\1 Was Bitwarden Breached in 2025? No. Here's What Actually Happened.
Back to Blog
Reading time: 10 minutes | Published: March 5, 2026 | Category: Password Managers

Was Bitwarden Breached in 2025? No. Here's What Actually Happened.

Written by Tim O., security engineer

The Short Answer

Bitwarden was not breached in 2025, 2024, or at any point in its history. If you found this article searching for a Bitwarden breach, here's what you're likely confusing it with: a 2025 ETH Zurich cryptography audit, Bitwarden's own State of Password Security report, or general post-LastPass breach anxiety about password managers in general. Bitwarden's security track record is clean. Read on for the full breakdown.

What's in This Article

What People Are Confusing It With

The search volume around "Bitwarden breach 2025" is real. Hundreds of people per month are looking for this. But after digging into what's driving those searches, three sources of confusion keep coming up.

1. The ETH Zurich Cryptography Audit (2025)

In 2025, Bitwarden published the results of a cryptography audit conducted by the Applied Cryptography Group at ETH Zurich. The audit tested Bitwarden's core cryptographic operations under an extreme scenario: a fully compromised, malicious server.

This was a proactive security exercise, not a breach disclosure. Bitwarden commissioned the audit themselves. All issues found were addressed and the full report was published publicly. That level of transparency is rare in this industry.

Audit findings getting headlines is normal. It does not mean the product was hacked.

2. Bitwarden's State of Password Security Report

Bitwarden publishes an annual password security research report. The 2025 edition analyzed data from 19 billion exposed credentials and found that 94% of people reuse passwords and 78% of common passwords can be cracked in under a second.

That's research about breached passwords across the internet broadly. Not a breach of Bitwarden itself. But headlines like "Bitwarden: 19 Billion Passwords Exposed" understandably create confusion.

3. LastPass Breach Fallout

The 2022 LastPass breach shook user trust in password managers across the board. After something that serious, people started auditing every tool they use. Searches for "was Bitwarden breached" spiked shortly after the LastPass news cycle. That anxiety is understandable, but Bitwarden and LastPass are different products with fundamentally different security track records.


Bitwarden Security Audit Timeline: 2018-2026

One of the reasons Bitwarden consistently earns trust from the security community is its commitment to publishing audit results. Here's the complete timeline:

Year Auditor Scope Outcome
2018 Cure53 Full source code audit, client apps, backend 5 findings, all resolved
2020 Insight Risk Consulting Network perimeter, web services penetration test Passed, no critical findings
2022 Cure53 Web app, browser extensions, security assessment 7 findings, 6 resolved post-assessment
2024 Fracture Labs Web app and network infrastructure 11 findings, majority resolved
2024 Unit 42 (Palo Alto) Mobile apps and mobile authenticator Published, issues addressed
2024 IOActive Client applications and SDKs Published, issues addressed
2025 ETH Zurich Applied Cryptography Group Core cryptography under malicious server scenario All findings addressed, report published

Every one of these reports is published on Bitwarden's compliance page. That's not what a company with something to hide does. Compare this to LastPass, which has not published a comparable independent security audit since their 2022 breach.


The ETH Zurich Audit: What It Actually Found

The 2025 ETH Zurich cryptography audit is worth covering in detail because it's the most technically significant security review Bitwarden has published.

The Applied Cryptography Group at ETH Zurich used what's called a "fully malicious server" threat model. In plain English: they assumed the worst possible scenario, that Bitwarden's own servers had been completely taken over by attackers. Then they tested whether a compromised server could extract user data.

This is a deliberately extreme test. As Bitwarden noted in their disclosure, a complete server takeover of this kind has never happened to any password manager. But they commissioned the test anyway because they wanted to know if their zero-knowledge architecture held up even under that scenario.

All issues identified in the report were addressed before publication. The full report is publicly available. This is what responsible security looks like.

Important context: Finding and fixing security issues through audits is not the same as being breached. Audits are proactive. Breaches are failures. Bitwarden's willingness to commission extreme-scenario testing and publish the results is a sign of security maturity, not weakness.


