Microsoft Locks Out WireGuard and VeraCrypt Developers — Windows Security Updates Blocked
Microsoft suspended developer accounts for WireGuard's Jason Donenfeld and VeraCrypt's Mounir Idrassi, halting Windows updates and leaving millions of encrypted systems facing a certification expiry in July 2026. Microsoft VP Scott Hanselman responded on April 9 that fixes are in progress.
Microsoft suspended developer accounts for Jason Donenfeld (WireGuard) and Mounir Idrassi (VeraCrypt) on April 8, blocking Windows software updates and leaving one of the most widely used full-disk encryption tools facing a certification cliff in July.
Donenfeld had been preparing WireGuard’s first major Windows update in nearly four years. The lockout stopped it entirely. Idrassi’s situation is more severe: VeraCrypt uses a Windows driver-signing certificate tied to his suspended account. That certificate expires in July 2026. If access isn’t restored in time, Microsoft will revoke the signature — and users with system drives encrypted by VeraCrypt could face boot failures after a Windows update. No automatic recovery path exists.
Windscribe VPN was also locked out under the same enforcement action.
All three trace back to Microsoft’s mandatory developer account verification program. Microsoft VP Scott Hanselman addressed it publicly on April 9: “We’ve been emailing developers since October 2025, and the fixes are happening as we speak.” He confirmed the accounts are under review.
The developer community’s response was not sympathetic to that explanation. WireGuard is embedded in Windows itself. VeraCrypt is used by journalists, lawyers, and security professionals to protect sensitive data against physical device seizure. These are not hobby projects. Treating them the same as abandoned apps in a generic compliance sweep is where the process broke down.
Microsoft controls the signing chain for every piece of software that runs on Windows. That authority comes with a responsibility to maintain escalation paths for security-critical infrastructure. Automated emails, sent once to open source maintainers without dedicated ops teams monitoring compliance dashboards, is not a sufficient safeguard.
The specific stakes: VeraCrypt has documented that users who encrypted their system drive with the tool will encounter boot errors once the certificate is revoked. The window to fix this before real user harm is roughly three months.
The VeraCrypt scenario deserves direct attention. System-drive encryption is not reversible on short notice. Administrators who deployed VeraCrypt across an organization cannot roll it back in a week. If certificate revocation proceeds in July before Idrassi’s account is restored, the damage isn’t theoretical — it’s machines that won’t boot.
WireGuard’s blocked update is a smaller emergency but a sharper embarrassment. Microsoft ships WireGuard as part of its own VPN infrastructure while simultaneously locking out the developer who maintains the Windows implementation. That contradiction speaks to how siloed the certification enforcement process is from the product teams that depend on its results.
Hanselman’s statement suggests remediation is underway. Whether it includes a formal grace period for security-critical open source projects — or just case-by-case account restoration — remains unclear.
Developers using Microsoft partner portals to ship signed Windows software should audit their account verification status immediately. Do not assume the emails arrived or were acted on.
Related reading
- Cybersecurity APT28 Is Actively Exploiting CVE-2026-32202 — A Zero-Click Windows Shell Flaw That Steals NTLM Hashes
- Developer Tools OpenCode Crosses 160K GitHub Stars — The Open-Source AI Coding Agent That Beat Claude Code on Adoption
- Developer Tools Supabase Raises $500M at $10.5B Valuation as Claude Code Becomes Its Biggest Database Creator