sub-Techniques do not currently cover.
The case is structurally distinct from the iCloud-backup MetaMask cohort (April 2022, ~$650K Dominic Iacovone case + cohort) at the third-party-storage-service shape layer: iCloud-backup-of-MetaMask-vault is auto-synced encrypted-at-rest cloud storage tied to the user's Apple ID security posture, while LastPass-Secure-Notes-storage-of-seed-phrase is user-initiated plaintext-equivalent storage tied to the user's master password. Both fall under the proposed T11.x cold-storage-seed-phrase-exfiltration-at-rest sub-class, but the per-incident shape differs (cloud-account compromise via SIM-swap or phishing for the iCloud cohort; vault exfiltration plus master-password brute-force for the LastPass cohort). Contributors writing future T11.x worked examples should preserve the per-incident-shape distinction explicitly.
For OAK's broader credibility, including the LastPass cohort in v0.1 closes a structural gap: T11 at v0.1 freeze covered organisational-customer / vendor-side compromise (T11.001), wallet-software distribution compromise (T11.002), and in-use multisig contract manipulation (T11.003), but did not cover the third-party-storage-service-at-rest failure surface that the LastPass cohort exhibits. The case operationalises the cold-storage-seed-phrase-exfiltration-at-rest sub-class into a live empirical anchor, anchors the architectural distinction between the third-party-storage shape and the vendor-side compromise shapes that dominate v0.1 T11, and provides contributors writing future T11.x worked examples with a tone-and-structure precedent for the cold-storage-at-rest sub-class.
The cohort is open at v0.1 reporting horizon. The brute-force window is unbounded once the encrypted vault material is in attacker hands; cohort drains continue to accumulate; further demixing analyses of the laundering chain will likely surface additional victims and additional realised loss. Contributors maintaining this worked example post-v0.1 should treat the cohort-window dimension as live and should update the cumulative-loss figure as further forensic analyses land.