Ripple co-founder Larsen’s $150M XRP theft linked to LastPass breach

0


The January 2024 theft of 283 million XRP (XRP) from Ripple co-founder Chris Larsen’s private accounts has been linked to a password supervisor breach, in accordance to a forfeiture criticism filed by US regulation enforcement revealed by crypto investigator ZachXBT.

The investigator shared a screenshot of the forfeiture criticism in his Telegram channel on March 7, claiming the theft “was the result of storing private keys in LastPass (password manager which was hacked in 2022). Up to this point, Chris Larsen had not publicly disclosed the cause of the theft.”

Related: ZachXBT rug pull drama reveals extent of unpaid detective work

According to the shared criticism, Larsen’s personal keys have been saved within the on-line password supervisor earlier than being destroyed. Four units have been enabled with the password supervisor, which had a protracted, distinctive password.

The password supervisor, LastPass, suffered two main breaches — one in August 2022 and the opposite in November 2022 — the place the attackers stole encrypted passwords and on-line password administration vault knowledge. According to the US Federal Bureau of Investigation, which investigated the case, the compromised knowledge was used to steal cryptocurrency, amongst different issues.

The 283 million XRP stolen in January could be price $683 million on March 7.

Source: Chris Larsen

ZachXBT traces token laundering

Following the XRP hack in opposition to Larsen, ZachXBT traced the tokens throughout a number of crypto exchanges, together with MEXC, Gate.io, Binance, Kraken, OKX, HTX, HitBTC and others.

As Cointelegraph reported, the LastPass hackers had stolen a further $45 million from crypto holders simply earlier than Christmas in December 2024. White hat hacker group Security Alliance considers seed phrases and personal keys saved on the password supervisor earlier than 2023 to be in danger.

Storing personal keys or seed phrases on-line anyplace is taken into account a dangerous observe, with many recommending writing them down and storing them in a secure or conserving them in offline digital storage like a USB. A person may cut up their seed phrase into completely different elements and retailer them in a number of places.

Password managers do have one place, nonetheless, in crypto security practices: the flexibility to generate and retailer advanced passwords that may make breaking into wallets that a lot more durable.

Related: Understanding multi-factor authentication (MFA) in cryptocurrency



Source link

You might also like
Leave A Reply

Your email address will not be published.