wallet: rpc: Deprecate `encryptwallet` RPC for encrypting existing wallets. #36387

pull davidgumberg wants to merge 8 commits into bitcoin:master from davidgumberg:2026-09-29-deprecate-encryptwallet changing 18 files +150 −73
  1. davidgumberg commented at 2:11 AM on September 30, 2026: contributor

    For more context, see: #36027

    Encrypting existing wallets that are unencrypted is fraught with footguns and complexity both for users and for developers.

    For example:

    • No efforts are made to ensure that remnants of unencrypted key material are not left on the user's disk, as attempting to ensure this would be difficult and dangerous, and for some SSD's infeasible.

    • Encrypting a wallet that has manually imported descriptors will cause the wallet to change the spending conditions out from under the user. (https://github.com/bitcoin/bitcoin/issues/26607)

    • Because new keys are made after encryption, restoring from a backup made before encryption may result in loss of funds.

    LLM Disclosure: Used gemma4-26B and qwen3.8-next-flash as research and drafting tools, but all code and text present here were written by me.

  2. refactor: test: Avoid encryptwallet in interface_bitcoin_cli.py
    This RPC will be deprecated in a future commit, so tests should avoid
    relying on it. This commit also adds scaffolding to init_wallet that
    will be used when refactoring other tests.
    645ea8b9b2
  3. refactor: test: rpc_psbt.py extract encrypted wallet signing
    This improves legibility of the test and avoids the use of
    `encryptwallet` which will be deprecated.
    2587fe96a8
  4. refactor: test: wallet_bumpfee.py isolate encrypted wallet tests f5f099eb58
  5. refactor: test: wallet_fundrawtransaction.py avoid encryptwallet
    A later commit will deprecate this RPC.
    0af48177dd
  6. refactor: test: wallet_listdescriptors.py extract encrypted wallet test 2c247497ff
  7. test: refactor: wallet_multiwallet.py use a new encrypted wallet d6aebe0ebc
  8. refactor: test: signrawtransaction isolate encrypted wallet test
    This is useful since a future commit will deprecate `encryptwallet`.
    df3ac8100e
  9. wallet: rpc: Deprecate `encryptwallet`
    Encrypting wallets from creation will still be supported, but there are
    footguns both for users and for developers in supporting wallets that
    are created unencrypted and then later become encrypted.
    
    The functional tests where the `deprecatedrpc` argument is added are
    ones where functionality or behavior of `encryptwallet` is being tested,
    they should be kept until the RPC command is removed.
    2cc0946985
  10. DrahtBot added the label Wallet on Sep 30, 2026
  11. DrahtBot commented at 2:11 AM on September 30, 2026: contributor

    <!--e57a25ab6845829454e8d69fc972939a-->

    The following sections might be updated with supplementary metadata relevant to reviewers and maintainers.

    <!--006a51241073e994b41acfe9ec718e94-->

    Code Coverage & Benchmarks

    For details see: https://corecheck.dev/bitcoin/bitcoin/pulls/36387.

    <!--021abf342d371248e50ceaed478a90ca-->

    Reviews

    See the guideline and AI policy for information on the review process.

    Type Reviewers
    Concept ACK pseudoramdom, w0xlt

    If your review is incorrectly listed, please copy-paste <code>&lt;!--meta-tag:bot-skip--&gt;</code> into the comment that the bot should ignore.

    <!--174a7506f384e20aa4161008e828411d-->

    Conflicts

    Reviewers, this pull request conflicts with the following ones:

    • #36257 <sub><img src="https://drahtbot.space/ack_count/bitcoin/bitcoin/36257.svg"></sub> (qa: assert_equals -> assert_true/assert_false by hodlinator)
    • #33954 <sub><img src="https://drahtbot.space/ack_count/bitcoin/bitcoin/33954.svg"></sub> (test: add functional test for outbound connection management by mzumsande)

    If you consider this pull request important, please also help to review the conflicting pull requests. Ideally, start with the one that should be merged first.

    <!--5faf32d7da4f0f540f40219e4f7537a3-->

  12. pseudoramdom commented at 5:00 AM on September 30, 2026: contributor

    Concept ACK, will review when I get a chance.

  13. w0xlt commented at 5:33 PM on September 30, 2026: contributor

    Concept ACK


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bitcoin. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-07 08:51 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me