Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

429+ Articles
114+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ETH Zurich Finds 25 Password Recovery Attacks Against
ETH Zurich Finds 25 Password Recovery Attacks Against
NEWS

ETH Zurich Finds 25 Password Recovery Attacks Against

Researchers from ETH Zurich demonstrated that the zero-knowledge encryption claims of major password managers break down if the server is compromised,...

Dylan H.

News Desk

February 17, 2026
2 min read

"Zero-Knowledge" Claims Challenged

Researchers from ETH Zurich have published findings demonstrating that the "zero-knowledge encryption" claims of major password managers break down if the server is compromised. Their research found 25 password recovery attacks across three major password managers serving 60+ million users collectively.


Attack Breakdown

Password ManagerTotal AttacksLeading to Password Disclosure
Bitwarden127
LastPass73
Dashlane61

How the Attacks Work

The research exploits a fundamental design choice: many password managers encrypt individual fields separately rather than the entire vault as a single authenticated blob. This enables "cut-and-paste" style attacks where a compromised server can:

  1. Rearrange encrypted entries within a vault without detection
  2. Inject malicious entries that exfiltrate data when the vault is decrypted client-side
  3. Modify metadata to redirect autofill to attacker-controlled domains
  4. Downgrade encryption on specific entries during sync operations

Threat Model

The attacks require the attacker to compromise the password manager's server — a scenario the vendors' "zero-knowledge" marketing specifically claims to protect against. The researchers argue this threat model is realistic given:

  • LastPass was breached in 2022 and encrypted vaults were stolen
  • Cloud services are frequent targets of sophisticated threat actors
  • Insider threats at the provider level
  • Supply chain compromises of server infrastructure

Vendor Responses

All three vendors have implemented countermeasures following responsible disclosure:

  • Bitwarden: Deployed additional vault integrity checks
  • LastPass: Enhanced encryption validation during sync
  • Dashlane: Implemented authenticated encryption improvements

Recommendations for Users

  1. Use a strong, unique master password — the attacks are easier with weak master passwords
  2. Enable hardware security keys for MFA on your password manager account
  3. Keep your password manager updated to benefit from vendor patches
  4. Consider local-only password managers (KeePass) for highest-sensitivity credentials
  5. Monitor for unexpected vault changes or new entries

Research Details

The research will be presented at USENIX Security 2026. The full paper details the attack methodology, proofs of concept, and vendor mitigations.


While password managers remain significantly more secure than password reuse, this research highlights that "zero-knowledge" is not an absolute guarantee — server compromise can still threaten stored credentials.

#Password Managers#Research#Bitwarden#LastPass#Dashlane#Zero-Knowledge#ETH Zurich

Related Articles

Anti-Piracy Coalition Takes Down AnimePlay App with 5 Million Users

The Alliance for Creativity and Entertainment has announced the shutdown of AnimePlay, a major unauthorized anime streaming platform serving over 5 million users worldwide.

3 min read

Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV Audio

Threat actors known as TeamPCP compromised the Telnyx Python package on PyPI, uploading malicious versions that conceal credential-stealing malware inside a WAV audio file using steganographic techniques.

4 min read

Bearlyfy Hits Russian Firms with Custom GenieLocker Ransomware

Pro-Ukrainian hacktivist group Bearlyfy has conducted over 70 cyberattacks against Russian companies since January 2025, recently deploying a custom Windows ransomware strain called GenieLocker in targeted operations.

4 min read
Back to all News