Ripple co-founder’s $150M hack tied to LastPass password vault breach

Ripple co-founder’s $150M hack tied to LastPass password vault breach
Blockchain detective ZachXBT questioned Larsen's resolution to withhold the rationale for the hack, which resulted in 213 million XRP stolen.

Duvet art/illustration by task of CryptoSlate. Picture contains mixed bellow material that can consist of AI-generated bellow material.
A forfeiture criticism shared by blockchain detective ZachXBT revealed that the $150 million hack suffered by Ripple co-founder Chris Larsen resulted from within most keys stored in the password manager LastPass, which used to be compromised in 2022.Â
The criticism necessary aspects how the attackers accessed Larsenâs cryptocurrency wallets through stolen vault records from LastPass.
LastPass compromise
In December 2022, LastPass suffered two most major records breaches, one in August and one other in November, which resulted in the theft of encrypted passwords and vault records.Â
In accordance to the criticism, Larsen â called Sufferer 2 â stored within most keys in LastPassâ password vault, which moreover contained stable notes, banking records, and other credentials.
In accordance to Larsen, he destroyed any physical yarn of the within most keys after inputting them in the password vault. A long, distinctive password secured secure correct of entry to to the on-line password manager, and units remained logged for as a lot as 30 days.
As a minimal four units had secure correct of entry to to the legend containing the within most keys, and easiest Larsenâs relatives had been responsive to the passcode to any of these units.Â
The FBI has been investigating the LastPass breach, and law enforcement agents working on Larsenâs case admire spoken with FBI agents relating to the stolen records.Â
The investigation suggests that attackers vulnerable the compromised vault records to manufacture unauthorized secure correct of entry to to a pair of victimsâ cryptocurrency accounts, electronic accounts, and other sensitive records.
The hack
Larsen first disclosed the hack on Jan. 31, 2024, bringing up that unauthorized secure correct of entry to had been detected in a entire lot of of his within most XRP accounts.Â
The attackers stole roughly 213 million XRP, valued at $112.5 million at the time. The stolen funds had been laundered through crypto exchanges, including Binance, Kraken, OKX, Gate, MEXC, HTX, and HitBTC.
Larsen and his crew at once notified crypto exchanges to freeze affected addresses nonetheless did now now not publicly gift any additional necessary aspects in regards to the hack.
ZachXBT questioned Larsenâs resolution to veil the rationale for the theft. He acknowledged:
“Most efficient if Chris Larsen had shown general transparency with sharing their findings for the root cause sooner than this or had helped plot up a category movement against LastPass.”
Talked about in this text
Source credit : cryptoslate.com