Skip to content
Head to head

Bitwarden vs LastPass

Bitwarden wins on nearly every axis that matters. It is source-available with published third-party audits, defaults to 600,000 PBKDF2 iterations or Argon2id, and its free tier has no device-category restriction. LastPass free limits you to computers or mobile devices, not both, and carries the 2022 breach.

Facts reviewed 2026-08-01. Every row below is sourced, and anything a vendor does not publish is marked as such rather than estimated.

The question that decides it

Is there a reason to stay with LastPass beyond the cost of moving?

Choose Bitwarden if

you want audits, unlimited free devices, and a choice of key derivation.

Choose LastPass if

the browser-cached recovery paths matter to you more than the breach history.

Side by side

Comparison of Bitwarden and LastPass by security and account features
 BitwardenLastPass
Storage modelCloud-synced encrypted vaultCloud-synced encrypted vault
Key derivationKey derivation sets how expensive each attacker guess is. A vendor that does not publish its parameters cannot be independently compared on this.PBKDF2-HMAC-SHA256 at 600,000 iterations (default), or Argon2id at 32 MiB / 6 iterations / 4 lanesPBKDF2-HMAC-SHA256; 600,000 iterations is the current standard, but historic accounts carried much lower settings
Source codeSource available; clients are open source, some server components use the Bitwarden License rather than AGPLProprietary
Independent auditsNumerous published reports from Cure53, IOActive, ETH Zurich and Unit 42.Operates a trust centre and disclosure programme; no current full independent source-code audit report was found published.
Free tierYes — unlimited items and devicesYes
Main free-tier limitEmergency Access is premium-only, and free organisation sharing is capped at two usersRestricted to one device category — computers or mobile devices, not both
Account recoveryNo master-password reset for personal accounts unless Emergency Access was configured in advance. Enterprise admins can perform enrolled account recovery.Several paths depending on prior setup: a one-time recovery password cached in a previously used browser, mobile biometric recovery, and SMS recovery where configured.
PasskeysStores and uses website passkeys; passkey login to the Bitwarden account itself requires a PRF-capable browser.Stores website passkey private keys in the vault.
PlatformsAll major desktop and mobile OSes, browsers, a web vault and a CLI.Broad browser extension, mobile and desktop coverage.
Documented incidents“None found” means no authoritative report surfaced during research. It is not a claim that no incident has ever occurred.None found in published sourcesAugust 2022: attackers stole source code from a developer endpoint, then used that to reach cloud backups — exfiltrating backups of all customer vault data along with an MFA/federation database and its decryption key. Encrypted fields stayed encrypted, but attackers gained unlimited offline attempts against every stolen vault, and vaults on older low-iteration settings were meaningfully exposed.

How Bitwarden works

A cloud-synced vault encrypted locally, which can also be self-hosted. Bitwarden documents the design as end-to-end encrypted and zero-knowledge in a published security white paper.

Key derivation
PBKDF2-HMAC-SHA256 at 600,000 iterations (default), or Argon2id at 32 MiB / 6 iterations / 4 lanes
If you forget the master password
No recovery — No master-password reset for personal accounts unless Emergency Access was configured in advance. Enterprise admins can perform enrolled account recovery.

How LastPass works

A cloud-synced vault with client-side encryption of sensitive fields. Critically, in the backups stolen in 2022, some metadata — notably website URLs — was not encrypted.

Key derivation
PBKDF2-HMAC-SHA256; 600,000 iterations is the current standard, but historic accounts carried much lower settings
If you forget the master password
Recovery is possible — Several paths depending on prior setup: a one-time recovery password cached in a previously used browser, mobile biometric recovery, and SMS recovery where configured.
A third option

Both Bitwarden and LastPass store your passwords. MoolKey does not.

Bitwarden and LastPass differ in how well they protect a stored copy of your passwords. MoolKey answers a different question: it recalculates each password from your private phrase and the site name whenever you need it, so no copy exists to protect. A breach would expose masked account names and integers, not credentials.

That is a real trade, not a free win. There is no autofill, no import of your existing passwords, and no recovery if you forget your phrase — none, by design. your private phrase never reaches the service, so nobody can reset it or reproduce a password derived from it.

Bitwarden vs LastPass FAQ

What is the main difference between Bitwarden and LastPass?
Bitwarden uses cloud-synced encrypted vault, while LastPass uses cloud-synced encrypted vault. Bitwarden wins on nearly every axis that matters. It is source-available with published third-party audits, defaults to 600,000 PBKDF2 iterations or Argon2id, and its free tier has no device-category restriction. LastPass free limits you to computers or mobile devices, not both, and carries the 2022 breach.
Is Bitwarden or LastPass more secure?
Security here is mostly about verifiable design rather than marketing. Bitwarden uses pbkdf2-hmac-sha256 at 600,000 iterations (default), or argon2id at 32 mib / 6 iterations / 4 lanes. LastPass uses pbkdf2-hmac-sha256; 600,000 iterations is the current standard, but historic accounts carried much lower settings. Is there a reason to stay with LastPass beyond the cost of moving?
Can I recover my account if I forget the master password?
Bitwarden: No master-password reset for personal accounts unless Emergency Access was configured in advance. Enterprise admins can perform enrolled account recovery. LastPass: Several paths depending on prior setup: a one-time recovery password cached in a previously used browser, mobile biometric recovery, and SMS recovery where configured.
Does Bitwarden or LastPass have a free plan?
Bitwarden: Yes — unlimited items and devices, though emergency Access is premium-only, and free organisation sharing is capped at two users. LastPass: Yes, though restricted to one device category — computers or mobile devices, not both.
Has Bitwarden or LastPass ever been breached?
Bitwarden: no authoritative breach report was found during research, which is not the same as a guarantee that none has occurred. LastPass: August 2022: attackers stole source code from a developer endpoint, then used that to reach cloud backups — exfiltrating backups of all customer vault data along with an MFA/federation database and its decryption key. Encrypted fields stayed encrypted, but attackers gained unlimited offline attempts against every stolen vault, and vaults on older low-iteration settings were meaningfully exposed..

Sources

Every factual claim above traces to vendor documentation or published reporting. Where a vendor does not publish a figure, this page says so instead of repeating a number from a comparison table we cannot verify.

Make one account easier today.

Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.

Free forever Works offline Phone or computer