Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Crypto investigator ZachXBT attributed $12.38 million in theft from nearly 150 cryptocurrency addresses on December 16 and 17, 2024, to the continuing fallout from LastPass vault backups stolen in 2022, according to IT Pro. That is an investigator-attributed estimate—not a loss total confirmed by a regulator—and the reporting does not establish that every victim’s funds were taken in the same way.

What was reported—and what the $12.38 million figure means

IT Pro reported that ZachXBT traced the December 16–17, 2024 thefts to nearly 150 victim addresses. According to the report, the stolen funds were swapped and moved through exchanges. The $12.38 million figure comes from ZachXBT’s analysis as relayed by IT Pro; it is not a total established by the UK Information Commissioner’s Office (ICO).

IT Pro also summarized separate ZachXBT reporting of approximately $4.4 million stolen from more than 25 victims on October 25, 2023. These reports point to cryptocurrency losses associated with the LastPass incidents, but they do not show that all affected addresses were compromised through an identical route, a particular seed phrase, or one specific password-cracking method. Nor do they mean that all LastPass users lost cryptocurrency.

How the 2022 LastPass incidents exposed vault backups

From a development environment to backup storage

LastPass said its first disclosure, in August 2022, concerned theft of source code and technical information from a development environment. In its December 2022 account, the company said customer data was not accessed in that initial incident. It said information taken from the development environment was later used to target an employee and obtain credentials and keys, enabling the attacker to reach cloud backup storage containing archived production data.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The ICO’s later account described employee devices, a keylogger, and access to the backup database. Its account adds detail to the company’s earlier description, while the two sources should not be treated as interchangeable: LastPass described its incident response, and the ICO reported its regulatory findings.

Encrypted vault fields were copied alongside unencrypted data

LastPass said the stolen backups contained basic account information and metadata, including names, addresses, email addresses, phone numbers, and IP addresses, as well as vault data. Sensitive vault fields—such as usernames, passwords, secure notes, and form-filled data—were encrypted, according to the company. But the backups also included information that was not encrypted, including website URLs; LastPass’s March 2023 update also listed software file paths and some email-address use cases among exceptions to encrypted vault fields. The company said end-user master passwords were not included in the stolen data.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

That distinction matters: encryption did not prevent attackers from copying the vault backups or the unencrypted information in them. At the same time, the ICO said it found no evidence that attackers decrypted customers’ encrypted passwords and other credentials. The regulator’s finding does not establish that every vault was accessed or that every reported crypto theft followed the same path.

Current encryption claims do not describe every 2022 vault

LastPass’s security page, accessed October 4, 2026, describes its current system as using AES-256 encryption and 600,000 PBKDF2-SHA-256 iterations with salting. That is the company’s present description, not independent verification or proof of the settings used by every customer’s vault at the time of the breach. In its December 2022 incident notice, LastPass described its recommended default configuration then as requiring a minimum 12-character master password and 100,100 PBKDF2 iterations. Those dated figures should not be conflated with the current security-page description.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What to do if you may have stored a crypto key or seed phrase

ZachXBT’s warning, quoted by IT Pro, was: “I cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass, migrate your crypto assets immediately.” The warning applies to people who may have put a seed phrase or private key in LastPass; it is not a claim that every LastPass user’s crypto is exposed.

The reporting does not provide a detailed migration procedure or endorse a particular wallet or service. If this applies to you, use trusted instructions for the wallet or assets involved, and do not disclose a seed phrase or private key to anyone offering unsolicited help. LastPass’s 2022 notice also warned about phishing and credential-stuffing attempts. It said the company would not ask customers by phone, email, or text to click a link to verify personal information or to disclose a master password outside vault sign-in.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the UK regulator found and how it responded

On December 11, 2025, the UK ICO said the combined LastPass incidents exposed personal information relating to up to 1.6 million UK users. It announced a £1.2 million fine against LastPass UK Ltd. The ICO said it found no evidence that encrypted customer passwords and other credentials had been decrypted.

UK Information Commissioner John Edwards said password managers remain a safe and effective way to manage login details, while businesses providing them should restrict system access and use to reduce attack risks. The ICO’s finding about the lack of evidence of decryption is specific to its investigation; it does not undo the exposure of copied backups or unencrypted fields and metadata.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Canadian settlement: the claims deadline has passed

A separate Canadian settlement concerns eligible claims under that settlement’s terms; it is not the ICO’s UK enforcement action and does not apply everywhere. The official Canadian settlement site reports that final approval was granted on February 18, 2026; claims opened March 25, and the deadline passed on June 23, 2026. It lists a US$3 million settlement and CAD $1.4 million allocated to a crypto claims distribution fund. Eligibility and any payment depend on the settlement terms, validation, and pro-rata distribution; the reported deadline is no longer open.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.