Ripple Co-founder’s $150M XRP Heist Related to LastPass Hack: ZachXBT

Tech

Share this article

By Shaurya Malwa|Edited by Parikshit Mishra

Updated Mar 8, 2025, 12:00 p.m. UTCPublished Mar 8, 2025, 11:18 a.m. UTC

money wallet
  • A $150 million theft from Ripple co-founder Chris Larsen’s wallet was traced back to a security lapse at password manager LastPass, according to a forfeiture complaint filed by U.S. law enforcement.
  • The hackers accessed Larsen’s private keys stored in LastPass, which had suffered a major breach in 2022, leading to the theft of encrypted customer password vaults and unencrypted metadata for an estimated 25 million users.
  • The fallout from the LastPass hack continues, with crypto losses connected to the breach estimated to be at least $250 million as of May 2024.

A $150 million theft targeting Ripple co-founder Chris Larsen has been traced back to a security lapse involving the password manager LastPass, according to a forfeiture complaint filed by U.S. law enforcement on March 6 flagged by blockchain sleuth ZachXBT.

ZachXBT shared that the complaint detailed how Larsen’s private keys — or code to access one’s token holdings — were stored in LastPass, the widely used password manager that suffered a major breach in 2022.

STORY CONTINUES BELOW

Don’t miss another story.Subscribe to the The Protocol Newsletter today.See all newslettersBy signing up, you will receive emails about CoinDesk products and you agree to ourterms of useandprivacy policy.

At the time, hackers stole source code and technical data by compromising a developer’s account. By November of that year, they used this access to infiltrate a cloud storage system, stealing encrypted customer password vaults and unencrypted metadata for an estimated 25 million users.

Although ‘vaults’ were encrypted, weak or reused master passwords could be brute-forced, exposing stored data.

Hackers exploited this vulnerability, accessing Larsen’s keys and siphoning off the XRP, valued at $150 million at the time of the theft and over $600 million as of Saturday’s prices.

“A forfeiture complaint filed yesterday by US law enforcement revealed the cause for the ~$150M (283M XRP) hack of Ripple co-founder, Chris Larsen’s wallet in Jan 2024 was the result of storing private keys in LastPass (password manager which was hacked in 2022),” ZachXBT wrote on his Telegram channel.

“Up to this point Chris Larsen had not publicly disclosed the cause of the theft,” he added.

Larsen confirmed the incident in January, where he clarified the hack affected only his personal accounts, not Ripple’s corporate wallets. He is yet to publicly comment on the forfeiture notice.

The fallout from the 2022 LastPass hack has been extensive and remain ongoing. In December, The Security Alliance (SEAL), a team of cybersecurity experts focused on the crypto market, estimated that crypto losses connected to the breach had touched at least $250 million as of May 2024.

Shaurya is the Co-Leader of the CoinDesk tokens and data team in Asia with a focus on crypto derivatives, DeFi, market microstructure, and protocol analysis.
Shaurya holds over $1,000 in BTC, ETH, SOL, AVAX, SUSHI, CRV, NEAR, YFI, YFII, SHIB, DOGE, USDT, USDC, BNB, MANA, MLN, LINK, XMR, ALGO, VET, CAKE, AAVE, COMP, ROOK, TRX, SNX, RUNE, FTM, ZIL, KSM, ENJ, CKB, JOE, GHST, PERP, BTRFLY, OHM, BANANA, ROME, BURGER, SPIRIT, and ORCA.
He provides over $1,000 to liquidity pools on Compound, Curve, SushiSwap, PancakeSwap, BurgerSwap, Orca, AnySwap, SpiritSwap, Rook Protocol, Yearn Finance, Synthetix, Harvest, Redacted Cartel, OlympusDAO, Rome, Trader Joe, and SUN.

Shaurya Malwa


Contact

DISCLOSURE & POLICES

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.

EthicsPrivacyTerms of UseCookie ConsentDo Not Sell My Info


© 2025 CoinDesk, Inc.

 

Leave a Reply

Your email address will not be published. Required fields are marked *