Gateholm

Moving on from LastPass

After LastPass disclosed in 2022 that attackers had copied customer vault backups, an enormous number of people re-evaluated where their most sensitive file on earth lives. If you’re one of them: this is the calm, boring, end-to-end encrypted place to land.

The situation, plainly

The 2022 incident put stolen encrypted vaults in attackers’ hands, where weak master passwords could be ground down offline — LastPass’s own notices urged users to rotate credentials. Whatever you think of how it was handled, the takeaway is architectural: your vault should be end-to-end encrypted with a strong master password, on infrastructure whose operator you actually trust. Vaultwarden is the open-source, Bitwarden-compatible server with exactly that design — we run it, patched and backed up, and we mathematically cannot read your vault.

What you get instead

  • End-to-end encrypted: the vault is encrypted on your device — we store only ciphertext
  • The official Bitwarden apps and browser extensions on every platform
  • LastPass CSV import: your logins, notes, and cards come across in minutes
  • TOTP codes, secure notes, attachments, and family sharing
  • A genuinely free vault tier — unlimited items and autofill

The honest tradeoffs

  • E2EE cuts both ways: if you lose your master password, nobody — including us — can recover the vault. Write the recovery info down somewhere real.
  • We’re a small operation and say so. What you get is a hardened, single-purpose instance and a straight answer to every security question — including this page.

Making the move

  1. Export from LastPass. Account settings → Advanced → Export gives you a CSV.
  2. Import in the web vault. Tools → Import, pick the LastPass format, upload. Delete the CSV afterwards — it’s plaintext.
  3. Install the apps. Official Bitwarden extension and mobile apps, pointed at your Gateholm server. Autofill everywhere.

Full import guide →

Questions people ask

Why Vaultwarden instead of Bitwarden’s own hosting?
Bitwarden’s hosted service is good, and if you’d rather have a large company, choose it honestly. Ours is for people who prefer a smaller operator, EU hosting, and the self-hosted architecture — with the same clients and the same E2EE math.
Could what happened to LastPass happen here?
Any service can be attacked; the design determines what an attacker gets. Vaults here are end-to-end encrypted client-side — a copy of our storage yields ciphertext locked to your master password. Pick a long passphrase and that ciphertext is, practically speaking, noise. We publish what we can and cannot see in plain language in our privacy policy.

Ready when you are

Cancel anytime, 14-day full refund, and your data exports whenever you like — the exit door stays open on purpose.

LastPass is a trademark of its owner; the 2022 incident summary reflects LastPass’s own public notices. Vaultwarden is an independent open-source project; Bitwarden is a trademark of Bitwarden, Inc. Gateholm is not affiliated with any of them.