But isn't it encrypted with a secret that is also used to log into their web site, or to log into their API to recover the vault?
From their statements so far, it doesn't seem that happened, but it seems likely that it could.
If that was the case I'm sure Lastpass would've found out and reported as such.