Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

980+ Articles
124+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ETH Zurich Finds 25 Password Recovery Attacks Against
ETH Zurich Finds 25 Password Recovery Attacks Against
NEWS

ETH Zurich Finds 25 Password Recovery Attacks Against

Researchers from ETH Zurich demonstrated that the zero-knowledge encryption claims of major password managers break down if the server is compromised,...

Dylan H.

News Desk

February 17, 2026
2 min read

"Zero-Knowledge" Claims Challenged

Researchers from ETH Zurich have published findings demonstrating that the "zero-knowledge encryption" claims of major password managers break down if the server is compromised. Their research found 25 password recovery attacks across three major password managers serving 60+ million users collectively.


Attack Breakdown

Password ManagerTotal AttacksLeading to Password Disclosure
Bitwarden127
LastPass73
Dashlane61

How the Attacks Work

The research exploits a fundamental design choice: many password managers encrypt individual fields separately rather than the entire vault as a single authenticated blob. This enables "cut-and-paste" style attacks where a compromised server can:

  1. Rearrange encrypted entries within a vault without detection
  2. Inject malicious entries that exfiltrate data when the vault is decrypted client-side
  3. Modify metadata to redirect autofill to attacker-controlled domains
  4. Downgrade encryption on specific entries during sync operations

Threat Model

The attacks require the attacker to compromise the password manager's server — a scenario the vendors' "zero-knowledge" marketing specifically claims to protect against. The researchers argue this threat model is realistic given:

  • LastPass was breached in 2022 and encrypted vaults were stolen
  • Cloud services are frequent targets of sophisticated threat actors
  • Insider threats at the provider level
  • Supply chain compromises of server infrastructure

Vendor Responses

All three vendors have implemented countermeasures following responsible disclosure:

  • Bitwarden: Deployed additional vault integrity checks
  • LastPass: Enhanced encryption validation during sync
  • Dashlane: Implemented authenticated encryption improvements

Recommendations for Users

  1. Use a strong, unique master password — the attacks are easier with weak master passwords
  2. Enable hardware security keys for MFA on your password manager account
  3. Keep your password manager updated to benefit from vendor patches
  4. Consider local-only password managers (KeePass) for highest-sensitivity credentials
  5. Monitor for unexpected vault changes or new entries

Research Details

The research will be presented at USENIX Security 2026. The full paper details the attack methodology, proofs of concept, and vendor mitigations.


While password managers remain significantly more secure than password reuse, this research highlights that "zero-knowledge" is not an absolute guarantee — server compromise can still threaten stored credentials.

#Password Managers#Research#Bitwarden#LastPass#Dashlane#Zero-Knowledge#ETH Zurich

Related Articles

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

The popular Bitwarden CLI password manager package @bitwarden/cli@2026.4.0 was compromised as part of an ongoing Checkmarx supply chain campaign, with...

6 min read

716,000 Impacted by OpenLoop Health Data Breach

Telehealth platform OpenLoop Health has disclosed that a January 2026 cyberattack resulted in the exfiltration of personal information belonging to 716,000 individuals, making it one of the largest healthcare data breaches reported this year.

4 min read

73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation

Attackers can compromise systems in under 90 seconds while patching and response still take hours or days. Picus Security breaks down why autonomous validation is becoming critical for modern defense strategies.

5 min read
Back to all News