Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
U.S. authorities traced or seized $23,604,815.09 in cryptocurrency between June 2024 and February 2025, linking the assets to the January 2024 theft of approximately $150 million from a wallet belonging to Ripple co-founder Chris Larsen. Investigators said the suspected attackers’ methods and the timing of the theft were consistent with criminals obtaining private keys from encrypted password-vault data stolen in the 2022 LastPass breaches.
That connection is significant, but it is not the same as a final court finding that LastPass caused the theft. The public reporting describes an unsealed civil forfeiture complaint and investigative reasoning—not a criminal conviction, a completed forfeiture judgment, or a confirmed recovery of the full $150 million.
What the United States seized
The disclosed amount was $23,604,815.09 in cryptocurrency. Investigators traced the funds through several exchanges and crypto services, including OKX, Payward Interactive (doing business as Kraken), WhiteBIT, AscendEX, FixedFloat, SwapSpace and CoinRabbit. The tracing covered activity from June 2024 through February 2025.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →“Seized” can describe several stages of a cryptocurrency investigation. An exchange may freeze suspicious funds; a service may transfer assets to wallets controlled by investigators; or the government may place property under its control while pursuing civil forfeiture. In this case, the available reporting is based on an unsealed forfeiture complaint and related statements. It does not establish that the cryptocurrency had already been finally forfeited to the government or distributed to victims.
#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
WhiteBIT said it detected suspicious activity, froze relevant funds and returned them to the FBI on August 14, 2024, under a court order. That arrangement allowed the assets to remain under government control during the legal proceedings and possible compensation process. It should not be read as proof that victims had already been paid.
How the seizure relates to the $150 million Ripple-linked theft
The seized cryptocurrency was linked to a much larger theft: approximately $150 million taken from a wallet belonging to Chris Larsen, Ripple’s co-founder and executive chairman. Larsen publicly disclosed the theft on January 31, 2024, in a public statement on X.
The $23.6 million represents only a portion of that estimated theft. It does not mean the United States recovered the entire amount. Dollar estimates can also vary depending on when the value of the stolen XRP and other assets is measured, because cryptocurrency prices fluctuate.
The forfeiture complaint reportedly did not name LastPass, Larsen or the alleged attackers. Instead, investigators connected the case to an unnamed password manager whose breach timeline and technical details matched LastPass’s publicly reported 2022 incidents.
How investigators connected the funds to LastPass
The reported theory is an attribution based on several facts rather than a publicly demonstrated, step-by-step reconstruction of every compromise:
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
- The victim’s devices reportedly showed no evidence that they had been hacked.
- The wallet’s private keys were believed to have been stored in a password vault.
- The relevant password-manager provider suffered two major breaches in 2022.
- Attackers stole encrypted vault backups and associated customer information.
- Investigators believed the attackers later cracked or decrypted the vault data needed to obtain wallet credentials.
- The scale, timing, rapid movement of funds and similarities to other crypto thefts were considered consistent with the same threat actors.
That reasoning supports the careful description that U.S. authorities linked the funds to suspected attackers behind the LastPass breaches. It does not prove that every crypto theft associated with stolen LastPass data came from the same group, that every affected vault was decrypted, or that every LastPass customer was compromised.
What happened in the LastPass breaches?
LastPass reported a two-stage attack in 2022. In August, an attacker compromised a developer account and gained access to the company’s development environment, including source code and proprietary technical information. In a later intrusion, the attacker used information and keys obtained from that environment to access archived production backups in cloud storage.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Those backups contained customer account information and metadata, along with encrypted password-vault data. LastPass said sensitive vault fields were protected with AES-256 encryption and that decryption depended on each customer’s master password, which the company did not possess. Reporting on the incidents is available in coverage of the developer-environment breach and the cloud-storage breach.
Encrypted vault theft does not automatically reveal every stored password. The practical risk depends on factors such as the strength and uniqueness of the master password, the vault’s password-derivation settings, whether the master password was reused, and whether the user changed credentials after the breach. However, stolen encrypted vaults can give attackers material for offline password-cracking attempts without repeatedly triggering an online login lockout.
Why cryptocurrency users faced unusual risk
Traditional website passwords can often be replaced. A blockchain private key or seed phrase is different: whoever possesses it may be able to sign transactions directly. Multifactor authentication on an exchange does not stop an attacker who already has the private key for a self-custodied wallet.
