The LastPass breach disclosed in late 2022, and the slow drip of additional context in the months that followed, made one thing clear. If you are still using LastPass, you should migrate. The breach exposed customer vault data, encrypted but with the salt and the encryption parameters available to attackers. Every account that had a weak master password is, three years later, still being slowly cracked offline.
This guide is the practical walkthrough for moving off LastPass. It covers exporting your data, choosing the destination, importing cleanly, dealing with the inevitable problems, and the steps you should take after the migration is technically complete to actually be safer than you were on LastPass.
Why migrate, in one paragraph
The 2022 LastPass breach exposed customer encrypted vaults to attackers. Encryption protects vaults whose master passwords are strong (long, random, not reused). Encryption does not protect vaults whose master passwords are weak (short, dictionary words, or reused from other breached services). Three years later, attackers are still working through the breached data and successfully cracking vaults with weak master passwords. The risk is ongoing for anyone still using a vault that was in the breach. Beyond the technical reasons, LastPass leadership’s communication during and after the incident was poor enough to break trust independently of the technical issue.
Step 1, choose your destination
Three reasonable choices for most users. Pick one before exporting from LastPass.
Bitwarden Premium ($10 per year). Open source, audited, fine apps across all platforms, broad ecosystem. The default recommendation if you want a hosted password manager with low friction and low ongoing cost.
1Password Individual ($35.88 per year). Closed source, but extremely well-engineered, with the strongest UX in the industry and the Secret Key model that mitigates the master-password-cracking risk. The right pick for users who want polish and family-friendly features.
Self-hosted Vaultwarden (free, you provide the server). Same as Bitwarden but you control the infrastructure. Right for users who specifically want server-side control. We have a separate guide for setup.
Skip LastPass alternatives that are not on this list for now. The other major players (Dashlane, NordPass, Keeper, RoboForm) are fine products but do not offer enough advantage over Bitwarden or 1Password to justify the migration cost.
For this guide I will assume you are migrating to Bitwarden, since that is the most common choice. The 1Password and Vaultwarden flows are similar enough that you can adapt.
Step 2, generate a strong master password for the new account
Before you do anything else, set up a master password for your new password manager that is genuinely strong. This is the single most important security decision in the whole migration.
A strong master password is:
- Long (16 characters minimum, 24 better)
- Not reused from any other service
- Not a common phrase or dictionary words
- Memorable enough that you will not need to write it down (or memorable enough to be safely written down on paper kept somewhere physically secure)
A common pattern that works well: pick four random words from a large word list, such as those generated by the EFF Diceware list. The result looks like “correct-horse-battery-staple-omega” and provides about 60 to 80 bits of entropy depending on word count. This is sufficient.
Critically, do not just generate a long random string and try to memorize it. Humans are bad at memorizing random strings and you will eventually write it down somewhere insecure. Phrase-based passwords are easier to memorize while still being strong.
Do not use the same master password as your old LastPass master password. The threat model includes “your LastPass master password was leaked or guessed.”
Step 3, export from LastPass
Log in to LastPass via the web vault (not the browser extension; the export feature has been more reliable from the web vault).
Navigate to: Account, Advanced Settings, Export.
You will be prompted for your master password and asked to confirm. The export downloads as a CSV file.
Critical security note: the exported CSV is plaintext. Every password is readable. Do not email it. Do not upload it to cloud storage. Do not save it to a shared folder. Keep it on your local machine and delete it as soon as the import is complete.
If you have very large vaults (over 1000 entries), the LastPass export occasionally truncates or fails. If you see fewer entries in the CSV than you expect, try again, or use the LastPass mobile app’s export feature as a fallback.
Step 4, sign up for Bitwarden and import
Go to vault.bitwarden.com. Create an account using a real email address (not a temporary email; you will need it for verification and recovery).
When setting up: use the strong master password you generated in Step 2. Bitwarden will check the password against breached databases and warn you if it has been seen; this is a good sanity check.
Enable 2FA immediately. Settings, Security, Two-step Login. TOTP via an authenticator app (Authy, Aegis, 2FAS) is fine. WebAuthn with a YubiKey is better. Do not skip this step.
Import the LastPass CSV: Tools, Import data. Select “LastPass (csv)” as the source format. Upload the file. Bitwarden will preview the import. Confirm.
Review the imported entries. Bitwarden generally imports cleanly from LastPass but watch for:
- Folders / collections that did not transfer correctly
- Custom fields on specific entries that may have lost data
- Notes that contained unusual formatting
Spot-check 10 to 20 entries to confirm passwords, URLs, and notes look right.
Step 5, install Bitwarden everywhere
You need the Bitwarden client on every device where you currently use LastPass.
Browser extensions: Bitwarden has extensions for Firefox, Chrome, Safari, Edge, Brave. Install in each browser you use.
Desktop apps: Bitwarden desktop app is available for Windows, macOS, Linux. The desktop app is optional if you primarily use the browser extension; install it if you want quick keyboard access (Cmd+Shift+L on Mac).
