Criptor

An RSS reader for cryptocurrency news

About
BeInCryptoBeInCryptoBitcoin MagazineBitcoin MagazineCrypto PotatoCrypto PotatoCrypto SlateCrypto SlateThe DefiantThe DefiantForkastForkastProtosProtos
Browse all

Criptor

Your comprehensive RSS reader for all things cryptocurrency. Stay updated with the latest news from around the globe.

Quick Links

  • About
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Resources

  • Disclaimer
  • Blog
  • Help Center
  • Contact

© 2025 Criptor. All rights reserved.

Built with ♥ for crypto enthusiasts

Home›BeInCrypto›Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering
BeInCrypto

BeInCrypto

Original publisher

Share:

Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering

December 28, 2025
2 min read
Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering

Russian cybercriminals are likely responsible for the laundering of more than $35 million in cryptocurrency stolen from LastPass users, according to a report by blockchain intelligence firm TRM Labs.

The analysis linked the multi-year drain of crypto wallets to the 2022 breach of the password manager LastPass. It noted that the stolen funds moved through illicit financial infrastructure tied to Russia’s cybercriminal underground.

How Russian Cybercriminals Laundered the Stolen Funds

TRM Labs researchers found that the attackers used privacy protocols to obscure the money trail, but ultimately routed the funds to Russia-based platforms.

According to the report, the perpetrators have continued to siphon assets from compromised vaults as recently as late 2025.

The malicious actors systematically laundered the stolen funds through off-ramps that Russian threat actors have historically used. One of those venues was Cryptex, an exchange currently sanctioned by the US Office of Foreign Assets Control (OFAC).

TRM Labs said they identified a “consistent on-chain signature” tying the thefts to a single, coordinated group.

The attackers repeatedly converted non-Bitcoin assets into Bitcoin using instant swap services. The funds were then moved to mixing services such as Wasabi Wallet and CoinJoin.

These tools are designed to pool funds from multiple users to scramble transaction histories, theoretically making them untraceable.

However, the report highlights a significant failure in these privacy technologies. Analysts were able to “de-mix” the transactions using behavioral continuity analysis.

Investigators tracked specific digital footprints, such as how wallet software imported private keys, and successfully unwound the mixing process. This allowed them to follow the digital currency through the privacy protocols and observe its final deposit into Russian exchanges.

In addition to Cryptex, investigators traced approximately $7 million in stolen funds to Audi6, another exchange service operating within the Russian cybercriminal ecosystem.

Russia Crypto Platforms' Role in Lastpass Fund Laundering.
Russia Crypto Platforms’ Role in Lastpass Fund Laundering. Source: TRM Labs

The report notes that the wallets interacting with the mixers showed “operational ties” to Russia both before and after the laundering process. This suggests the hackers were not merely renting infrastructure but operating directly from the region.

The findings underscore Russia crypto platforms’ role in enabling global cybercrime.

By providing liquidity and off-ramps for stolen digital assets, these exchanges allow criminal groups to monetize data breaches while evading international law enforcement.

The post Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering appeared first on BeInCrypto.

RELATED TOPICS

russian cybercriminalsprivacy protocolstrmassetslabscryptocryptocurrency stolenreportlaunderingbeincryptotrm labsstolenlaundered stolenrussianfundsstolen fundslaundering cryptocurrencyresponsible launderinglastpasscybercriminals responsiblecriptorfunds moved

More From BeInCrypto

World Liberty Financial Proposes Using Treasury to Boost USD1 Adoption

World Liberty Financial Proposes Using Treasury to Boost USD1 Adoption

3 hours ago

Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering

Russian Cybercrime Networks Tied to $35 Million LastPass Crypto Laundering

2 hours ago

Cardano Founder Charles Hoskinson Pitches Midnight as a Privacy Layer for Bitcoin and XRP

Cardano Founder Charles Hoskinson Pitches Midnight as a Privacy Layer for Bitcoin and XRP

1 day ago

View All Articles

Market Overview

BitcoinBitcoin
87,587.23-0.330%
EthereumEthereum
2,937.99-0.375%
Binance CoinBinance Coin
857.871.517%
RippleRipple
1.8606-0.683%
SolanaSolana
123.83-0.730%

You May Also Like

Andrew Tate’s Crypto Wallets Tied to $30 Million Money Laundering Trail
BeInCrypto

Andrew Tate’s Crypto Wallets Tied to $30 Million Money Laundering Trail

9 hours ago
Will Zcash Price Pullback or Continue Its Rally Towards $600?
BeInCrypto

Will Zcash Price Pullback or Continue Its Rally Towards $600?

8 hours ago
Hyperliquid Drops Hint on HYPE Unlocks—What’s Coming January 6?
BeInCrypto

Hyperliquid Drops Hint on HYPE Unlocks—What’s Coming January 6?

3 hours ago
Is XRP at Risk of a Breakdown Before 2026 Begins? Three Metrics Hint at Trouble
BeInCrypto

Is XRP at Risk of a Breakdown Before 2026 Begins? Three Metrics Hint at Trouble

1 day ago