Ripple co-founder’s $150M hack tied to LastPass password vault breach

A forfeiture complaint shared by blockchain detective ZachXBT revealed that the $150 million hack suffered by Ripple co-founder Chris Larsen resulted from private keys stored in the password manager LastPass, which was compromised in 2022. 

The complaint details how the attackers accessed Larsen’s cryptocurrency wallets through stolen vault data from LastPass.

LastPass compromise

In December 2022, LastPass suffered two major data breaches, one in August and another in November, which resulted in the theft of encrypted passwords and vault data. 

According to the complaint, Larsen — referred to as Victim 2 — stored private keys in LastPass’ password vault, which also contained secure notes, banking information, and other credentials.

According to Larsen, he destroyed any physical record of the private keys after inputting them in the password vault. A long, unique password secured access to the online password manager, and devices remained logged for up to 30 days.

At least four devices had access to the account containing the private keys, and only Larsen’s family members were aware of the passcode to any of these devices. 

The FBI has been investigating the LastPass breach, and law enforcement agents working on Larsen’s case have spoken with FBI agents regarding the stolen data. 

The investigation suggests that attackers used the compromised vault data to gain unauthorized access to multiple victims’ cryptocurrency accounts, electronic accounts, and other sensitive information.

The hack

Larsen first disclosed the hack on Jan. 31, 2024, stating that unauthorized access had been detected in several of his personal XRP accounts. 

The attackers stole approximately 213 million XRP, valued at $112.5 million at the time. The stolen funds were laundered through crypto exchanges, including Binance, Kraken, OKX, Gate, MEXC, HTX, and HitBTC.

Larsen and his team immediately notified crypto exchanges to freeze affected addresses but did not publicly reveal any further details about the hack.

ZachXBT questioned Larsen’s decision to hide the cause of the theft. He said:

“Only if Chris Larsen had shown basic transparency with sharing their findings for the root cause prior to this or had helped organize a class action against LastPass.”

The post Ripple co-founder’s $150M hack tied to LastPass password vault breach appeared first on CryptoSlate.

  • Related Posts

    Whales accumulate 65,000 Bitcoin as market uncertainty grows

    Over the past 30 days, Bitcoin (BTC) whales have acquired more than 65,000 BTC, signaling sustained buying pressure despite the broader market correction. At the same time, the Coinbase premium…

    Continue reading
    Bullish bets soar as Bitcoin call options target $120K strike

    Analyzing open interest distribution across different strike prices offers critical insights into market sentiment and potential price trajectories. Strike prices represent the specific levels at which options contracts can be…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Whales accumulate 65,000 Bitcoin as market uncertainty grows

    Whales accumulate 65,000 Bitcoin as market uncertainty grows

    Bullish bets soar as Bitcoin call options target $120K strike

    Bullish bets soar as Bitcoin call options target $120K strike

    StarkWare bolsters Bitcoin strategy with new strategic reserve and L2 integration

    StarkWare bolsters Bitcoin strategy with new strategic reserve and L2 integration

    SEC postpones altcoin ETF decisions but 2025 approval prospects remain strong

    SEC postpones altcoin ETF decisions but 2025 approval prospects remain strong

    Court ruling in Uniswap case sets precedent for DeFi developers’ legal protection

    Court ruling in Uniswap case sets precedent for DeFi developers’ legal protection

    Bitcoin needs sovereign buying or macro clarity to end risk-off sentiment for breakout – StanChart

    Bitcoin needs sovereign buying or macro clarity to end risk-off sentiment for breakout – StanChart