Researchers from ETH Zurich and Università della Svizzera italiana reported a set of password-recovery attacks affecting major cloud password managers Bitwarden, LastPass, and Dashlane, challenging common “zero-knowledge encryption” (ZKE) assurances. The work models a scenario where an attacker controls or compromises the provider-side infrastructure (i.e., a malicious/hacked server) and evaluates whether ZKE design goals still prevent credential exposure.
The study describes 25 total attacks—12 against Bitwarden, 7 against LastPass, and 6 against Dashlane—ranging from vault integrity violations to complete compromise of all vaults in an organization, with many attacks enabling recovery of stored passwords. The researchers attribute the findings to recurring design anti-patterns and cryptographic misconceptions in account recovery and related workflows, warning that server-side compromise can still translate into customer-impacting password theft even when vault data is marketed as “zero-knowledge” protected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly reported 25 attacks against cloud password managers under a malicious-server threat model: 12 affecting Bitwarden, 7 affecting LastPass, and 6 affecting Dashlane. The study said these weaknesses could enable integrity violations, password disclosure, password recovery, and in some cases full compromise of organizational vaults, challenging common zero-knowledge encryption claims.
Following disclosure, Bitwarden said several issues were resolved or were being remediated, while LastPass said it was strengthening integrity protections and planned to harden admin password reset and sharing workflows. 1Password said the reported behaviors reflected already documented architectural limitations rather than new attack vectors.
As part of its response to the disclosed issues, Dashlane said it removed support for legacy cryptography in its browser extension and published a response describing fixes. The company also said it found no evidence the issues had been exploited.
Researchers from ETH Zurich and USI notified Bitwarden, Dashlane, LastPass, and related vendors about malicious-server attack findings, shared proof-of-concept exploits, and started a coordinated disclosure process. The outreach began in early-to-mid 2025, with a 90-day deadline that was later extended in at least one case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcearstechnica.com
Open sourcegovinfosecurity.com
Open sourcethehackernews.com
Open sourcetechxplore.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.