HexVault
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Blog
  • Download
Sign In Start Free Trial
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Extension Security
  • Enterprise
  • Blog
  • Download
  • About
  • Contact
  • Trust Centre
  • FAQ
Sign In Start Free Trial
Comparison

HexVault vs LastPass

An honest comparison — updated July 2026

Most people comparing LastPass with an alternative in 2026 are doing so because of the 2022 breach. This page treats that honestly and factually rather than gleefully — the details are a matter of public record, and they matter for anyone deciding where to keep their passwords. It also covers the architectural differences and how to migrate safely if you decide to move.

What happened in 2022 — the facts

In 2022 LastPass disclosed two linked security incidents. An attacker first accessed parts of LastPass’s development environment, then used information from that intrusion to compromise a senior engineer’s device and reach a cloud backup store. The result, confirmed by LastPass and the UK Information Commissioner’s Office, was that attackers exfiltrated backup copies of customer vault data — including encrypted fields such as usernames and passwords, and unencrypted fields such as website URLs.

Because the stolen vaults were encrypted, they were not immediately readable. But an offline copy gives attackers unlimited time to brute-force weak master passwords, and security researchers and law enforcement have since linked the stolen data to a long series of cryptocurrency thefts continuing for years afterward. In November 2025 the UK ICO issued a monetary penalty against LastPass’s UK entity, and a class-action settlement was reached in the US. These are not allegations; they are documented outcomes.

If you had a LastPass vault before December 2022, treat its contents as potentially exposed to offline cracking — especially anything financial or any stored recovery phrases. Rotating those credentials is worth doing regardless of which manager you move to.

At a glance

 HexVaultLastPass
EncryptionAES-256-GCMAES-256-CBC
Key derivationArgon2id (memory-hard)PBKDF2
Per-entry key separationYes (per-entry HKDF)No
Unencrypted metadata in vaultNo — URLs are encrypted tooYes historically (URLs were not encrypted)
Known vault-data breachNoneYes (2022, confirmed)
Free tierYes (full personal vault)Yes (limited)
JurisdictionUnited KingdomUnited States

Competitor details as of July 2026 and subject to change. The breach facts are drawn from LastPass’s own disclosures, the UK ICO, and public reporting.

The lesson HexVault took from it

The LastPass breach is instructive regardless of which product you choose, and it shaped choices in HexVault:

  • Encrypt the metadata too. One of the most damaging details of the LastPass theft was that stored URLs were not encrypted, which let attackers prioritise the most valuable vaults. HexVault encrypts entry data including URLs, so a stolen blob reveals far less about what is worth attacking.
  • Make the master password expensive to attack. The vaults that fell were protected by weak master passwords run through PBKDF2. HexVault uses Argon2id, which is memory-hard and dramatically slower to brute-force at scale — buying time even against a stolen copy.
  • Separate keys per entry. Per-entry HKDF means there is no single key whose recovery unlocks everything at once.
  • Assume backups can be stolen. The failure was a backup store, not the live vault. Designing as though any stored blob may eventually leak is the only safe assumption.

None of this makes any product breach-proof, and HexVault does not claim to be. The honest difference is in what an attacker gets if a copy is ever taken.

The honest summary

LastPass remains a functioning password manager, and its current encryption is standard. But if the 2022 breach is why you are here, the reasonable response is to move your credentials somewhere with a clean record and a more conservative design, and to rotate anything sensitive that lived in a vault stolen in that incident. HexVault offers memory-hard key derivation, encrypted metadata, per-entry separation, and a free personal tier — and, like LastPass, is zero-knowledge, so we cannot read your vault.

Importing from LastPass takes about five minutes — and rotate the important ones after →

Other comparisons

HexVault vs Bitwarden  ·  HexVault vs 1Password

HexVault

Zero-knowledge credential infrastructure for individuals, teams, and enterprises.

Product

Free Team Enterprise Extension Download Import Compare Security Changelog

Company

About Blog Careers Contact Press Status

Legal

Privacy Policy Terms of Service Cookie Policy Sub-processors Trust Centre FAQ
© 2026 HexVault Ltd · Registered in England & Wales hexvault.co.uk — Built in the UK · Patent Pending