WireGuard VPN Developer Unable to Release Updates After Microsoft Lock

WireGuard Microsoft developer lockout VeraCrypt Windows Hardware Program VPN security updates Jason Donenfeld open source security
D
Daniel Richter

Open-Source Security & Linux Privacy Specialist

 
April 17, 2026
2 min read
WireGuard VPN Developer Unable to Release Updates After Microsoft Lock

TL;DR

This article covers the recent suspension of developer accounts belonging to the creators of WireGuard and VeraCrypt, which prevents them from signing Windows drivers. It explores how Microsoft’s new mandatory identity verification process has created a bottleneck for open-source security tools. You will learn about the potential risks to encryption and VPN users if emergency patches cannot be deployed.

Jason Donenfeld, the creator of the open-source WireGuard VPN software, has been locked out of his Microsoft developer account. This restriction prevents him from signing drivers or shipping critical updates for WireGuard on Windows. As an open-source project that serves as the foundation for services like Proton and Tailscale, a lockout of this nature halts the distribution of modernized code and security patches. Donenfeld noted that while there is currently no critical vulnerability, users would be "totally exposed" if a fix were needed immediately.

an illustration of an underground tunnel gong bending around a corner to the left using mostly green, yellow and black, with the light of the tunnel exit in the near distance

Image courtesy of TechCrunch

Windows Hardware Program Restrictions

The issue stems from the Windows Hardware Program, which requires developers to verify their identity to deploy device drivers. These drivers are highly sensitive because they grant deep access to the operating system, a level of privilege often abused by hackers in ransomware attacks. Microsoft implemented a mandatory account verification process starting in April 2024, requiring government-issued IDs. Although Donenfeld completed the verification through a third-party service, his account remains suspended. At squirrelvpn.com, we monitor these ecosystem shifts closely to ensure our users stay informed about the latest VPN updates and platform risks.

Impact on Encryption and Privacy Tools

WireGuard is not the only project affected. Mounir Idrassi, the developer of the popular encryption software VeraCrypt, reported a similar abrupt lockout. VeraCrypt is used by hundreds of thousands of people to encrypt files and operating systems. The inability to update the software before a certificate authority expiry could prevent some users from booting their machines. Additionally, Windscribe stated they have been locked out of their Partner Center account for over a month, despite having a verified account for eight years. These incidents highlight the fragility of relying on centralized platforms for distributing open-source security auditing tools and privacy software.

Support Bottlenecks and Review Delays

Developers facing these lockouts have reported significant difficulties reaching Microsoft support. Donenfeld was referred to an executive support team but was told a review could take up to 60 days. Windscribe described their support experience as "non-existent." While Donenfeld recently established contact with Microsoft to resolve the issue, the "access restricted" errors continue to block the release of modernized Windows code. Staying updated on cybersecurity trends is essential for power users who manage their own self-hosted privacy infrastructure or rely on hardened Linux configurations.

Explore the latest in VPN technology and enhance your online security with insights from squirrelvpn.com.

D
Daniel Richter

Open-Source Security & Linux Privacy Specialist

 

Daniel Richter is an open-source software advocate and Linux security specialist who has contributed to several privacy-focused projects including Tor, Tails, and various open-source VPN clients. With over 15 years of experience in systems administration and a deep commitment to software freedom, Daniel brings a community-driven perspective to cybersecurity writing. He maintains a personal blog on hardening Linux systems and has mentored dozens of contributors to privacy-focused open-source projects.

Related News

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns
SonicWall SMA1000 zero-day

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities Triggers Deployment of Custom Malware Campaigns

SonicWall SMA1000 appliances face active exploitation by UTA0533. CVE-2026-15409 and CVE-2026-15410 allow root access. Patch your systems immediately.

By James Okoro July 21, 2026 4 min read
common.read_full_article
Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security
WireGuard VPN protocol

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security

Private Internet Access integrates WireGuard protocol across its suite for faster, more secure remote access. Learn how this update improves your VPN connection.

By Marcus Chen July 20, 2026 4 min read
common.read_full_article
Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks
CVE-2023-4966

Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks

Discover how the Citrix Bleed (CVE-2023-4966) vulnerability allows session hijacking. Learn how to patch your NetScaler Gateway against authentication bypass.

By Elena Voss July 19, 2026 4 min read
common.read_full_article
Hackers Exploiting CitrixBleed 2 to Hijack Session Tokens and Bypass Enterprise MFA Protections
CitrixBleed 2

Hackers Exploiting CitrixBleed 2 to Hijack Session Tokens and Bypass Enterprise MFA Protections

Hackers are exploiting CitrixBleed 2 (CVE-2025-5777) to hijack session tokens and bypass MFA. Patch your NetScaler instances immediately to prevent breach.

By James Okoro July 18, 2026 3 min read
common.read_full_article