Does this mean they got access to unencrypted vaults? I have had a few beers and cannot comprehend from the article or lastpass's statement.
To get unencrypted vaults, they'd need to change the client-side code. But we haven't been told that this happened.
(As a best practice, it's probably best to assume everything in LastPass vault was compromised at this point.)