Bitwarden vs LastPass: Breach History Compared

The contrast between Bitwarden and LastPass's security records is stark. Here's the side-by-side:

Factor Bitwarden LastPass
Confirmed breaches None 2015, 2021, 2022-2023
Vault data stolen No Yes (2022, millions of vaults)
Open source Yes, fully No
Independent audits published Yes, annually, all public Not published post-breach
ETH Zurich cryptography review Yes (2025) No
SOC 2 Type 2 certified Yes Yes
Zero-knowledge architecture Yes Yes (but breached despite it)
Free tier Full-featured, unlimited devices Limited to 1 device type
Our verdict Recommended Switch to something else

The LastPass 2022 breach gave attackers offline copies of encrypted vaults for millions of users. Those vaults can be brute-forced indefinitely. If you're still on LastPass, read our full breakdown: Is LastPass Safe in 2026? The Honest Answer After 3 Breaches.


Is Bitwarden Safe to Use in 2026?

Yes. Bitwarden is one of the safest password manager choices available right now. Here's why I say that with confidence:

No breach history. In a decade of operation, Bitwarden has never had a confirmed security breach. That's not luck. That's architecture.

Open source means public scrutiny. Anyone can review Bitwarden's code on GitHub. Security researchers do, regularly. Vulnerabilities get found and reported through their HackerOne bug bounty program before they can be exploited.

Annual audits, published results. Every year, Bitwarden hires external security firms to try to break their product. The results go public regardless of outcome. That's a level of accountability most software companies avoid.

Zero-knowledge architecture, actually tested. The ETH Zurich audit specifically tested whether Bitwarden's zero-knowledge claims hold up even under a compromised server scenario. They held up.

The free tier is genuinely good. You get unlimited passwords and unlimited devices at no cost. There's no pressure to upgrade just to use basic features. This matters because it removes the financial incentive to cut corners on the free tier.

My honest take: if you're on Bitwarden, stay on Bitwarden. If you're evaluating password managers for the first time, Bitwarden earns its reputation. If you want a premium option with a polished interface and built-in breach scanner, NordPass is my top recommendation at $1.99/month.

For a detailed comparison of Bitwarden against 1Password, see our 1Password vs Bitwarden 2026: 30-Day Test.


What Would a Real Bitwarden Breach Look Like?

It's worth being clear about what would constitute an actual Bitwarden breach, so you know what to watch for.

A real breach would involve unauthorized access to Bitwarden's servers resulting in vault data being exfiltrated, or a vulnerability being exploited in the wild before it could be patched. Bitwarden would be required to disclose this, and as a public-facing security company, they would have every incentive to be transparent about it quickly.

Audit findings, research reports, and academic security papers are not breaches. They're the security industry doing its job.

If a real Bitwarden breach ever happens, it will be major news across every security publication simultaneously. You won't find out about it through a search engine months later.


Frequently Asked Questions

Was Bitwarden breached in 2025?

No. Bitwarden was not breached in 2025. Bitwarden has never experienced a confirmed security breach. The searches around this topic are likely driven by the 2025 ETH Zurich cryptography audit or Bitwarden's own State of Password Security research report, neither of which represents a breach.

Was Bitwarden breached in 2024?

No. Bitwarden was not breached in 2024. Bitwarden completed multiple third-party security audits in 2024 conducted by Fracture Labs, Unit 42 by Palo Alto Networks, and IOActive. All identified issues were disclosed publicly and resolved. Completing audits is not the same as being breached.

Has Bitwarden ever been hacked?

No. Bitwarden has no confirmed breach history. This distinguishes it from LastPass, which suffered a major infrastructure compromise in 2022 that resulted in encrypted user vaults being stolen by attackers.

What is the ETH Zurich Bitwarden audit?

The ETH Zurich audit is a 2025 cryptography review conducted by the Applied Cryptography Group at ETH Zurich. It stress-tested Bitwarden's core cryptographic operations under a worst-case scenario: a fully compromised server. All issues found were addressed before the report was published. The full report is publicly available on Bitwarden's compliance page.

Is Bitwarden safe to use in 2026?

Yes. Bitwarden is one of the safest password managers available in 2026. It is open source with no breach history, undergoes annual third-party security audits by external firms, publishes all audit results publicly, and maintains SOC 2 Type 2 certification. The free tier includes unlimited passwords across unlimited devices.

How does Bitwarden compare to LastPass on security?

Bitwarden has no confirmed breach history. LastPass suffered major incidents in 2015, 2021, and 2022-2023, with the 2022 breach resulting in millions of encrypted vaults being stolen. Bitwarden is open source and publishes annual audit results. LastPass has not published a comparable independent security audit since the 2022 breach. For most users, Bitwarden is the safer choice.


Disclosure: Some links in this article are affiliate links. If you sign up through them, we may earn a commission at no extra cost to you. We only recommend products we actually trust.