LastPass Referral Code
If you had a vault in 2022, the exposure has not expired
LastPass is a password manager. In 2022 attackers obtained encrypted backups of approximately 30 million user vaults, which have since been linked to multi-year cryptocurrency theft.
Genie Says
Attackers took encrypted backups of roughly 30 million LastPass vaults in 2022, via a developer-environment breach and then the GoTo cloud storage provider. Because they hold the data offline, master passwords can be attacked indefinitely — and TRM Labs has traced over US$35 million in crypto thefts to those backups, with more than US$28m laundered through Wasabi in late 2024/early 2025 and drains continuing through late 2025. Anyone with a 2022 vault should rotate everything, email first, and migrate any crypto whose seed phrase was stored.
How much can you earn?
Share your own code and earn rewards when friends use it
The same. This page does not lead with it, for the reasons set out above.per successful referral*
Submit Your Code NowTop LastPass Referral Codes
No referral codes yet. Be the first to share yours and start earning!
Add Your Referral CodeNo codes match your search.
How to Use a LastPass Referral Code
Rotate email credentials first
Email recovers everything else, so it is the account that unlocks the rest if it is compromised.
Then financial and everything else
Assume every credential stored in a 2022 vault is compromised. Offline cracking leaves no trace you could detect.
Migrate any crypto that was in there
A seed phrase cannot be rotated. If one was ever stored in the vault, move the funds to a newly generated wallet.
Add hardware-backed 2FA and reissue recovery codes
Hardware 2FA survives a stolen password, and recovery codes stored in vaults are commonly forgotten.
Reward Details
- Your Reward
- Referral rewards are typically free premium months for both sides. Verify current terms with the provider.
- Referrer Reward
- The same. This page does not lead with it, for the reasons set out above.
- Minimum Purchase
- Not applicable.
- Validity
- 2022 breach: developer environment compromised, then GoTo cloud storage, yielding encrypted vault backups for approximately 30 million vaults.
- Available In
- USA, UK, India, Canada, Australia, Germany, France, Japan, China, Brazil, Italy, Spain, Mexico, South Korea, Russia, Netherlands, Switzerland, Sweden, Norway, Denmark, Finland, Ireland, Belgium, Austria, Portugal, Poland, Turkey, Saudi Arabia, United Arab Emirates, Israel, Singapore, Malaysia, Indonesia, Thailand, Philippines, Vietnam, Cyprus, Bangladesh, Sri Lanka, Nepal, South Africa, Nigeria, Egypt, Kenya, Argentina, Chile, Colombia, Peru, New Zealand, Greece, Czech Republic, Romania, Hungary, Qatar
- Referral Limit
- Not reliably documented.
- Payout Time
- Not applicable.
- Eligibility
- TRM Labs has traced over US$35m in crypto thefts to the stolen backups; more than US$28m laundered through Wasabi in late 2024/early 2025; drains continued through late 2025.
Why Choose LastPass?
No lockout, no rate limit. Attackers can attempt master passwords offline for as many years as they choose.
TRM Labs linked over US$35 million in crypto theft to the backups, with drains continuing through late 2025.
Irreversible, instantly liquid, and commonly stored as secure notes — but every other credential was in there too.
This is a warning about one incident, not an argument for reusing passwords across sites.
About LastPass
This page is not really about a referral bonus. If you held a LastPass vault in 2022 and have not since rotated what was in it, there is something you need to know, and it is still happening.
In 2022 LastPass suffered a two-stage compromise. Attackers first breached a developer environment and took portions of the company's source code. Then, using credentials obtained in that intrusion, they breached the cloud storage provider GoTo and took LastPass database backups — including encrypted vault backups for approximately 30 million vaults.
The critical property of that theft is not what was decrypted at the time. It is that the attackers hold the data.
An encrypted vault sitting on an attacker's disk can be attacked forever. There is no lockout, no rate limit and no expiry — they can try master passwords offline, at whatever speed their hardware allows, for as many years as they care to. A strong, unique, high-iteration master password remains very hard to break. A weak one, a reused one, or one protected by an older key-derivation configuration does not, and older accounts were disproportionately exposed to exactly that.
The consequences have been measured rather than theorised. TRM Labs has traced more than US$35 million in cryptocurrency thefts to the stolen vault backups, with on-chain indicators suggesting Russian cybercriminal involvement. More than US$28 million was converted to Bitcoin and laundered through Wasabi in late 2024 and early 2025, with off-ramps including Russia-based exchanges — one of which had previously been sanctioned for facilitating ransomware laundering. Wallet drains tied to the breach continued through late 2025.
Crypto seed phrases were hit hardest because they are the perfect target: irreversibly valuable, instantly liquid, and commonly stored in password managers as secure notes. But the vaults contained everything else people store — banking logins, email credentials, recovery codes — and those do not announce themselves when they are used.
So the practical instruction, which matters more than anything else on this page. If you had a LastPass vault at any point in 2022:
Treat everything that was in it as compromised, regardless of how strong you believe your master password to be, because you cannot detect an offline cracking attempt. Rotate passwords for every account that was stored, prioritising email first — because email recovers everything else — then financial accounts, then the rest. If any crypto seed phrase or private key was ever stored in that vault, move the funds to a newly generated wallet; rotating a seed phrase is not possible, so the only remedy is migration. Enable hardware-backed two-factor authentication wherever it is offered, since it survives a stolen password. And check any account that offered recovery codes, because those were commonly stored in vaults and commonly forgotten.
None of that is a comment on whether password managers are a good idea — they are, and using one remains far safer than reusing passwords across sites. It is a comment on a specific incident whose exploitation window has now run for over three years and has not closed.
On the referral: this site is not going to lead a page with a bonus when the more useful thing to hand someone is a list of accounts to rotate. If you want a password manager, the questions to ask are what happens to vault backups, how key derivation is configured, and whether the provider has published an independent audit.
Frequently Asked Questions
What Users Say About LastPass
Honest reviews from the GiveRefer community. Reviews from members with a verified referral are marked.
No reviews yet. Be the first to review LastPass.

