> Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error.
A lot of corporate text in this blog. This seems to be the only sentence where they say that the unusual login activity was actually a software error.
(PS: I editorialised the title since the actual title is very generic says nothing)