Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised. The team, comprised of researchers from ETH Zurich and Università della Svizzera italiana (USI), examined the "zero-knowledge encryption" promises made by Bitwarden, LastPass, and Dashlane, finding all three could expose passwords if attackers compromised servers. The premise of zero-knowledge encryption is that user passwords are encrypted on their device, and the password manager's server acts merely as a dumb storage box for the encrypted credentials. Therefore, in the event that the vendor's servers are controlled by malicious parties, attackers wouldn't be able to view users' secrets. As one of the most popular alternatives to Apple and Google's own password managers, which together dominate the market, the researchers found Bitwarden was most susceptible to attacks, with 12 working against the open-source product. Seven distinct attacks worked against LastPass, and six succeeded in Dashlane. The attacks don't exploit weaknesses in the same way that remote attackers could exploit vulnerabilities and target specific users. Instead, the researchers worked to test each platform's ability to keep secrets safe in the event they were compromised. In most cases where attacks were successful, the researchers said they could retrieve encrypted passwords from the user, and in some cases, change the ent...
You probably can't trust your password manager if it's compromised
The Register
·Connor Jones
·Published Feb 16, 2026
·Updated
Affected Software
3 affected components
Bitwarden Bitwarden<=12
LastPass LastPass<=7
DashLane DashLane<=6
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses vulnerabilities in three popular password managers and their effectiveness in protecting user credentials during server compromises.
2
What security implications are discussed in the article?
The implications include potential risks to user data integrity and confidentiality if these password managers are compromised.
3
Which password managers are affected by the flaws mentioned?
The affected password managers are Bitwarden, LastPass, and Dashlane.
4
What versions of the affected software should be noted?
Bitwarden versions up to 12, LastPass versions up to 7, and Dashlane versions up to 6 are noted as affected.
5
Who conducted the research on these vulnerabilities?
The research was conducted by a team of academics from ETH Zurich.