Bitskrieg: Another Bitlocker Bypass Technique

Last Updated: June 6, 2026 1:44 AM

What’s Happening

On June 5th, 2026 yet another researcher, @jonasLyk on X, has sidestepped the MSRC disclosure process and released a Bitlocker Bypass Vulnerability, this time dubbed Bitskrieg.

The POC:

hxxps://x[.]com/jonasLyk/status/2062768028090007773

A very nice summary of the POC:

https://infosec.exchange/@wdormann/116699350092887103

Nightmare Eclipse’s Blog Post:

Actions

Adding a boot PIN (TPM+PIN) is currently the best mitigation, similar to the Yellowkey Bitlocker Bypass vulnerability.

Notes

The comments section of the original POC:

https://xcancel.com/jonasLyk/status/2062768028090007773#m

Previous reporting on the Yellowkey Vulnerability:

https://discourse.ifin.network/t/chaotic-eclipse-nightmare-eclipse-drops-two-windows-0days-cve-2026-45585/437

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585

4 Likes

Microsoft appears to have addressed this vulnerability, along with several others (including the similar Yellowkey vulnerability) with the June 9th Patch Tuesday.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50507

We suggest updating your Windows machines to the latest version of Windows to address these security issues.