LastPass breach #N: the offline cracking clock is the real story

4 min read 1 source clear_take
├── "The real threat isn't this new breach — it's the 2022 ciphertext being ground offline against outdated KDF parameters"
│  └── top10.dev editorial (top10.dev) → read below

The synthesis argues the specific disclosure is less important than the cumulative posture: vaults were already exfiltrated in 2022 and are being cracked continuously. With PBKDF2 at 100,100 iterations (or 5,000 for legacy accounts) against modern GPU clusters, time-since-exfiltration is now the dominant variable in the threat model.

├── "Users should migrate to alternative password managers with stronger architecture"
│  └── @mooreds (Hacker News, 487 pts) → view

The HN submission surfaced the 9to5Mac disclosure and drove 487 points of discussion centered on switching vendors. The thread surfaced Bitwarden, 1Password, KeePassXC, and self-hosted Vaultwarden as the recommended exits from LastPass.

└── "LastPass's prior breaches are already causally linked to massive real-world losses"
  └── 9to5Mac (9to5Mac) → read

The article frames the new disclosure against the backdrop of independent researcher work — notably ZachXBT's on-chain forensics — tying the 2022 vault theft to $150M+ in cryptocurrency losses. The framing implies this isn't theoretical risk but realized, measurable damage that continues to compound.

What happened

LastPass has notified users of another data exposure incident, the latest entry in a now-multi-year timeline that began with the August 2022 source-code theft and culminated in the November 2022 exfiltration of customer vault backups from a third-party cloud storage bucket. The new disclosure, surfaced via 9to5Mac and lit up Hacker News at 487 points within hours, lands against a backdrop where the company's prior breaches have already been credibly linked by independent researchers to roughly $150M+ in cryptocurrency theft tracked across on-chain forensics by ZachXBT and others.

The specifics of this incident matter less than the cumulative posture. LastPass's threat surface is no longer 'will attackers get the vaults' — they already did, in 2022, and have been grinding them offline ever since. Every subsequent disclosure is a reminder that the 2022 ciphertext is still out there, still being attacked, and still yielding plaintext credentials at a rate determined by Moore's Law and the resale price of used H100s.

The HN thread surfaced the usual recommendations — Bitwarden, 1Password, KeePassXC, self-hosted Vaultwarden — but the more interesting comments came from people who've been running the actual cracking math. The 100,100 PBKDF2 iteration count LastPass used for older accounts (it was 5,000 for some legacy vaults, a fact the company quietly acknowledged in 2023) is not a 2026 threat model. It's a 2015 threat model running on 2026 hardware.

Why it matters

The story everyone wants to write is "password manager bad, switch vendors." That's not the story. The story is that offline cracking has crossed a threshold where the *time-since-exfiltration* variable now dominates the threat model — and most users have no mental model for it.

Here's the math senior devs should internalize. PBKDF2-SHA256 at 100,100 iterations runs at roughly 2-4 million hashes per second on a single RTX 4090. An eight-GPU rig hits ~25M/s. A 10-character random alphanumeric password has ~10^18 combinations; at 25M/s that's ~1,300 years to brute force. Sounds safe. Now drop to 8 characters: ~3.7 years. Drop the assumption of true randomness — most humans pick passwords with ~40 bits of effective entropy regardless of length — and you're at days to weeks on a rented cloud rig. The 2022 vaults have been sitting in attacker storage for over three and a half years. Compute has roughly doubled in that window. Cloud GPU spot pricing has dropped by a third.

The community reaction on HN has shifted noticeably from prior breach cycles. In 2022, the top comments were vendor recommendations. In 2026, they're forensic — people are linking specific on-chain heists to specific user demographics (DeFi-active accounts with seed phrases stored in notes fields) and arguing that the *attribution methodology itself* is now mature enough to be evidence in litigation. Class-action filings against LastPass have been winding through the courts; this new disclosure will be cited in amended complaints within weeks.

There's also a regulatory angle that practitioners keep underweighting. The FTC's 2023 settlement framework with Drizly established that executives can be personally enjoined from infosec roles after breaches. LastPass leadership has not been named in any such action — yet — but the GoTo (parent company) corporate structure is exactly the kind of multi-entity arrangement that plaintiffs' firms are now trained to pierce. If this breach involves customer PII beyond the already-exposed vault metadata, the disclosure timeline alone (the gap between detection and notification) becomes a litigable question under several state laws.

What this means for your stack

If you, your team, or anyone whose vault you can influence had a LastPass account before December 2022, the threat is not theoretical and not future-tense. Treat every credential that was in that vault as compromised-pending-cracking, prioritized by entropy of the master password and sensitivity of the stored secret. Specifically:

Rotate any credential that (a) was in a pre-2023 LastPass vault, (b) protects a high-value asset, and (c) cannot be MFA-gated. Crypto seed phrases stored in vault notes fields are the canonical worst case — there's nothing to rotate, the asset is bearer, and on-chain attribution suggests this is the exact target profile being prioritized. If you stored a seed phrase in any password manager, ever, move the funds.

For team password managers, audit the iteration count on your current vendor. Bitwarden defaults to 600,000 PBKDF2 iterations now; 1Password uses 650,000 plus a secret key (the 128-bit local entropy that makes their vaults effectively uncrackable even with a weak master password). If you're on a self-hosted Vaultwarden install older than 2023, check your KDF settings — the defaults have changed and existing accounts don't auto-migrate.

The broader stack implication is that "encrypted at rest" is no longer a meaningful security property in isolation when the attacker has the ciphertext and unlimited time. This applies to far more than password managers — backup tarballs, encrypted S3 buckets with weak passphrases, BitLocker images on stolen laptops with TPM-less recovery keys. The 2022 LastPass incident is the canonical case study, but the threat model generalizes to anywhere your team is implicitly relying on "they'd need to crack it" as a control.

Looking ahead

The next 18 months will produce the first wave of insurance-driven KDF audits — cyber insurance underwriters are already asking for PBKDF2/Argon2 iteration counts on renewal questionnaires. Expect Argon2id to become a compliance checkbox by 2027, not because PBKDF2 is broken, but because the cost gap between defender (one hash per login) and attacker (billions per second) has finally outrun what iteration counts alone can close. If you're building anything that stores user secrets, the move is Argon2id with memory-hard parameters tuned to make GPU parallelism economically painful — not picking a higher PBKDF2 number and calling it done. The LastPass story isn't over; it's just that the interesting chapters are now being written by cryptographers and plaintiffs' attorneys, not by the breached company itself.

Hacker News 501 pts 221 comments

LastPass notifies users of yet another data breach

→ read on Hacker News
jagged-chisel · Hacker News

How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.

khurs · Hacker News

Lots more companies affected. Some more listed below:>"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Spro

variety8675 · Hacker News

https://blog.lastpass.com/posts/klue-supply-chain-incident-a...> The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addres

bradley13 · Hacker News

WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc..For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose t

fusslo · Hacker News

I'm sure this is worse than using lastpass in some waybut for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change

// share this

// get daily digest

Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.