If you're like "well don't worry about lastpass, it's encrypted client-side"... look up what the government wanted to coerce Lavabit to do.
You should assume that the attackers did something similar.
(This is a reason I don't trust these kinds of web applications where you just get some program handed to you as a blob, if it's also supposed to do encryption...)