Rank #3
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
Password vaults may contain much more than ordinary login credentials, including:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Wallet private keys and seed phrases
- Exchange passwords and API keys
- Email credentials and cloud-storage logins
- Two-factor authentication backup codes
- Notes containing wallet instructions or recovery information
Researchers had previously linked additional cryptocurrency thefts to private keys and passphrases found in stolen LastPass databases, while noting that weak master passwords were more susceptible to offline cracking. That research is an attribution, not a court judgment.
What LastPass says
LastPass said it cooperated with law enforcement but had not been told of conclusive evidence connecting cryptocurrency thefts to its incident, according to the reporting. That response matters because the forfeiture complaint’s connection appears to be investigative and circumstantial in the public record.
The strongest accurate summary is therefore: investigators believe stolen LastPass vault data was used to obtain credentials involved in the Larsen-linked theft, but the available material does not establish a final judicial finding that LastPass caused the theft or that all related cryptocurrency losses followed one attack path.
What former LastPass users should do now
If you used LastPass in 2022—or stored sensitive information there before changing it—changing only your LastPass master password is not enough. Treat old secrets as potentially exposed and work through the following priorities.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
1. Replace exposed wallet keys
If a seed phrase or private key was stored in the vault, create a completely new wallet and transfer assets to it. Do not reuse the old seed phrase. Changing a wallet app’s PIN or password may protect the application, but it does not replace the underlying blockchain key.
Use a trusted device and independently verify the destination address on a trusted hardware-wallet screen or another reliable channel before approving a transfer. Do not store the new seed phrase in the old vault, email, cloud notes, screenshots or an unencrypted document.
2. Rotate account credentials
- Change the email account associated with cryptocurrency services first, because email access can enable password resets.
- Change exchange, brokerage and financial-account passwords.
- Revoke and regenerate exchange API keys, especially keys with trading or withdrawal permissions.
- Replace passwords that were stored in the vault during the affected period.
- Change any password reused on financial, workplace, cloud or social accounts.
- Reissue exposed recovery codes and remove unfamiliar authentication methods.
3. Revoke access and monitor activity
Sign out active sessions, review login history, inspect email forwarding rules and check cryptocurrency and exchange transaction histories. Watch for unauthorized withdrawals, new API keys, address-book changes and unfamiliar devices.
4. Preserve evidence and report losses
Keep wallet addresses, transaction hashes, exchange notifications, screenshots and relevant correspondence. If assets are missing, contact the exchange or wallet provider, report the incident to law enforcement and consider a qualified cryptocurrency incident-response provider. Never send additional money to anyone promising to recover seized funds.
Free tools Windows power users keep installed
One-click scans. No signup required.
Security lessons beyond LastPass
A new password manager can improve future credential hygiene, but it cannot make an already exposed seed phrase safe. Password managers remain useful for generating and storing unique website passwords, and services such as Bitwarden, 1Password and Proton Pass offer different approaches to encryption, sharing, passkeys and account protection. Do not import old wallet secrets into a replacement service until you have assessed and replaced them.
Best Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
Security keys using FIDO2 or WebAuthn can add strong phishing resistance to email, exchanges and password-manager accounts. Hardware wallets can keep new signing keys away from ordinary computers. Neither protects a seed phrase that has already been copied into a breached vault.
Local or self-hosted vaults reduce reliance on a single cloud provider but transfer responsibility for backups, patching, availability and recovery to the user. Paper or metal seed backups avoid cloud exposure but introduce risks of theft, loss, fire and unauthorized physical access. Multifactor authentication, passkeys and hardware wallets address different parts of the threat model; none can revoke a private key that an attacker already possesses.
What this case proves—and what it does not
The seizure demonstrates the continuing danger of stolen encrypted password-vault data, particularly when users placed cryptocurrency keys inside those vaults. Data stolen years earlier can remain valuable if attackers can eventually crack the relevant master password or otherwise obtain the protected contents.
It does not prove that every LastPass user was compromised, that every stolen vault was cracked, that the entire $150 million was recovered, that LastPass was legally found liable, or that the seized assets have already been returned to victims. The legal status of the cryptocurrency—and any eventual compensation—depends on the forfeiture proceedings and subsequent court action.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

