Amazon Changes Kindle Ebook Encryption — Protect Your Library

Amazon has quietly changed the encryption algorithm used for ebook downloads on older Kindle devices, according to reports from multiple outlets including Good e-Reader and PCMag. The change, which appears to have rolled out in mid-July 2026, affects the cryptographic key derivation that protects purchased Kindle books, rendering existing third-party decryption tools — including the widely-used DeDRM plugin for Calibre — unable to process newly downloaded copies.

For anyone who owns a Kindle made before 2020 and relies on Calibre to back up their ebook library, this is the most significant technical change Amazon has made to its ebook ecosystem since the AZW-to-KFX format migration. Here is what changed, which devices are affected, and — most importantly — what you can do right now to protect your digital library.

What Amazon Actually Changed

The change is not a new format or a firmware update pushed to older devices. Instead, Amazon appears to have modified the server-side encryption key derivation that applies when a Kindle ebook file is downloaded from its servers. When a user downloads a purchased book to an older Kindle via Wi-Fi or USB transfer from "Manage Your Content and Devices," the file is now encrypted with a different key structure than previously used.

Existing third-party tools that strip Kindle DRM — including the Calibre DeDRM plugin, which has been the gold standard for ebook backup for over a decade — rely on knowing the precise encryption scheme Amazon uses. With the key derivation changed, newly downloaded files will not decrypt correctly even if the user has their Kindle serial number registered in the tool. Older downloads that were already on a device or previously backed up to a computer remain unaffected; only fresh downloads after the change are encrypted differently.

Multiple ebook community forums have reported the issue since July 15. Users attempting to add recently-purchased books to Calibre for format conversion (e.g., AZW3 to EPUB) report seeing "Error — file not decrypted" or similar failures. The DeDRM plugin's maintainers have not yet released an updated version that accounts for the new key derivation, though the open-source community is actively reverse-engineering the change.

Which Kindle Models Are Affected

The encryption change appears to target older Kindle models — specifically devices manufactured before approximately 2020. Based on community reports, the following models are likely affected:

Model Release Year Last Major Firmware Risk Level
Kindle Keyboard (3rd Gen) 2010 3.4.3 High
Kindle Touch (4th Gen) 2011 5.3.7 High
Kindle Paperwhite (1st Gen) 2012 5.6.1.1 High
Kindle Paperwhite (2nd Gen) 2013 5.12.2 High
Kindle Voyage 2014 5.13.6 High
Kindle Oasis (1st Gen) 2016 5.13.6 High
Kindle (8th Gen / Basic) 2016 5.15.1 Medium
Kindle Oasis (2nd Gen) 2017 5.16.2.1.1 Medium
Kindle Paperwhite (10th Gen) 2018 5.16.2.1.1 Low
Kindle (10th Gen / Basic) 2019 5.16.2.1.1 Low

Newer models — the Kindle Paperwhite 11th Gen (2021), Kindle Scribe (2022), Kindle Oasis 3 (2019+), and Kindle Basic 11th Gen (2022) — do not appear affected. Amazon may have limited the encryption change to devices running firmware versions that can no longer be updated, effectively drawing a line between supported and legacy hardware.

Why This Matters for Your Digital Library

This is the second major Kindle ecosystem change in July 2026. Earlier this month, Amazon made KDP DRM opt-in for self-published authors, a move that was widely praised as a step toward consumer-friendly digital ownership. The encryption change on older devices takes the opposite direction — it makes it harder for long-time Kindle users to back up and convert books they have purchased legally.

If you own one of the older models listed above and regularly use Calibre to convert your Kindle books to EPUB for reading on other devices — or to create DRM-free backups — here is what is at stake:

What You Can Do Right Now

There are several practical steps you can take to protect your library, depending on your situation.

1. Do Not Re-Download Existing Books

If you already have DRM-free copies of your Kindle books backed up in Calibre, keep them as-is. Do not delete and re-download them from Amazon — the re-downloaded file may use the new encryption and break your existing workflow. Your current Calibre library is the gold standard; protect it.

2. Download New Purchases on a Newer Device

If you have a newer Kindle (Paperwhite 11th Gen, Scribe, or later), download new purchases on that device first, then transfer the file to your computer via USB. Newer devices appear to use a different download path that may not trigger the encryption change. Once on your computer, you can process the file with Calibre as usual.

