The LastPass Warning
In 2022, LastPass was breached. Hackers stole encrypted password vaults for 25+ million users. Since then, over $35 million in cryptocurrency has been stolen from LastPass users whose vaults were cracked,and the thefts continue into 2026. [1]
As of March 2025, federal prosecutors linked a $150 million crypto heist to the LastPass breach. The FBI and Secret Service confirmed the connection. [2]
Your password manager choice matters. Here's how they compare.
Quick Comparison
| Feature | Bitwarden | 1Password | LastPass | Dashlane | Proton Pass |
|---|---|---|---|---|---|
| Price (Individual) | Free / $10/year | $36/year | $36/year | $60/year | Free / $36/year |
| Open Source | Yes (full) | No | No | Partial (mobile only) | Clients only |
| Security Breaches | None known | None known | Multiple (2022 major) | None known | None known |
| Self-Hosting | Yes | No | No | No | No |
| Free Tier | Unlimited passwords | 14-day trial only | 1 device type | 25 passwords max | Unlimited passwords |
| Encryption | AES-256 | AES-256 + Secret Key | AES-256 | AES-256 | AES-256-GCM |
| Our Rating | Recommended | Recommended | Avoid | Acceptable | Recommended (caveats) |
Why LastPass Is No Longer Recommended
LastPass used to be the default recommendation. Not anymore.
The 2022 Breach Timeline
- August 2022: Hackers access LastPass source code
- November 2022: LastPass discloses second breach,vaults stolen
- February 2023: Reveals a DevOps engineer's home computer was compromised via vulnerable third-party software
- December 2022 onwards: Crypto thefts targeting LastPass users begin
The Ongoing Damage
The breach wasn't just data exposure,it was vault theft. [3]
- 25+ million users had encrypted vaults stolen
- $35+ million in cryptocurrency stolen from users since breach
- $150 million heist in January 2024 linked to breach by FBI [2]
- Thefts continued through December 2024 [2]
The threat actors are cracking stolen vaults to access cryptocurrency wallet seeds and private keys. Once cracked, funds are drained within minutes.
If You Still Use LastPass
- Export your data and migrate to another manager immediately
- Change ALL passwords stored in LastPass
- Move cryptocurrency to new wallets with fresh seed phrases
- Enable 2FA everywhere the compromised credentials were used
- Delete your LastPass account after migration
Bitwarden: The Open Source Choice
Why We Recommend It
- Fully open source: All code publicly auditable on GitHub
- No breaches: Clean security record
- Best free tier: Unlimited passwords, unlimited devices, free forever
- Self-hosting option: Run your own server for maximum control
- Regular audits: Cure53 and other third-party security testing
- Affordable premium: $10/year adds advanced 2FA and file storage
Security Architecture
- AES-256-CBC encryption
- PBKDF2 SHA-256 key derivation (100,001 iterations minimum)
- Zero-knowledge: Bitwarden can't see your passwords
- Salted hashing: Additional protection layer
- End-to-end encryption: Data encrypted before leaving device
Limitations
- Interface less polished than 1Password
- No Secret Key for additional protection
- Self-hosting requires technical knowledge
Best For
- Privacy-conscious users who value open source
- Budget-conscious users
- Technical users who want self-hosting
- Anyone migrating from LastPass
Get Bitwarden: Read our full review or visit bitwarden.com
1Password: The Premium Choice
Why We Recommend It
- No breaches: Clean security record
- Secret Key: Additional encryption layer unique to 1Password
- Travel Mode: Hide sensitive vaults when crossing borders
- Polished UI: Best user experience of major managers
- 25+ security audits: Extensive third-party testing
- Passkey support: Ready for passwordless future
Security Architecture
- AES-256-GCM encryption
- Dual-key model: Master password + Secret Key required
- Zero-knowledge: 1Password can't decrypt your data
- PBKDF2 key derivation with high iteration counts
- Secret Key: 128-bit key generated locally, never sent to 1Password
The Secret Key Advantage
Even if attackers steal your encrypted vault AND crack your master password, they still can't access your data without the Secret Key stored on your devices. This is a significant security advantage over other managers.
