Leaving LastPass for HexVault takes about five minutes: export a CSV from LastPass, import it into HexVault, then rotate anything sensitive. If you are moving because of the 2022 breach, the rotation step matters — read on.
Where to import: open your HexVault vault and go to Settings → Data → Import Passwords, choose LastPass, and drop in the file you export below.
.csv file.Handle the export file carefully. It is unencrypted plaintext — anyone who opens it has your passwords. Keep it only as long as the import takes, then delete it and empty your trash.
If your LastPass vault existed before December 2022, treat its contents as potentially exposed. In the 2022 breach, attackers exfiltrated backup copies of customer vaults — including some unencrypted metadata such as URLs — and offline cracking of weak master passwords has been linked to thefts for years since, with a UK ICO penalty issued in November 2025. This is public record. Moving managers is the right instinct; while you are at it, rotate your most important passwords — email, banking, anything financial, and any stored recovery phrases — because a stolen copy of an old vault does not expire.
HexVault is built to reduce exactly this class of risk: your key is derived with memory-hard Argon2id, entry data including URLs is encrypted, and each entry gets its own derived key. See the full HexVault vs LastPass comparison →
Import happens in your browser: your file is parsed and re-encrypted locally with your master password before anything is sent. Your key is derived with Argon2id and entries are sealed with AES-256-GCM. How the encryption works → · All import sources →