HexVault
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Blog
  • Download
Sign In Start Free Trial
  • HexGuard AI
  • Pricing
  • Security
  • IAM
  • Extension
  • Extension Security
  • Enterprise
  • Blog
  • Download
  • About
  • Contact
  • Trust Centre
  • FAQ
Sign In Start Free Trial
Migration

Switch from LastPass to HexVault

4 min · Export from LastPass, import to HexVault

Leaving LastPass for HexVault takes about five minutes: export a CSV from LastPass, import it into HexVault, then rotate anything sensitive. If you are moving because of the 2022 breach, the rotation step matters — read on.

Where to import: open your HexVault vault and go to Settings → Data → Import Passwords, choose LastPass, and drop in the file you export below.

Step 1 — Export from LastPass

  • Open the LastPass browser extension or web vault.
  • Go to Account Options → Advanced → Export.
  • Confirm your master password if prompted, and save the .csv file.

Handle the export file carefully. It is unencrypted plaintext — anyone who opens it has your passwords. Keep it only as long as the import takes, then delete it and empty your trash.

Step 2 — Import into HexVault

  • Open HexVault and go to Settings → Data → Import Passwords.
  • Choose LastPass as the source.
  • Drop in the CSV file you just exported. HexVault parses it and re-encrypts every entry in your browser with your master password before anything is sent — we only ever receive ciphertext.
  • Review the preview and confirm.

Before you switch: rotate what matters

If your LastPass vault existed before December 2022, treat its contents as potentially exposed. In the 2022 breach, attackers exfiltrated backup copies of customer vaults — including some unencrypted metadata such as URLs — and offline cracking of weak master passwords has been linked to thefts for years since, with a UK ICO penalty issued in November 2025. This is public record. Moving managers is the right instinct; while you are at it, rotate your most important passwords — email, banking, anything financial, and any stored recovery phrases — because a stolen copy of an old vault does not expire.

HexVault is built to reduce exactly this class of risk: your key is derived with memory-hard Argon2id, entry data including URLs is encrypted, and each entry gets its own derived key. See the full HexVault vs LastPass comparison →

Compare HexVault and LastPass in detail →

Step 3 — After you import

  • Delete the export file and empty your trash — it is plaintext.
  • Run a security check. HexVault flags reused, weak, and breached passwords so you can fix the worst first.
  • Turn on two-factor for your HexVault account.

Import happens in your browser: your file is parsed and re-encrypted locally with your master password before anything is sent. Your key is derived with Argon2id and entries are sealed with AES-256-GCM. How the encryption works →  ·  All import sources →

HexVault

Zero-knowledge credential infrastructure for individuals, teams, and enterprises.

Product

Free Team Enterprise Extension Download Import Compare Security Changelog

Company

About Blog Careers Contact Press Status

Legal

Privacy Policy Terms of Service Cookie Policy Sub-processors Trust Centre FAQ
© 2026 HexVault Ltd · Registered in England & Wales hexvault.co.uk — Built in the UK · Patent Pending