Mobile apps: Bitwarden iOS and Android. Install on every phone or tablet.
Sign in to each with your new master password and 2FA. The vault will sync automatically across devices.
CRITICAL: do not uninstall LastPass yet. Run both side-by-side for at least two weeks. You will discover entries that did not import cleanly only when you try to use them.
Step 6, change critical passwords
The migration is when you should also rotate the passwords that matter most. The reason: if your LastPass vault was in the breach and your old master password was weak, attackers may already have your existing passwords. The migration to Bitwarden does not protect those passwords; you have to change them at the source.
Priority order for password changes:
- Email accounts (the master account that resets everything else): Gmail, ProtonMail, etc.
- Banking: any account that holds money
- Financial: brokerages, payment services (PayPal, Venmo)
- Identity: government accounts, IRS, healthcare portals
- Cloud storage: anything that holds personal data
- Social media: anything that could be used for impersonation
- Subscription services with stored payment methods
For each: log in with the existing password (from your new Bitwarden vault), change to a new strong password generated by Bitwarden, save the new password.
For the lower-stakes accounts (one-off forum signups, defunct services), do not bother. Spend your time on the accounts where compromise actually matters.
This step takes hours. Do not skip it. The whole point of moving away from LastPass is to be safer; if you keep the same passwords, you have not become safer.
Step 7, enable 2FA on accounts that support it
While you are rotating passwords, also enable 2FA on every account that supports it. Most major services do.
Use Bitwarden’s TOTP authenticator (Premium feature) for convenience, or a separate authenticator app (Aegis on Android, Raivo on iOS, 2FAS) if you prefer to keep TOTP separate from your password manager.
For your most critical accounts (email, primary cloud), use a hardware security key (YubiKey, Nitrokey) instead of TOTP. The cost is around $55 per key plus an hour of setup; the security benefit is significant.
Step 8, the safety net
Before you delete LastPass, set up the safety net.
Bitwarden export: from your new Bitwarden, export the entire vault (Tools, Export Vault). Save the export in a secure location. The encrypted format (.json) is safer than the plaintext CSV. Test that the export can be re-imported into a fresh Bitwarden account in case you need disaster recovery.
Hardware backup: print your master password (or write it down) and store it in a physically secure location. Bank safe deposit box, fireproof safe at home, or with a trusted family member.
Recovery codes: any 2FA setup gives you recovery codes. Print and store these too.
Account recovery: Bitwarden does not have a master password recovery process by design. If you forget your master password, the data is gone. The hardware backup is your only recovery path; treat it accordingly.
Step 9, delete LastPass
After two weeks of running both side-by-side and confirming that everything imported correctly, delete your LastPass account.
LastPass account deletion: log in to the web vault, Account, Delete Account. Confirm via email. The deletion is permanent and immediate.
Uninstall the LastPass browser extensions and apps. Clear any saved passwords from the LastPass apps before uninstalling.
The old LastPass account is now gone. Your data has migrated. The old vault on LastPass servers is, in principle, deleted (LastPass’s data retention policy says they delete deleted-account data within 30 days; whether this actually happens is hard to verify).
Step 10, the long-term hygiene
Some habits to maintain after migration:
Do not let the new vault grow weak passwords. Every time you log in to a service, check that the password is strong. Bitwarden’s Security Reports feature surfaces weak, reused, and breached passwords; review it monthly.
Keep your master password strong. Resist the urge to simplify it for convenience. The password you cursed at while typing it correctly the first time is the password that is doing its job.
Update Bitwarden when prompted. Both the apps and the browser extensions. Security patches matter.
Re-test backup quarterly. Confirm that your exported vault can still be re-imported into a fresh account. Test on a real second device, not just in your head.
Re-evaluate every two years. Password manager landscape shifts. Bitwarden today is the right answer; in three years, it might not be. The migration discipline you built doing this LastPass exit will serve you again.
What this migration does not solve
Moving to a more secure password manager does not undo the past. If your LastPass vault was breached and contained passwords that have already been used by attackers (rare but possible), the damage from those uses cannot be reversed. The hope is that the migration plus password rotation prevents future damage.
The migration does not protect against future breaches at the new provider. Bitwarden could, in principle, be breached. The mitigation is the strong master password (which makes offline cracking infeasible) and 2FA (which prevents online account takeover even if the vault is compromised).
The migration does not eliminate the inherent risk of using a hosted password manager. If your threat model requires zero hosted-service risk, self-hosted Vaultwarden is the right answer. We cover that setup separately.
Time and money cost
Total time investment for a typical user with 100 to 300 passwords: 6 to 12 hours, spread over a few weeks.
Direct money cost: $10 per year for Bitwarden Premium, plus optionally $55 to $110 for hardware security keys.
The cost is real. It is also lower than the cost of having an account compromised because you delayed the migration.
Bitwarden | 1Password | Vaultwarden setup guide
Related: 1Password versus Bitwarden in 2026, Bitwarden setup walkthrough on a five dollar VPS, How to evaluate any privacy tool