Microsoft Blocking Open Source VPN Developer Accounts and Software Updates
- Microsoft has suspended the developer accounts of two high-profile open-source projects, preventing the creators of WireGuard and VeraCrypt from shipping critical software updates to Windows users.
- Jason Donenfeld, the creator of the open-source VPN software WireGuard, reported that he was locked out of his Microsoft developer account without prior notification.
- The inability to ship updates poses a potential security risk for the millions of users who rely on WireGuard.
Microsoft has suspended the developer accounts of two high-profile open-source projects, preventing the creators of WireGuard and VeraCrypt from shipping critical software updates to Windows users. The abrupt account terminations have blocked the developers from signing the drivers necessary for their software to operate at the kernel level on Windows 10, and 11.
Jason Donenfeld, the creator of the open-source VPN software WireGuard, reported that he was locked out of his Microsoft developer account without prior notification. This lockout stopped a WireGuard update from shipping on April 8, 2026. Because the Windows Hardware Program requires developers to verify their identities and sign drivers, the account suspension prevents Donenfeld from certifying new kernel drivers.
Impact on Cybersecurity and User Safety
The inability to ship updates poses a potential security risk for the millions of users who rely on WireGuard. While Donenfeld stated there is currently no critical vulnerability to fix, he noted the hypothetical danger if one were to emerge.

If there were a critical vulnerability to fix right now — there isn’t! I just mean hypothetically — then users would be totally exposed.
Jason Donenfeld via TechCrunch
WireGuard serves as the foundational code for numerous commercial security services, including Tailscale and Proton, as well as the Mullvad VPN. The project is widely recognized for its simplicity and security, making the disruption of its update pipeline a significant concern for the broader cybersecurity ecosystem.
Parallel Issues for VeraCrypt
The situation is not isolated to WireGuard. Mounir Idrassi, the developer of the open-source disk encryption software VeraCrypt, reported that Microsoft terminated the account he had used for years to sign the bootloader and Windows drivers. VeraCrypt is used by hundreds of thousands of people to encrypt operating systems and files.
Idrassi stated that the lockout prevents him from updating the software in time for a crucial certificate authority expiry. This specific technical failure may prevent some users from being able to boot their systems.
Unlike other platforms, the impact on Windows is particularly severe because the operating system flags unsigned drivers and blocks them from loading at the kernel level. Idrassi noted that while updates for macOS and Linux can still be performed, the inability to deliver Windows releases is a major blow since Windows is the platform used by the majority of the project’s users.
Developer Challenges and Resolution Efforts
Donenfeld encountered the account deactivation approximately two weeks prior to April 8, 2026, while attempting to certify a new kernel driver. He discovered that the Microsoft partner portal listed his account as deactivated without providing a specific reason.
The developers have faced difficulties in resolving the issue through official channels. Donenfeld mentioned that he found a Microsoft appeals process, but learned the response time for such appeals is 60 days. His company, Edge Security, also used social media to urge Microsoft to resolve the problem.
Following the public complaints, Donenfeld later indicated that he is in communication with Microsoft and that they are in the process of sorting out the issue.
This incident underscores the systemic risks open-source developers face when relying on proprietary third-party platforms for critical infrastructure, such as driver signing and software distribution, where abrupt account suspensions can leave a wide user base vulnerable.
