Dashlane has disclosed a brute-force attack that exploited a gap in its device registration process, letting an attacker walk off with encrypted user vaults.
When Dashlane users add a new device, the service runs a registration step to verify the device should be allowed to sync their vault. According to the company's disclosure, an attacker brute-forced that registration step to gain unauthorized access. The payoff was encrypted password vaults: the attacker got ciphertext, not the plaintext credentials inside.
The device registration layer is exactly the kind of checkpoint that security models rarely foreground but turns out to be load-bearing. The encryption held; the authentication wrapper around reaching it did not. Password managers attract high-value attackers, so even encrypted vaults are worth stealing if master passwords are weak.
LastPass disclosed a similar vault theft in 2022, and the lesson is the same: "encrypted" buys time, not immunity.
