element-hq / element-hq/element-web

Unable to decrypt all message history after verifying session with recovery key

Open
#34,829 0 comments 0 reactions 0 assignees View on GitHub
A-E2EE-Key-Backup A-Electron O-Uncommon S-Critical T-Defect
Dominant language
TypeScript
Stars
13.5k
Forks
2.8k
PR merge metrics
PR metrics pending

Description

### Steps to reproduce

1. I was using Element Desktop normally on Windows and could access my encrypted message history.
2. On 25 August 2026, Element asked me to verify my session.
3. I selected "Verify this session" and completed the verification.
4. The session is now shown as verified.
5. My recovery key is available and valid. I successfully used it to verify additional sessions in Firefox and Edge.
6. Recovery/backup is enabled in Element.
7. After the verification, all my previous encrypted messages show "Unable to decrypt".
8. The same historical messages are undecryptable in Element Desktop, Firefox and Edge, including newly verified sessions.
9. New/current messages appear to work normally; the issue affects the previous message history.
To the best of my recollection, I only selected "Verify this session" when the issue occurred.

### Outcome

#### What did you expect?
After verifying the session with my recovery key, I expected my existing encrypted message history to remain accessible or to be restored from key backup.

#### What happened instead?
The session was successfully verified, but all historical encrypted messages now show "Unable to decrypt". The recovery key is accepted when verifying new sessions, but the historical messages remain undecryptable on every verified session I tested.

I am particularly concerned that the message keys may still exist in key backup but are not being restored. I would like to avoid resetting my cryptographic identity or recovery setup before determining whether the historical keys can still be recovered.

### Operating system

Windows

### Application version

Element 1.12.26 — Rust SDK 0.18.0 (16a138b), Vodozemac 0.10.0

### How did you install the app?

Downloaded from the official Element website (element.io)

### Homeserver

https://matrix-client.matrix.org

### Will you send logs?

Yes

Contributor guide

Open the contributing guide

Research direction

Reproduce the failure in Element Desktop and the tested web clients using the supplied recovery key, then collect the promised logs around session verification, key backup, and historical message decryption. Compare whether current messages decrypt while older history does not, and determine whether the missing message keys are present in backup before proposing any recovery or identity reset.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust, typescript
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
32/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.