Microsoft Locks Out VeraCrypt, WireGuard Devs, Halting Windows Updates

Microsoft has terminated VeraCrypt and WireGuard developer accounts, blocking Windows driver updates and risking boot failures for encrypted systems.

TL;DR
  • Account Lockout: Microsoft terminated the developer accounts used by VeraCrypt and WireGuard to sign Windows drivers, blocking both projects from shipping updates.
  • Boot Risk: VeraCrypt’s Windows signatures expire after July 2026, potentially causing boot failures for nearly a million users with encrypted systems.
  • Partial Resolution: Microsoft restored WireGuard’s account after public backlash, but VeraCrypt’s account remains locked with no confirmed timeline for restoration.
  • Wider Fallout: Other affected projects include LibreOffice, MemTest86, and Windscribe, all caught by Microsoft’s automated verification sweep.

Nearly a million Windows users running VeraCrypt disk encryption face potential boot failures after July 2026, following Microsoft’s decision to terminate the developer account used to sign the software’s drivers and bootloader. WireGuard, the widely used VPN protocol underpinning services like Mullvad and Proton VPN, was hit by the same lockout. Neither developer received advance warning or any explanation from Microsoft.

Account blocks of Mounir Idrassi, who maintains VeraCrypt, prevents him from publishing Windows updates for the open-source encryption tool, whose latest installer recorded almost a million downloads since its May 2025 release. Microsoft’s driver-signing infrastructure requires accounts to pass verification to cryptographically sign kernel-level drivers for Windows 10 and 11; without that signature, new builds cannot install drivers or bootloaders on Windows, making future full-disk encryption releases impossible. Linux and macOS updates remain unaffected, but Windows represents the vast majority of VeraCrypt’s user base.

WireGuard faces the same barrier. Its driver updates cannot ship through normal channels, potentially disrupting VPN connectivity for millions of users whose services, including Mullvad, Proton VPN, and Tailscale, depend on WireGuard’s protocol at the network layer.

Broader Impact and the WireGuard Parallel

Idrassi disclosed the termination in a SourceForge post after he attempted to sign Windows drivers in January 2026. Microsoft sent no emails, no advance notifications, and no explanation for why an account used for years to maintain critical security software had been shut down. For nearly three months, Idrassi tried to resolve the issue through Microsoft’s support channels before going public in late March 2026.

Microsoft’s automated response stated his company did not meet verification requirements, with no specifics and no avenue for appeal according to Idrassi. Repeated attempts to reach human support produced only automated replies, leaving him without a path to resolution. Beyond VeraCrypt, the lockout hit his IDRIX company account, affecting driver signing for his commercial clients and blocking his ability to sign drivers for entirely separate projects.

WireGuard creator Jason Donenfeld reported the same developer account suspension in late March 2026. He had been rebuilding the project’s driver infrastructure to pass the Windows Hardware Lab Kit test suite when he discovered his account was suspended. Compounding the damage, the lockout halted a modernization effort that would have improved WireGuard’s Windows integration and rendered an expensive extended validation code-signing certificate he had recently purchased entirely useless.

Donenfeld told TechCrunch that “Microsoft never sent me any notification at all about this. I’ve looked in every inbox in every spam folder in every mail log, and zero, nothing, zilch.” He faced a catch-22 in the appeal process: filing an appeal required an active account, but the account was already terminated. After reaching Microsoft through personal connections, he learned the standard appeal timeline was 60 days, regardless of the project’s profile or user base.

Both developers’ accounts being locked simultaneously compounds the security risk. WireGuard’s code serves as the foundation of numerous commercial VPN implementations, meaning the lockout’s reach extends well beyond the open-source project itself. If a severe vulnerability were discovered in WireGuard for Windows, Donenfeld would have no way to push a patched driver to users through normal channels, a scenario he called “kind of crazy.” Identical risk applies to VeraCrypt, where any security fix requiring a new signed driver or bootloader cannot reach Windows users until account access is restored.

Microsoft Responds, WireGuard Restored

A Microsoft spokesperson initially declined to comment on the account terminations. Public backlash then prompted a response from Pavan Davuluri, Microsoft’s President of Windows and Devices, who posted on X that accounts would be restored:

“We’ve seen these reports and are actively working to resolve this as quickly as possible. We’ve reached out to VeraCrypt and have spoken to Jason at WireGuard, they should be back up and running soon.”

Pavan Davuluri, Microsoft President of Windows and Devices (via X)

Donenfeld’s WireGuard account was reinstated as of April 9, resolving one half of the lockout within a day of Davuluri’s public statement. Idrassi’s account remains unresolved, and Davuluri’s statement did not provide a specific timeline for VeraCrypt’s restoration. Scott Hanselman, a Microsoft developer advocate, also emailed Idrassi directly to help restore the account.

Microsoft attributed the deactivations to account verification requirements announced in October 2025 requiring re-verification for accounts not updated since April 2024. Behind the crackdown lies a specific incident: in 2022, hackers exploited the hardware developer program to get malware signed by Microsoft, giving malicious drivers a veneer of legitimacy that allowed them to bypass security tools. Tightening verification requirements was a reasonable response to that breach, but the execution caught legitimate open-source maintainers in the same net. Other affected projects include LibreOffice, MemTest86, and Windscribe, indicating the verification sweep has hit multiple established projects whose software runs on millions of machines.

Rather than individually vetting high-profile open-source maintainers whose projects serve millions of users, the automated process treated VeraCrypt and WireGuard identically to abandoned or fraudulent accounts, then offered no meaningful escalation path when developers tried to object. Only after the story reached the press and social media did senior Microsoft figures intervene personally.

Boot Failures Loom for Encrypted Windows Systems

For VeraCrypt users, the pressing concern is a hard deadline. Windows systems with Secure Boot enabled may refuse to load drivers or trigger boot failures once existing signatures expire. Expiration is set for late June 2026, with Microsoft revoking the certificate authority used for the VeraCrypt bootloader after July 2026. Signing a replacement bootloader under the new certificate authority requires the very developer account that remains terminated, creating a circular dependency with a ticking clock.

Users who have enabled VeraCrypt system encryption on their primary drives face the greatest risk: a boot failure on an encrypted system could leave data inaccessible without recovery procedures. Idrassi has urged affected users to prepare by creating VeraCrypt rescue disks and backing up their encryption headers while current installations remain functional.

Idrassi told TechCrunch that if the issue is not resolved in time, it would amount to a “death sentence for VeraCrypt.” He added that “for affected users, there is nothing special to do for now as VeraCrypt will continue to work, and there are no security issues identified currently.” Existing software installations remain safe to use, but no new Windows releases can be signed or distributed until Microsoft restores the account.

Whether Idrassi’s account is restored in time to meet the July 2026 deadline, the incident clearly demonstrates how fragile the distribution chain remains for security software that operates at the kernel level on Windows. Projects like VeraCrypt and WireGuard protect millions of systems, yet their ability to ship updates depends entirely on a single company’s developer program and its automated verification processes. Any open-source project that requires kernel-level access on Windows faces the same single point of failure. For users who chose VeraCrypt specifically because they distrust Microsoft’s own BitLocker encryption, which the company has previously handed BitLocker encryption keys to the FBI, the dependence on Microsoft for distribution adds a notable tension to an already precarious situation.

Markus Kasanmascheff
Markus Kasanmascheff
Markus has been covering the tech industry for more than 15 years. He is holding a Master´s degree in International Economics and is the founder and managing editor of Winbuzzer.com.
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted