
If you have been putting off switching password managers because you are afraid of losing a decade of logins, you are not alone. In my inbox alone, "how do I move my passwords without wrecking everything" is one of the most common questions I get from readers. The fear is rational: your password vault holds bank credentials, recovery codes, work SSO logins, and the answers to security questions you barely remember writing.
Here is a fact that surprised me when I dug into the numbers. According to breach-tracking service Have I Been Pwned, the average person now juggles credentials across 80 to 100 accounts, and password reuse still hovers above 60% among people who do not use a manager at all. Migrating to a better tool is one of the highest-leverage security moves you can make in an afternoon, and yet most people avoid it out of a vague dread of a botched export.
I have personally migrated between LastPass, Bitwarden, 1Password, and KeePassXC over the past six years, and I have made almost every mistake possible. This guide walks you through exactly how to switch password managers safely, with a real worked example, a comparison table of the major options, and a cleanup checklist that closes the security gaps most tutorials ignore.
Key Takeaways
- Always export from your old manager and verify the file before deleting anything.
- Treat the exported file as toxic waste: it is plaintext, so encrypt it, use it, then shred it.
- Migrate in a clean, offline environment and confirm a random sample of 10 to 15 logins after import.
- Rotate your most critical passwords (email, banking, financial) as part of the move, not after.
- Do not cancel or wipe the old account until you have lived on the new one for at least a week.
- Audit any browser extensions and helper apps you granted vault access to along the way.
Why Switching Password Managers Feels Risky (And What Actually Goes Wrong)
The dread is not irrational. Password migration touches three things at once: your most sensitive data, an export process that produces a plaintext file, and an import process that can silently mangle entries. When migrations go wrong, it is almost never because the data vanished. It is because of subtler failures.
Here are the real-world problems I have seen and experienced firsthand:
- Silent field mapping errors. The old manager stores a TOTP secret in a "notes" field, the new one ignores it, and your two-factor codes disappear.
- Duplicate explosions. You import twice after a "did that work?" moment and end up with 240 entries where you had 120.
- Orphaned plaintext exports. The unencrypted CSV sits in your Downloads folder for months, silently syncing to a cloud drive.
- Lost attachments and secure notes. Passport scans, license keys, and recovery codes stored as attachments frequently do not survive a CSV export.
- Broken TOTP / passkeys. Time-based codes and passkeys often need re-enrollment rather than a simple copy.
The good news: every one of these is preventable with a deliberate process. If you are the type who audits tools before adopting them, you will feel right at home; the same discipline described in our guide on how to vet open-source software before adding it to your stack applies to picking a password manager too.
Choosing the Right Password Manager Before You Migrate
Do not migrate to the first tool a review site recommends. Migrate to the one you will actually still be using in three years. The three questions that matter most:
- Where does the vault live? Cloud-synced (1Password, Bitwarden cloud) versus self-hosted or local-only (KeePassXC, Bitwarden self-hosted).
- What is the import quality? Some tools have first-class importers for specific competitors; others only accept generic CSV.
- Can you export freely later? If a tool makes leaving painful, that is a red flag. You want the freedom to migrate again.
A quick comparison of popular options
| Manager | Storage model | Import quality | TOTP support | Free tier | Best for |
|---|---|---|---|---|---|
| Bitwarden | Cloud or self-hosted | Excellent (50+ importers) | Yes (paid) | Generous | Value + control |
| 1Password | Cloud only | Very good | Yes | Trial only | Polish + families |
| KeePassXC | Local file | Good (CSV/XML) | Yes | Fully free | Offline purists |
| Proton Pass | Cloud (E2E) | Good | Yes | Decent | Privacy-first users |
| Dashlane | Cloud only | Moderate | Yes (paid) | Limited (25 items) | Simplicity seekers |
My honest bias: if you want maximum flexibility, Bitwarden's importer library is the most forgiving I have used, and KeePassXC is unbeatable if you refuse to trust a cloud with your vault. Whatever you pick, verify it has a real export function so a future migration is never held hostage.
