In this guide
Identification
Encrypted drives and containers after a death
How to recognise encrypted storage (VeraCrypt, TrueCrypt, BitLocker, LUKS, encrypted archives and backups) after a death, and what to preserve without damaging anything.
Families clearing a home or estate sometimes find storage that cannot be opened: an encrypted USB drive, a container file, a disk that asks for a recovery key, or a password-protected archive. The encryption is not a problem by itself, it is evidence that the owner deliberately protected something. What matters for an estate is the same as for every other find: recognise it, preserve it, and never try to force it open.
What encrypted storage is
Encrypted storage protects its contents with a password, passphrase or recovery key. After a death, the important point is that the encryption is a layer around whatever is inside, often the wallet files, backups and documents that the estate needs. The medium itself is usually not the wallet; the wallet (or its backup) is what the encryption protects.
The types you are most likely to find
| What it looks like | What it usually is | Your first step |
|---|---|---|
A single file (often with a .hc extension) that opens as a drive when mounted | VeraCrypt or TrueCrypt container | Preserve the file and any written password; note the software name and version |
| A hard drive, USB stick or partition that asks for a password when connected | VeraCrypt/TrueCrypt or LUKS encrypted volume | Preserve the medium; keep the written password with the estate file, separately |
| A Windows computer or drive that asks for a BitLocker recovery key | BitLocker-encrypted disk | Preserve the device and any printed or saved recovery key (often a .bev file or a paper printout) |
A password-protected archive (.7z, .zip, .rar) | Encrypted archive, often holding documents or backups | Preserve the archive and any written password; do not upload it anywhere |
| A backup file that asks for a password when opened | Encrypted backup, possibly from wallet or phone software | Preserve the file, the software name and the password separately |
A password-vault database (for example KeePass .kdbx) | Encrypted password manager | Access follows the same authority rules as the accounts themselves; see wallet passwords and passphrases |
The exact file name and extension vary; do not identify by extension alone. The software installed on the same computer, the written notes nearby and any printed recovery key are the most reliable clues.
How it differs from a wallet file
- An encrypted keystore or wallet file (for example a
UTC--keystore or awallet.dat) is the wallet’s own key material, those have their own pages: Ethereum keystore and wallet.dat. - An encrypted container or drive is a storage layer that may contain wallet files, backups, documents, or nothing crypto-related at all. Nobody can know without lawful examination.
If you are not sure which one you found, start at what did you find and treat everything as possibly sensitive until it is identified.
What to preserve
- The medium itself, exactly as found: the drive, USB stick, archive file or computer.
- Any written password, passphrase or recovery key: kept separately, and never photographed or typed into any online service.
- The name and version of the encryption software, if visible (VeraCrypt, TrueCrypt, BitLocker, LUKS, 7-Zip and so on). The software version can matter as much as the password.
- A note of where it was found, by whom and when, see chain of custody.
What not to do
- Do not format, reinstall or “fix” the device, formatting destroys what the encryption protects.
- Do not mount the volume and then write to it, and do not let an operating system “repair” it.
- Do not guess the password repeatedly or run password-guessing tools, you risk damaging the only copy, and the attempt has no lawful basis before authority is confirmed.
- Do not upload the file to an online service that offers to “unlock” or “decrypt” it.
- Do not photograph or type any written password into an app, message or website.
The password decides everything
An encrypted volume without its password cannot be opened by the estate’s documents alone. If the password exists in the estate’s papers, the combination of medium, password and software version restores access. If it is missing, some cases can be assessed technically and some cannot, nobody can know which without examining the exact situation. Read what is realistically possible in wallet recovery, and never pay anyone who guarantees an unlock before seeing the material.
What happens next
- Record the find in the estate inventory, facts only, never the password.
- Confirm legal authority before anything is opened, see legal authority vs technical access.
- Understand the password and passphrase rules: see wallet passwords and passphrases.
What this page is not
This page is identification and preservation guidance. It contains no tools, no “unlock” services and no instructions for decrypting anything: opening an encrypted volume belongs to the estate process, after authority is confirmed, using the owner’s own password or a verified professional.
For the full index of every wallet format and its deep guide, see the wallet format library.
For how storage methods compare for owners planning ahead, see crypto storage methods compared.
Quick answers to common questions
We found an encrypted drive or container, what is it?
It is storage protected by encryption: a VeraCrypt or TrueCrypt container or drive, a BitLocker-encrypted disk, a LUKS volume, or a password-protected archive or backup. The outside rarely shows what is inside, the password, the software and its version are the key. Preserve the medium and any written password separately, and identify the format before anything is touched.
The password is missing, can the encrypted storage be opened?
Not by guessing. Some cases can be assessed technically after legal authority is confirmed, and some cannot, nobody can know which without examining the exact situation. Never upload the file to an online service that offers to 'unlock' it, and read what is realistically possible in wallet recovery.
Can we try to crack the password ourselves?
No. Password-guessing tools risk damaging the only copy, and attempts to decrypt before legal authority is confirmed have no lawful basis. Preserve the medium exactly as found, record what you know about it, and let the estate process decide the next step.
Sources and useful links
- VeraCrypt, DocumentationChecked 2026-08-12
- Microsoft, BitLocker overviewChecked 2026-08-12