Argues the new disclosure isn't a standalone story but an update to an unresolved 2022 incident where encrypted vaults — with plaintext URLs and laughably low PBKDF2 iteration counts — are still being cracked. Cites ZachXBT and Taylor Monahan attributing $150M+ in crypto thefts to seed phrases from those vaults, with thefts ongoing into 2026.
Criticizes LastPass's 'characteristically narrow' language ('limited subset,' 'no master passwords compromised') and 'characteristically late' disclosure timing. Frames this as a pattern across at least five public incidents since August 2022, suggesting the company's communications consistently downplay scope.
Argues that with ~25M users still on the platform, many on free/family tiers, the perceived friction of migration is being weighed against an outdated view of the risk. Contends the math has been wrong since December 2022 because the security model — not features — is the product, and that model has demonstrably failed.
Submitted the 9to5Mac article to Hacker News where it reached 331 points and 149 comments, signaling strong community resonance with the concern that LastPass continues to disclose breaches and users should reconsider staying. The submission framing aligns with the 'yet another' exhaustion narrative.
LastPass is, once again, emailing customers about a security incident. The 9to5Mac report covers a notification going out this week disclosing unauthorized access to user data — the company's framing is characteristically narrow ("limited subset," "no master passwords compromised"), and characteristically late. For anyone keeping score, this is at least the fifth public incident since August 2022, when an attacker pulled source code from a developer environment and used it as a beachhead into customer vault backups four months later.
The 2022 breach is the one that still matters, because the encrypted vaults exfiltrated then are still being cracked now. Those vaults included URL fields stored in plaintext (a design choice LastPass defended for years), iteration counts on PBKDF2 that were, for legacy accounts, as low as 1 — yes, one — and a customer base that had been told for a decade that "zero-knowledge" meant their data was safe even if LastPass itself was compromised. Chain-analysis researcher ZachXBT and Taylor Monahan of MetaMask have publicly attributed more than $150 million in crypto thefts across 2023 and 2024 to wallet seed phrases stored in LastPass vaults from that 2022 dump. The thefts are still ongoing in 2026.
The new notification, by contrast, concerns a smaller-scale intrusion — exact scope still being characterized — but lands against that backdrop. It's not a standalone story. It's an update to an open ticket that should have been closed by user migration two years ago.
Password managers are a category where the security model is the product. There is no feature parity argument that overrides "the vendor keeps getting breached and the previous breach is still being monetized by criminals." And yet LastPass retains an estimated 25 million users, many of them on free or family tiers where switching cost feels higher than residual risk.
That math is wrong, and it's been wrong since December 2022. The correct mental model: assume any credential, TOTP seed, or secure note you stored in LastPass before March 2023 is in an offline cracking queue somewhere, being chewed on by GPU farms that get cheaper every year. PBKDF2-SHA256 at 100,100 iterations — LastPass's default after the 2018 increase — falls to a determined attacker with a $50K rig in a matter of weeks for any master password under ~12 characters of real entropy. The math gets dramatically worse for users grandfathered in on lower iteration counts, which LastPass quietly upgraded server-side but did not force re-encryption for until well after the breach.
Meanwhile, the rest of the category moved. 1Password shipped Secret Key — a second client-side factor that makes offline vault cracking computationally infeasible even with a weak master password — in 2017, and the 2022 LastPass breach is essentially the worked example for why that design exists. Bitwarden published its third independent security audit, moved Argon2id to default for new accounts, and open-sourced its server. Vaultwarden, the Rust reimplementation, lets paranoid teams self-host the whole stack. Proton Pass arrived with end-to-end encrypted aliases and sharing built on the same crypto stack as Proton Mail. Even Apple's Passwords app — admittedly platform-locked — ships with Secure Enclave-backed key storage on every modern iPhone.
The LastPass response across the same window has been: a CEO blog post that buried the vault exfiltration in paragraph six, a slow drip of follow-up disclosures, a refusal to publish a meaningful post-mortem of the developer-environment compromise, and continued marketing that emphasizes UX over the security architecture deficit. The new breach notification doesn't change the trajectory. It confirms it.
Community reaction on Hacker News (331 points, top of front page) is uncharacteristically unified for a security thread: the top comments are not arguing about whether to switch, they're sharing migration scripts. When the HN comment section stops debating and starts tooling, the conclusion is already in.
If you or anyone on your team still has a LastPass vault, the action items aren't subtle:
First, don't just export and import. The vault export is a snapshot of credentials that have, statistically, already been compromised. You need to rotate, not migrate. Pull the export to inventory what's in there, then walk every credential and rotate it at the source. TOTP seeds need to be re-enrolled, not copied. Secure notes containing API keys, recovery phrases, or SSH passphrases need to be treated as burned.
Second, pick a successor with a second factor in the crypto, not just the login. 1Password's Secret Key and Proton Pass's account key serve the same function: they make the encrypted blob useless even if the vendor's storage is fully compromised. Bitwarden doesn't have this primitive, but its Argon2id default and open-source server make self-hosting realistic for teams that want full custody. Pick based on your threat model, but pick something where a future server-side breach doesn't immediately put your master password under offline attack.
Third, audit your team's shared vaults. The LastPass enterprise tier is widely deployed at companies that haven't revisited the decision since the 2022 breach. If you're a security engineer at one of those companies, the cost-of-switching argument no longer holds up against a credible probability that historical shared secrets are in adversary hands. Quantify it: how many production credentials lived in shared LastPass folders in 2022? How many of those have been rotated since? The delta is your unmitigated exposure.
The LastPass story is the closest thing the password manager category has to a control group: same problem space, same threat model, same customer expectations, dramatically different security investments. Four years of breaches have produced a real-world result that no amount of marketing can re-frame. The interesting question now isn't whether LastPass survives — it probably will, as enterprise inertia is a hell of a moat — but whether any new incident will move the needle on user migration, or whether the password manager market has reached the same equilibrium as antivirus: a tier of incumbents whose security failures are priced in, and a tier of challengers competing on the architecture the incumbents won't ship.
Lots more companies affected. Some more listed below:>"Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Spro
https://blog.lastpass.com/posts/klue-supply-chain-incident-a...> The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addres
WTF is LastPasd doing, handing customer details to a market research company? Any such data should have been fully anonymized: no names, no specific addresses, etc..For anyone looking for a recommendation: I use KeepassXC with Keepass2Android. Open source, with a local database that you can choose t
I'm sure this is worse than using lastpass in some waybut for the past couple years I've just generated and forgotten 90% of my passwords. the final 10% I keep in a password manager. But if the service isn't really that important I just use the 'forgot my password' to change
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
How does anyone seriously trust LastPass anymore? Years ago, I was working for a company handling bank data. They were using LP immediately following a previous LP security incident and had no plans to migrate away.