Tech and Digital Media

Thursday, September 7, 2023

[New post] “Experts link LastPass security breach to a string of crypto heists” by Jess Weatherbed

Site logo image jaydiaz2013 posted: " One researcher claims the number of victims who stored their crypto keys on LastPass was "simply too much to ignore." | Illustration: Beatrice Sala Security experts are claiming that some of the LastPass password vaults stolen duri" Technopreneurph

"Experts link LastPass security breach to a string of crypto heists" by Jess Weatherbed

jaydiaz2013

Sep 7

A cartoon illustration shows a shadowy figure carrying off a red directory folder, which has a surprised-looking face on its side.
One researcher claims the number of victims who stored their crypto keys on LastPass was "simply too much to ignore." | Illustration: Beatrice Sala

Security experts are claiming that some of the LastPass password vaults stolen during a security breach near the end of 2022 have now been cracked open following a string of six-figure cryptocurrency heists. Cybersecurity blogger Brian Krebs reports that several researchers have identified a "highly reliable set of clues" that seemingly connect over 150 victims of crypto theft with the LastPass service. Collectively, over $35 million in crypto has reportedly been stolen so far, with between two to five high-value heists occurring each month since December 2022.

Taylor Monahan, lead product manager at crypto wallet company MetaMask and one of the key researchers investigating the attacks, concluded that the common thread connecting the victims was that they'd previously used LastPass to store their "seed phrase" — a private digital key that's required to access cryptocurrency investments. These keys are often stored on encrypted services like password managers to prevent bad actors from gaining access to crypto wallets. The stolen funds were also moved to the same blockchain addresses, further linking the victims.

At this point I'm also confident in saying that, in most of these cases, the compromised keys were stolen from @LastPass

The number of victims who only had the specific group of seeds/keys that were drained stored in LastPass is simply too much to ignore.

— Tay (@tayvano_) August 28, 2023

https://platform.twitter.com/widgets.js

Password management service LastPass suffered two known security breaches in August and November last year, with hackers using information obtained during the first breach to access shared cloud storage containing customer encryption keys for vault backups during the latter incident. We have reached out to LastPass to confirm if any of the stolen password vaults have been cracked and will update this story if we hear back.

In a statement to The Verge, LastPass CEO Karim Toubba says that the security breach last November remains "the subject of an ongoing investigation by law enforcement and is also the subject of pending litigation." The company did not say whether the 2022 LastPass breaches have anything to do with the reported crypto thefts.

Researcher Nick Bax, director of analytics at crypto wallet recovery company Unciphered, also reviewed the theft data and agreed with Monahan's conclusions in an interview with KrebsOnSecurity:

"I'm confident enough that this is a real problem that I've been urging my friends and family who use LastPass to change all of their passwords and migrate any crypto that may have been exposed, despite knowing full well how tedious that is."

source https://www.theverge.com/2023/9/7/23862658/lastpass-security-breach-crypto-heists-hackers

Comment
Like
Tip icon image You can also reply to this email to leave a comment.

Unsubscribe to no longer receive posts from Technopreneurph.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://technopreneurph.wordpress.com/2023/09/07/experts-link-lastpass-security-breach-to-a-string-of-crypto-heists-by-jess-weatherbed/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at September 07, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

[New post] ‘Everyone Is Freaking Out’: Disney Explores Sale of ABC Network and Stations Amid Financial Challenges

...

  • [New post] Xiaomi’s Mi Smart Band 6 NFC is finally available in Europe officially
    Tech News For Today posted: "Xiaomi's Mi Smart Band 6 NFC is finally available in Europe officially At Xiaomi's bi...
  • [New post] ‘Everyone Is Freaking Out’: Disney Explores Sale of ABC Network and Stations Amid Financial Challenges
    ...
  • [New post] Asus is recruiting Android 12 beta testers for Zenfone 8
    Top Tech posted: " The Zenfone 8 announced in May with Android 11 already got a couple of Android 12 beta builds, but those...

Search This Blog

  • Home

About Me

Tech and Digital Media
View my complete profile

Report Abuse

Labels

  • 【ANDROID STUDIO】navigation
  • 【FLUTTER ANDROID STUDIO and IOS】backdrop filter widget
  • 【GAMEMAKER】Scroll Text
  • 【PYTHON】split train test
  • 【Visual Studio Visual Csharp】Message Box
  • 【Visual Studio Visual VB net】Taskbar properties
  • 【Vuejs】add dynamic tab labels labels exceed automatic scrolling

Blog Archive

  • September 2023 (502)
  • August 2023 (987)
  • July 2023 (954)
  • June 2023 (1023)
  • May 2023 (1227)
  • April 2023 (1057)
  • March 2023 (985)
  • February 2023 (900)
  • January 2023 (1040)
  • December 2022 (1072)
  • November 2022 (1145)
  • October 2022 (1151)
  • September 2022 (1071)
  • August 2022 (1097)
  • July 2022 (1111)
  • June 2022 (1117)
  • May 2022 (979)
  • April 2022 (1013)
  • March 2022 (982)
  • February 2022 (776)
  • January 2022 (681)
  • December 2021 (1197)
  • November 2021 (3156)
  • October 2021 (3212)
  • September 2021 (3140)
  • August 2021 (3271)
  • July 2021 (3205)
  • June 2021 (2984)
  • May 2021 (732)
Powered by Blogger.