Limitations
- Not open source (proprietary code)
- No free tier (14-day trial only)
- More expensive than Bitwarden
- Canada jurisdiction (Five Eyes member)
- No self-hosting option
Best For
- Users who prioritize UX and features
- Families (good family plan)
- Travelers (Travel Mode)
- Users willing to pay for premium experience
Get 1Password: Read our full review or visit 1password.com
Proton Pass: The Privacy Bundle Newcomer
Proton Pass is the youngest name here. It launched in beta in April 2023 and hit general availability that June, years after Bitwarden and 1Password had matured. That youth shows. Reviewers who like it still note missing folders, occasional autofill misses, and duplicate entries when you mix logins and aliases. So we recommend it with caveats, not without them.
What makes it interesting is who is behind it. Proton AG is the Swiss company behind Proton Mail, founded in 2014 by scientists who met at CERN. In 2024 the founders handed voting control to the non-profit Proton Foundation, whose board includes web inventor Tim Berners-Lee. That structure is unusual, and it is a real answer to the "what happens when the founders cash out" question that hangs over most privacy tools.
Why We Recommend It (With Caveats)
- Open source clients, audited: Proton released the client apps under GPLv3 in July 2023 and had Cure53 run a white-box audit at the same time. A second firm, Recurity Labs, audited the apps again in early 2026 and rated the security posture "well above par."
- Everything is encrypted, not just the password: usernames, web addresses and notes are all end-to-end encrypted, so Proton cannot see which services you hold accounts with.
- Built-in email aliases: Proton bought SimpleLogin in 2022, so hide-my-email aliases are baked in. This is the feature no other manager on this page matches.
- Genuine free tier: unlimited logins on unlimited devices, plus 10 hide-my-email aliases and up to three stored 2FA codes.
- Passkeys on every plan: passkey support arrived in 2024 for free and paid users alike.
Security Architecture
- 256-bit AES-GCM vault keys, with a separate key for each item so encryption is item-level, not just vault-level
- bcrypt key derivation from your account password plus a salt; Proton argues bcrypt is tougher than the PBKDF2 most rivals use
- SRP authentication: a hardened Secure Remote Password handshake to resist man-in-the-middle attacks
- OpenPGP with Curve25519 for the cryptography behind encrypted sharing between users
- PIN and extra-password locks for local protection on top of the account password
Pass Monitor: Free vs Paid
Proton splits its monitoring feature down the middle. Password Health checks and inactive-2FA detection are free. Dark Web Monitoring and Proton Sentinel account-takeover protection need a paid plan. The built-in 2FA authenticator with unlimited codes and file attachments are paid-only too.
Pricing (Read the Renewal, Not the Promo)
The free plan is real and usable. Pass Plus lists at $4.99/month billed monthly, or $2.99/month on the annual plan (about $36 a year) as of mid-2026. Proton has run promos as low as $1/month at launch, and from January 2024 the regular annual price was officially $1.99/month, so third-party reviews quoting those lower figures may just be dated. Check the live price on proton.me before you commit, and judge it at the renewal rate rather than the first-year teaser.
Limitations
- Youngest of the bunch: thinner documentation, a smaller community, and rough edges like no folders and the odd autofill miss, versus Bitwarden's seven-year head start
- No self-hosting: the server code is closed source and cloud-only, so unlike Bitwarden you cannot run your own instance
- Ecosystem lock-in: the alias feature that makes Pass great also ties you to Proton, and heavy alias users face real friction if they ever want to leave
Best For
- People who want email aliases and a password manager in one tool
- Existing Proton Mail or Proton VPN users
- Privacy-conscious users who value the non-profit ownership structure
- Anyone content with a cloud-only manager who does not need self-hosting
Get Proton Pass: Read our full review or visit proton.me/pass
Dashlane: The Middle Ground
Why It's Acceptable
- No breaches: Clean security record
- ISO 27001 certified: Business-grade security standards
- VPN included: Basic VPN with premium plans
- Dark web monitoring: Alerts for compromised credentials
- AES-256 encryption: Industry standard
Limitations
- Most expensive: $60/year for individual plan
- Weak free tier: Only 25 passwords
- Mostly proprietary: Only mobile app is open source
- No self-hosting: Cloud-only
Best For
- Users who want VPN bundled
- Business users needing compliance features
What About KeePass?
