Blog & News

Security Vulnerabilities in Password Managers

Written by Xiomi Paulino | 16.02.2026

Password Managers under the Microscope: ETH Study reveals Security Vulnerabilities and what Companies need to know now.

Researchers at ETH Zurich released a study yesterday showing that password managers offer less protection than promised. They recently examined several popular cloud-based password managers including Bitwarden, Dashlane, and LastPass. In tests, the ETH Zurich researchers were able to view and even modify stored passwords!

Many providers promise «zero-knowledge encryption.» This means that even they do not have access to the encrypted passwords. And even if someone gains access to the server, the security risk is said to be low because the data is encrypted and therefore unreadable. We will summarize for you what this means, how your company can address this, and what steps you should take.

 

What the ETH Researchers found.

  • The ETH researchers were able to demonstrate that, under certain conditions, an attacker can not only read encrypted passwords but also manipulate them.
  • The researchers demonstrated 12 attacks on Bitwarden, 7 on LastPass, and 6 on Dashlane. To do this, they set up their own servers that behaved like a hacked password manager server.
  • This was made possible through simulations in which an attacker controlled a password manager’s server and exploited typical user interactions.
  • The vulnerabilities stem, among other things, from complex, disorganized architecture and cryptographic mechanisms that are not robust enough against malicious server responses. Such attacks do not require particularly powerful computers or servers – only small programs that can be used to spoof the server’s identity.
  • The ETH study gave the providers 90 days to address the issues before publication. The providers were largely cooperative and grateful.


What ETH recommends.

  • Providers should communicate more clearly which security guarantees actually apply.
  • Systems should be upgraded to the latest cryptographic standards.
  • Users should choose password managers that are transparent, externally audited, and use end-to-end encryption by default.

 

Statement from LastPass: Response to the ETH Research.

The vendor LastPass has also responded by publishing an official statement in which it addresses the ETH findings and explains its actions.

  • LastPass welcomes security research and collaboration with ETH Zurich to strengthen systems.
  • LastPass emphasizes that there is no evidence that the identified vulnerabilities were actually exploited.
  • According to LastPass, the described issues require a highly privileged attacker with server-side control – not a typical usage scenario.

Specifically for LastPass, the reported issues can be divided into five major categories: 

 

LastPass emphasizes that each of these scenarios assumes a sophisticated attacker with persistent access to its production infrastructure. They do not reflect LastPass’s normal operations or expected user behavior.

Measures LastPass is working on.

Already implemented in the short term:

  • Improved handling of website icons and URLs to mitigate the manipulation scenarios described.

Mid-term and planned updates:

  • Strengthening cryptographic parameter validation and preventing insecure configurations.
  • Improvements to account recovery and sharing workflows to ensure that cryptographic keys cannot be swapped or tampered with.
  • Enhanced integrity of Vault data to prevent encrypted components from being inadvertently swapped out.

 

Recommendation for Customers.

It is generally recommended to take the following steps to enhance security:

  1. Enablemulti-factor authentication (MFA) and/or SSO for administrative accounts.
  2. Limit the number of super admins and regularly review permissions. Also, restrict permissions for shares and shared folders.
  3. Ensure that all users are using the latest versions of the apps and browser extensions.
  4. Use a strong, unique master password.
  5. Always keep software and extensions up to date.
  6. Choose password managers with open auditing, transparent security policies, and strong encryption.

 

Epic Fusion is staying on top of Things.

Our customers do not need to take any action. We are closely monitoring all developments and remain in contact with the providers. Should there be any impact on operational processes or customer environments, we will inform you immediately and proactively.