Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1577+ Articles
153+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ETH Zurich Finds 25 Password Recovery Attacks Against
ETH Zurich Finds 25 Password Recovery Attacks Against
NEWS

ETH Zurich Finds 25 Password Recovery Attacks Against

Researchers from ETH Zurich demonstrated that the zero-knowledge encryption claims of major password managers break down if the server is compromised,...

Dylan H.

News Desk

February 17, 2026
2 min read

"Zero-Knowledge" Claims Challenged

Researchers from ETH Zurich have published findings demonstrating that the "zero-knowledge encryption" claims of major password managers break down if the server is compromised. Their research found 25 password recovery attacks across three major password managers serving 60+ million users collectively.


Attack Breakdown

Password ManagerTotal AttacksLeading to Password Disclosure
Bitwarden127
LastPass73
Dashlane61

How the Attacks Work

The research exploits a fundamental design choice: many password managers encrypt individual fields separately rather than the entire vault as a single authenticated blob. This enables "cut-and-paste" style attacks where a compromised server can:

  1. Rearrange encrypted entries within a vault without detection
  2. Inject malicious entries that exfiltrate data when the vault is decrypted client-side
  3. Modify metadata to redirect autofill to attacker-controlled domains
  4. Downgrade encryption on specific entries during sync operations

Threat Model

The attacks require the attacker to compromise the password manager's server — a scenario the vendors' "zero-knowledge" marketing specifically claims to protect against. The researchers argue this threat model is realistic given:

  • LastPass was breached in 2022 and encrypted vaults were stolen
  • Cloud services are frequent targets of sophisticated threat actors
  • Insider threats at the provider level
  • Supply chain compromises of server infrastructure

Vendor Responses

All three vendors have implemented countermeasures following responsible disclosure:

  • Bitwarden: Deployed additional vault integrity checks
  • LastPass: Enhanced encryption validation during sync
  • Dashlane: Implemented authenticated encryption improvements

Recommendations for Users

  1. Use a strong, unique master password — the attacks are easier with weak master passwords
  2. Enable hardware security keys for MFA on your password manager account
  3. Keep your password manager updated to benefit from vendor patches
  4. Consider local-only password managers (KeePass) for highest-sensitivity credentials
  5. Monitor for unexpected vault changes or new entries

Research Details

The research will be presented at USENIX Security 2026. The full paper details the attack methodology, proofs of concept, and vendor mitigations.


While password managers remain significantly more secure than password reuse, this research highlights that "zero-knowledge" is not an absolute guarantee — server compromise can still threaten stored credentials.

#Password Managers#Research#Bitwarden#LastPass#Dashlane#Zero-Knowledge#ETH Zurich

Related Articles

Leak Confirms OpenAI Is Testing a ChatGPT for Science Subscription

A leaked interface reveals OpenAI is developing a specialized ChatGPT subscription tier for scientific research, potentially offering tailored tools for...

3 min read

Security of 100 AI Agents Tested and Ranked – What You Need to Know

A new AI Risk Quadrant framework has benchmarked 100 AI agents across three dimensions: vulnerability to compromise, potential breach impact, and strength of…

3 min read

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane's security systems automatically locked affected accounts to protect users after a brute-force attack resulted in a limited number of encrypted vault…

5 min read
Back to all News