KeePass deserves mention as the fully offline option:
- Completely local: Database never leaves your device
- Open source: Fully auditable
- Free forever: No subscription
- No cloud sync: You manage backups and sync
KeePass Is Best For
- Maximum paranoia (data never touches internet)
- Technical users comfortable with manual sync
- Air-gapped systems
KeePass Drawbacks
- No built-in sync (manual or third-party required)
- Less polished interface
- Browser integration requires plugins
- Mobile apps are third-party (KeePassDX, Strongbox)
Security Features Comparison
Two-Factor Authentication
- Bitwarden: TOTP free, hardware keys with premium
- 1Password: TOTP and hardware keys included
- LastPass: TOTP free, hardware keys premium
- Dashlane: TOTP and hardware keys included
- Proton Pass: Up to three 2FA codes free, unlimited authenticator with Plus
Breach Monitoring
- Bitwarden: Vault health reports (free)
- 1Password: Watchtower dashboard
- LastPass: Dark web monitoring (premium)
- Dashlane: Dark web monitoring included
- Proton Pass: Password health free, dark web monitoring (paid)
Emergency Access
- Bitwarden: Yes (premium)
- 1Password: Yes (via recovery)
- LastPass: Yes
- Dashlane: Yes
Passkey Support
- Bitwarden: Yes
- 1Password: Yes
- LastPass: Yes
- Dashlane: Yes
- Proton Pass: Yes (free and paid)
Privacy Considerations
Jurisdiction
- Bitwarden: USA (can be mitigated with self-hosting)
- 1Password: Canada (Five Eyes)
- LastPass: USA
- Dashlane: USA/France
- Proton Pass: Switzerland (strong privacy law, though a 2025 surveillance-ordinance proposal that Proton threatened to leave the country over was sent back for an external review after public pushback and remains unresolved as of mid-2026)
Data Collection
All major password managers claim zero-knowledge architecture,they can't see your passwords. However:
- Bitwarden: Minimal telemetry, can self-host for zero data sharing
- 1Password: Some service data collected, clear privacy policy
- LastPass: More extensive analytics
- Dashlane: Standard analytics
Our Recommendations
For Most People: Bitwarden
Best combination of security, privacy, and value. Free tier is genuinely excellent. Open source means verifiable security.
For Premium Features: 1Password
If you're willing to pay and want the best user experience, Travel Mode, and Secret Key protection. No security compromises.
For Maximum Security: Bitwarden (self-hosted) or KeePass
Keep your password database on your own infrastructure. Zero trust in third parties.
For Email Aliases and a Privacy Bundle: Proton Pass
If you want hide-my-email aliases built into your password manager, or you already live in Proton's ecosystem, Pass is the pick. Go in knowing it is the youngest option here and there is no self-hosting.
Avoid: LastPass
The 2022 breach and ongoing crypto thefts make it impossible to recommend. Migrate immediately if you're still using it.
How to Choose
Ask Yourself:
Budget Priority?
→ Bitwarden (free tier is best in class)
Best UX and Features?
→ 1Password (polished experience, Travel Mode)
Open Source Required?
→ Bitwarden (fully open source)
Self-Hosting Required?
→ Bitwarden or KeePass
Completely Offline?
→ KeePass
Family Sharing?
→ 1Password or Bitwarden (both have good family plans)
Setting Up Your Password Manager
Step-by-Step
- Choose your manager based on priorities above
- Create a strong master password - 16+ characters, random or passphrase
- Enable 2FA immediately - Before adding any passwords
- Save recovery codes offline - Print or write down, store securely
- Install on all devices - Browser extension + mobile app
- Import existing passwords - From browser or old manager
- Run security audit - Fix weak/reused passwords
- Delete passwords from browser - Don't store in multiple places
The Bottom Line
Any password manager is better than no password manager. But after the LastPass disaster, choice matters.
Our top picks:
- Best overall: Bitwarden - Open source, free, secure, no breaches
- Best premium: 1Password - Secret Key, Travel Mode, polished UX
- Avoid: LastPass - Ongoing fallout from 2022 breach
Don't reuse passwords. Don't store them in browsers. Don't use LastPass. Use a proper password manager and enable 2FA on the account.
References
- Krebs on Security - Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach (September 2023)
- Krebs on Security - Feds Link $150M Cyberheist to 2022 LastPass Hacks (March 2025)
- LastPass Blog - Security Incident December 2022 Update
- Cyber Insider - 1Password vs Bitwarden: 8 Tests, 1 Clear Winner (2025)
- 1Password - Security Audits