Skip to main content
  1. Home
  2. Computing
  3. News

The massive LastPass hack from 2022 is still haunting us

Add as a preferred source on Google
LastPass website on a laptop.
Digital Trends

Just when you thought the LastPass breach of 2022 was over, we’re still learning just how detrimental the hack was. According to blockchain expert ZachXBT and spotted by The Block, $5.36 million was stolen from 40 users in a string of attacks. This is on top of the $4.4 million stolen in October 2023 and $6.2 million earlier this year in February 2024.

The original hack goes back to 2022 when hackers claimed to have accessed LastPass’ data, which contained API tokens, customer keys, multifactor authentication seeds (MFA), and encrypted password vaults. Although no official information explains how the breach happened, it’s possible that the hacker responsible gained access to information that aided the breach. Hackers forced their way in despite the password vaults being encrypted because users reused weak or previously leaked combinations. This access, combined with the users’ weak or reused passwords, led to the various accounts being compromised.

Recommended Videos

“Cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass migrate your crypto assets immediately,” ZachXBT wrote in an X post last year.

Only time will tell if this string of attacks continues, which makes you wonder if LastPass is safe. But how did the original breach happen? LastPass revealed that the hackers stole the app’s source code. In a subsequent attack, the hackers merged the stolen data with information discovered in another data breach.

The hackers then exploited a weakness in a remote-access app that LastPass employees used. This allowed the hacker to install a keylogger onto the PC of a senior engineer at LastPass, which registered all the key inputs.

The breach highlights the importance of always having a strong password on all your accounts. Never reuse passwords or have easy-to-guess passwords that hackers will love you for. If creating long, strong passwords is not your thing, you can always use one of the best password generators.

Judy Sanhz
Computing Writer
Judy Sanhz is a Digital Trends computing writer covering all computing news. Loves all operating systems and devices.
Viture Pro 2 review: Affordable glasses that I loved more for work than play
One of the lightest and brightest XR glasses you will find for the price.
Viture Pro 2 smart glasses

Quick summary

Two years ago, I had the chance to test out the Viture Pro smart glasses. I was impressed by the chic design and the stunning display units, but there were a few minor hiccups that kept them from becoming an instant buy for XR fans. The asking price of $459, ultimately, made them a tough recommendation for anyone who is not a diehard enthusiast or doesn't have the spare cash to spend. The successor, however, is an altogether different beast.

Read more
Your Mac might have a screen sharing problem, and hackers already know about it
A patch is only useful once you install it.
macOS Tahoe 26 public beta running on the M4 MacBook Air 15

If you've been putting off that macOS update sitting in your notifications, this is the week to stop and install it. 

Apple quietly patched a serious screen sharing flaw in macOS earlier this month. While that usually means the issue is resolved, new evidence shows hackers already broke into unpatched Macs, hijacked them, and used them for cryptocurrency mining before the fix shipped.

Read more
The US is trying to kick foreign robots out, but the local supply chain might not be there yet
Building a robot supply chain from scratch takes years that Washington isn't giving anyone.
LG CLOiD Home Robot

The FCC has a track record of using its Covered List to squeeze Chinese tech out of American markets, and robots just became its newest target. Foreign-made humanoids, quadrupeds, and even robot vacuums now need to be mostly built in the U.S. to sell here (via Rest of World). 

So what does the new rule actually require?

Read more