XDRIPACADEMY
Sign in

Curriculum·F106 The Threat Model·60 min

Who gets targeted and how

By the end of this lesson you can

  • Describe how target lists are actually assembled, and why selection is automated rather than personal
  • Explain why the interval between exposure and attack is measured in years, and what that implies for any past mistake
  • Locate yourself honestly on the target spectrum and name the tier you have most recently crossed into
  • Treat any secret that was ever exposed as compromised, and act on the ones in your own history
AutopsyThe LastPass vaults, breached 2022 and drained for years afterwards$150M in the single largest linked theft, more than $438M across the cluster by mid 2025

In 2022, intrusions at LastPass exposed backups of roughly 30 million encrypted customer vaults. Vaults with weak master passwords could be cracked offline, at the attacker's convenience, with no time limit and no way for the owner to know it was happening.

The pattern was found from the other end. Taylor Monahan and Nick Bax noticed a run of six-figure thefts from experienced, security-conscious holders who showed none of the usual indicators: no SIM swap, no email compromise, no phishing event. By tracing proceeds from many victims into shared addresses, and then interviewing them, they found the one thing every victim had in common. Each had, at some point, stored a seed phrase in the Secure Notes section of LastPass.

Federal investigators later linked a $150M theft on 30 January 2024 to the same breaches. Independent researchers connected the dataset to more than $438M in losses by mid 2025.

Now the part that makes this the right autopsy for this lesson. The damaging decision was made years before the loss. It was reasonable when it was made. And it was completely invisible afterwards.

Nobody was phished on the day their funds moved. There was no message to be suspicious of, no urgency to resist, no procedure from F106-02 that would have fired. The victims were selected by a dataset and worked through at leisure.

That is what target selection actually is, and it looks nothing like being singled out.

Primary source

Ask someone how they imagine being targeted and you get a person: someone who noticed them, decided they were worth it, and went after them.

That happens, at the very top of the range. For everyone else the picture is wrong in a way that produces bad decisions, mostly the decision that you are too ordinary to bother with.

How lists actually get built

Four inputs, joined by software.

Breach corpora. Billions of records from thousands of incidents, aggregated, cross-referenced and sold. The Coinbase records in F106-04 went into this pool with balances attached, which is unusually valuable. Most entries are older and thinner and still enough to make a message convincing.

On-chain screening. Every balance on every public chain is queryable. Filtering for addresses above a threshold, or recently active, or holding a particular asset, is a query anyone can run for free. There is no privileged access involved and no cost per address examined.

Correlation of handles and identities. The same username on a forum, an exchange, a domain registration and a public profile. This is joined automatically, at scale, and it is how bucket one from F106-04 turns into a real name.

Insider access. Bribed support contractors, as in the Coinbase autopsy. Rarer and much higher quality.

Nothing in that pipeline involves a human finding you interesting. It is a join across datasets, and you appear in the output because your row matched a filter.

Worked example
Why there is no lower bound

Work out what the attacker needs a target to be worth, given what selection actually costs them.

Screening. Scanning millions of addresses for balance is a database query against public data. Amortised per address, call it effectively $0.

Enrichment, meaning joining an address to an identity from breach data: a lookup in a dataset already purchased. Say $0.001 per record.

Contact, meaning a personalised message. From F111-01, roughly $0.005.

Total cost to select, enrich and attempt one target: about $0.006.

Now the break-even. If a success extracts $2,000, which is below the $2,764 average scam payment reported for 2025, the attacker profits at any success rate above:

$0.006 / $2,000 = 0.0000030 = 0.0003 percent, or about 1 in 333,000

Read the implication rather than the number. There is no balance small enough to be uneconomic, because the cost of trying is essentially zero and the whole list gets attempted regardless. "I hold too little to target" describes a decision nobody makes.

What being small does change is what kind of attempt arrives. Below a threshold you get the automated version, which is generic, high-volume, and reliably defeated by a written procedure. Above it, someone spends real time on you, and F106-02's levers get applied by a person who has read about your life.

So the useful question is never whether you are worth attacking. It is which of those two things is coming.

The interval is the cruel part

The LastPass vaults were taken in 2022. Funds moved in 2024 and 2025. Some have not moved yet.

An attacker holding an encrypted file is under no time pressure at all. They can wait for cracking to get cheaper, for a balance to grow, for a moment when the theft is less likely to be noticed. There is no cost to waiting and no expiry on the data.

This has one specific consequence and it is the most actionable thing in the lesson.

