[ad_1]
Experts warn LastPass users to move their crypto funds as there are multiple indications the breach is being actively exploited against cryptocurrency owners
Several experts have warned LastPass users who store cryptocurrency-related login credentials in their vaults to change those login credentials as soon as possible.
Apparently, cybercriminals who have access to stolen information are making data decryption a priority in an attempt to gain access to cryptowallets and online accounts.
The violation
According to LastPass, an unknown attacker gained access to a cloud-based storage environment using information obtained during the August 2022 LastPass breach. Some of the stolen source code and technical information was used to target another LastPass employee, allowing the attacker to obtain credentials and keys that were used to access and decrypt certain storage volumes at the within the cloud-based storage service.
Unencrypted data
As we mentioned in a previous post about the LastPass breach, some of the stolen data was unencrypted. The unencrypted data included URLs, which could serve as a pointer for the attacker to determine which accounts deserve attention. For example, if someone has stored their login credentials on Blockchain.com or any other crypto services platform in LastPass, the threat actor will be able to see the URL for that platform and can then choose to prioritize attempts to decrypt this information.
Decrypt
At this point, it’s unclear whether the attacker is trying to crack the master password for these accounts of interest or the crypto-related login credentials, but it’s likely they’ll try both. And because they stole copies of the safes, they have unlimited time to keep trying.
Secret keys
If your secret keys were in the stolen data, simply changing your passwords won’t be enough. With a secret key, you can prove ownership of a blockchain address, which means you can change all other information associated with that address. The password, recovery email, etc., everything a hacker needs to clear the account.
That’s why the tweet from Responders.nu (a Dutch incident response cybersecurity company) states that you will need to transfer your funds to another account.
Changing your LastPass master password and enabling 2FA is good, but it doesn’t help in the event that attackers have a copy of your vault, as they can access the copy at any time. Once they’ve cracked your master password, they’ll be able to see everything you’ve stored in that vault in the clear, and they’ll have plenty of time to use brute force attacks to crack the encrypted data.
We realize that opening new accounts and transferring funds to them is time consuming and expensive, but it’s definitely better than waking up to a depleted account.
Class action
A “John Doe” class action lawsuit has been filed against LastPass arising from the August 2022 data breach. The class action lawsuit was filed in the U.S. District Court in Massachusetts on January 3 by an anonymous plaintiff (John Doe) and on behalf of others in the same situation. The LastPass data breach allegedly resulted in the theft of approximately $53,000 worth of Bitcoin.
We contacted LastPass, but it did not return our request for comment. We’ll keep you posted on any developments here.
We don’t just report threats, we remove them
Cybersecurity risks should never extend beyond a headline. Protect your devices against threats by downloading Malwarebytes today.
|
Sources 2/ https://www.malwarebytes.com/blog/news/2023/01/lastpass-users-should-move-their-crypto-funds-experts-warn The mention sources can contact us to remove/changing this article |
[ad_2]