For more context, see: #36027
Encrypting existing wallets that are unencrypted is fraught with footguns and complexity both for users and for developers.
For example:
No efforts are made to ensure that remnants of unencrypted key material are not left on the user's disk, as attempting to ensure this would be difficult and dangerous, and for some SSD's infeasible.
Encrypting a wallet that has manually imported descriptors will cause the wallet to change the spending conditions out from under the user. (https://github.com/bitcoin/bitcoin/issues/26607)
Because new keys are made after encryption, restoring from a backup made before encryption may result in loss of funds.
LLM Disclosure: Used gemma4-26B and qwen3.8-next-flash as research and drafting tools, but all code and text present here were written by me.