A Worked Example: Migrating 47 Logins From LastPass to Bitwarden
Let me make this concrete. Say you have 47 passwords across 12 services, plus 3 secure notes and 4 TOTP codes, currently stored in LastPass. Here is exactly how I would move that vault, step by step.
Step 1: Inventory what you actually have
Open your old manager and count. In our example: 47 logins, 3 secure notes, 4 TOTP entries, 0 attachments. Write these numbers down. After import, you will confirm you have at least 47 + 3 = 50 items in the vault, with TOTP handled separately.
Step 2: Export from the old manager
In LastPass: Account Options → Advanced → Export → LastPass CSV File. You will be asked to re-authenticate. The result is an unencrypted .csv file. This file contains every password in plaintext. Treat it accordingly for the rest of this process.
Step 3: Secure the export file immediately
Move the CSV out of Downloads and into a folder you control. If you are on Windows and juggling files across drives or sandboxes, a tool like Windows Symlink Creator Pro can keep working directories tidy and off any auto-syncing cloud folder. Whatever you do, make sure this file is not sitting inside OneDrive, Dropbox, or Google Drive while it is plaintext.
Step 4: Import into the new manager
In Bitwarden's web vault: Tools → Import Data → Select LastPass (csv), choose the file, and import. Bitwarden's LastPass importer maps fields intelligently, so URLs, usernames, and notes usually land in the right place.
Step 5: Verify a random sample
Do not trust the count alone. Pick 10 to 15 entries at random and actually log in to those sites using the new vault. In our example, I would test the email account, the primary bank, two shopping sites, a work SSO login, and a couple of low-stakes accounts. If 12 out of 12 work, you have high confidence the batch imported cleanly.
Step 6: Rebuild TOTP and passkeys manually
Two-factor secrets rarely survive a CSV export intact. For each of the 4 TOTP entries, go into the account's security settings, disable the old authenticator, and re-enroll into the new manager (or a dedicated authenticator app). Passkeys almost always need re-creation on the new device.
Step 7: Rotate high-value passwords
Since you are already in each critical account for TOTP, change the passwords too. Migration is the perfect moment to retire any password you reused elsewhere.
Step 8: Securely destroy the export file
This is the step everyone skips. Do not just drag the CSV to the Recycle Bin. Use a secure-delete utility that overwrites the file, or a shredding feature from a reputable desktop utility. On Linux/macOS you can use shred -u file.csv or rm -P file.csv respectively.
How to Handle the Plaintext Export File Safely
The single most dangerous artifact in any migration is the exported file. It is your entire digital life in a spreadsheet. Follow these rules without exception:
- Never leave it in an auto-syncing folder. Cloud sync can push a plaintext copy to servers within seconds.
- Do the migration offline if possible. Disconnect from Wi-Fi during export and import to eliminate accidental uploads.
- Encrypt it if you must keep it briefly. Wrap the CSV in an encrypted archive (7-Zip with AES-256) if you need to move it between machines.
- Delete every copy. Check Downloads, Recent files, email drafts, and any USB drive you used.
- Empty caches. Some apps cache imported files in temp directories.
If you are moving files between a Mac and a Windows environment during this process, our walkthrough on running Windows apps on a Mac covers isolation setups that keep sensitive files off the host system entirely.
Post-Migration Security Cleanup Most Guides Skip
You imported successfully. You are not done. The migration created new attack surface, and a proper cleanup closes it.
Audit browser extensions and their permissions
Every password manager installs a browser extension, and old ones linger. Uninstall the extension for the manager you are leaving, and review the permissions on the new one. While you are in there, look for anything suspicious. Rogue extensions are a real threat, as we detail in our guide on detecting and
Cover image: Innovate Maryland Emerging Technology Center by MDGovpics, licensed under BY 2.0 via Openverse.








