Get all your news in one place.
100's of premium titles.
One app.
Start reading
Windows Central
Windows Central
Technology
Kevin Okemwa

"I have proof for every single word": This security researcher's GitHub and Microsoft accounts were deleted after claiming a Windows 11 exploit in BitLocker is by design

Windows 11 displaying BitLocker settings on a laptop in front of a BitLocker Drive Encryption page from Microsoft.

Earlier this month, security sleuth and researcher "Chaotic Eclipse" (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLocker-protected drives on Windows 11 with a simple USB key. "Just can't come up with an explanation besides the fact that this was intentional. Also, for whatever reason, only Windows 11 (+Server 2022/2025) is affected; Windows 10 is not," they explained.

Last week, Microsoft publicly acknowledged awareness of the security feature bypass vulnerability in Windows. It further disclosed that it is tracking the YellowKey zero-day exploit under CVE-2026-45585 and shared mitigation measures to prevent it from gaining unauthorized access to protected drives. "The proof of concept for this vulnerability has been made public, violating coordinated vulnerability best practices," the company added.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.