Nothing happened is not evidence that nothing will

If a secret of yours was ever exposed, and years have passed without incident, the natural conclusion is that you got away with it.

That conclusion is not supported. The LastPass victims had exactly that experience for two years, and it ended when someone got round to their row.

So: any secret that was ever exposed is compromised, regardless of elapsed time. A seed that was ever a photo, ever in a cloud note, ever in a password manager, ever typed into a machine you no longer trust. The remedy is not vigilance and it is not hoping. It is generating a new seed and moving the funds, which costs an afternoon and some transaction fees.

Most people reading this have at least one such secret in their history. This paragraph is the reason this lesson exists.

Where you sit, honestly

Four tiers. Locate yourself, then locate yourself again in two years.

Tier 0, in the pool. Anyone with an exchange account or an on-chain balance. You receive automated attempts continuously. Written procedures handle this tier completely.

Tier 1, correlated. Your identity can be joined to a balance: KYC data in a breach, a reused handle, a public address. Attempts get personalised. They will know your name, your platform, and roughly your size. Everything in F106-04 is about staying out of this tier or degrading the quality of the join.

Tier 2, known. People who are not looking for you know you hold. A public profile, a company role, a local reputation, a post that circulated. Attempts become bespoke and the physical risk from F110-05 enters the model.

Tier 3, worth a campaign. The holding justifies weeks of work: research, an approach through a person you trust, a synthetic-media component. Nine figures, but also considerably less if you are reachable and unprotected.

The transitions are what to watch, because they are silent. Nothing notifies you when a breach moves you from 0 to 1. Nothing notifies you when a post moves you from 1 to 2. The LastPass victims moved from 0 to a targeted list in 2022 and found out in 2024.

Common misconception

The people who lose money are the ones who were not being careful.

Read the researchers' own description of the LastPass victims: experienced, security-conscious investors, showing none of the usual signs of compromise. They were using a password manager, which is what security advice tells everyone to do. They were not being careless. They were being careful in 2019, using the standard recommendation of 2019, and the recommendation changed underneath them.

That is the general shape. The Coinbase customers did nothing wrong. The Genesis victim in F106-02 had clearly thought about security. What these cases share is not carelessness, it is a decision that was correct when made and was never revisited.

The practical version of this is that your security has an expiry date you will not be told about. F106-01's threat model is not a document you write once. The annual review is the control.

What this actually asks you to do

Audit your own history, not just your present. Where has your seed ever been? Which services hold your identity? Which handles do you reuse? The exposure that matters is usually already in the past.

Rotate anything that was ever exposed. New seed, move the funds. Once. Then stop worrying about it, which is the actual benefit.

Watch your transitions. Before you post something that names you as a holder, notice that you are choosing to move a tier, and that the move does not reverse.

Review annually. Not because attacks change fast, though they do, but because your own tier changes quietly and the setup that fit you two years ago was built for a different person.

Key takeaway

You are not chosen, you are filtered: breach corpora, on-chain balance screening and reused handles are joined automatically, and at a cost near zero per attempt there is no balance too small to be tried. What being small changes is whether the attempt is automated or crafted. The interval between exposure and theft is measured in years, so quiet is not safety, and any secret that was ever exposed should be treated as compromised and rotated now. The LastPass victims were careful people following the standard advice of the day, which is the real warning: your threat model expires without telling you.

These come back later

How are targets actually selected?
By filtering a dataset, not by choosing a person. Breach corpora, on-chain balance screening, KYC leaks and reused handles are joined automatically. Nobody decided you were interesting.
How long can the gap be between exposure and theft?
Years. The LastPass vaults were taken in 2022 and drained through 2024 and 2025. An attacker holding an encrypted file has no deadline, which means silence is not evidence that you got away with anything.
What do you do about a secret that was exposed once, long ago, with no consequences since?
Treat it as compromised and rotate it. Absence of loss is not evidence of safety when the attacker's cost of waiting is zero.

Sources and review

Confidence medium·Volatility high·Reviewed 2026-08-05·Owner unassigned

Contested

The attribution of specific thefts to the LastPass breach is investigative and circumstantial, built from on-chain clustering plus victim interviews, and later supported by federal seizures. It is strong and it is not a court finding for every case in the cluster. Say linked, not proven.

Loss totals attributed to this breach range from $150M for the single largest theft to more than $438M across the cluster by mid 2025, and continue to move. Always attach the date and the source to any figure.

The attacker economics in the worked example are constructed to illustrate why selection has no lower bound. They are not derived from a measured campaign.

Track your progress

Create a free account to mark lessons complete and pick up where you left off.