3. Use USB Transfer, Not Wi-Fi Sync

For older Kindles, downloading books directly to the device via Wi-Fi seems to trigger the server-side encryption change. If you download a book on your computer via "Manage Your Content and Devices" and transfer it via USB, the file may still use the older encryption scheme. Test this with a single low-cost purchase before relying on it.

4. Keep Your Calibre Library Offline

Your existing Calibre library — with its converted EPUB files, metadata, and cover art — is already future-proof. EPUB is an open standard that no vendor can lock down. The encryption change only affects Kindle-format files (AZW3, KFX) downloaded from Amazon's servers. Your EPUB library is immune to this change.

5. Monitor the DeDRM Plugin Updates

The open-source community is actively working on an updated DeDRM plugin that accounts for the new key derivation. Check the Apprentice Alf / Apprentice Harper forums or the NoDRM repository on GitHub for updates. A fix typically arrives within weeks of encryption changes like this.

Comparing Amazon's Two July 2026 DRM Moves

It is worth stepping back and looking at the two Amazon DRM-related changes in July 2026 side by side:

Change Date Impact on Users Direction
KDP DRM opt-in July 14 Self-published authors can now publish DRM-free by default Pro-consumer
Older Kindle encryption change mid-July Legacy device owners lose ability to back up new purchases Anti-consumer

These two changes send conflicting signals. On one hand, Amazon is making it easier for new self-published ebooks to be DRM-free — a clear win for authors and readers who value open formats. On the other hand, the company is quietly tightening technical controls on older devices, effectively pushing legacy users toward upgrading to newer hardware if they want to keep their current backup workflows alive.

For the broader ebook ecosystem, the net effect is clear: the window for backing up Kindle books purchased on older devices is closing. If you own a legacy Kindle, now is the time to ensure your existing purchases are properly archived in an open, future-proof format.

How to Convert Your Kindle Library to EPUB Now

If this news has you thinking about future-proofing your library, here is the workflow that still works today:

  1. Download your Kindle books to your computer via "Manage Your Content and Devices" on Amazon's website.
  2. Import them into Calibre with the current DeDRM plugin installed and your device's serial number configured.
  3. Convert to EPUB using Calibre's built-in conversion tools. Calibre handles AZW3, MOBI, and older KFX formats reliably.
  4. Verify the output by opening each converted EPUB in Calibre's viewer or a dedicated EPUB reader app.
  5. Store your EPUB files in a separate backup location — cloud storage, an external drive, or a self-hosted Calibre Content Server.

Once your books are in EPUB format, they are vendor-independent. You can read them on a Kobo, a PocketBook, an iPad, a phone, or even transfer them back to a newer Kindle via the Send to Kindle service. EPUB is the format that lasts.

If you only need to convert a few files right now, you can also use converter-epub.com for quick browser-based conversion. It is client-side, private, and requires no upload — ideal for sensitive ebook files.

The Bottom Line

Amazon's quiet encryption change on older Kindles is a reminder that digital book ownership is conditional. When you buy a Kindle book, you are buying a license, not a file — and the technical terms of that license can change without notice. The encryption change does not break your existing library, but it does put a deadline on future backup capability for anyone using older hardware.

The safest long-term strategy remains the same as it has always been: convert your purchases to open formats like EPUB while conversion is still possible, and store your library independently of any vendor's servers. The Calibre library you build today is the only copy you truly own.

Frequently Asked Questions

Will my existing Kindle books stop working?

No. Books you already downloaded before the encryption change will continue to work normally on your Kindle and in Calibre. Only newly downloaded or re-downloaded files after the change use the different encryption key.

Can I still use Calibre to convert my Kindle books to EPUB?

For books you already downloaded and imported into Calibre before the encryption change, yes — those files will continue to convert to EPUB without issues. For new purchases, you may need to wait for an updated DeDRM plugin or use a newer Kindle device to download them first.

Which Kindle models are affected by the encryption change?

Older Kindle models released before approximately 2020 are affected, including the Kindle Keyboard, Kindle Touch, Kindle Paperwhite 1st and 2nd Gen, Kindle Voyage, and Kindle Oasis 1st Gen. Newer models like the Paperwhite 11th Gen (2021) and Kindle Scribe do not appear to be affected.

Was this change announced by Amazon?

No. Amazon has not issued any official statement about the encryption change. The news was first reported by Good e-Reader and confirmed by community reports from Kindle users who found their DeDRM tools suddenly failing. This appears to be a server-side change with no public announcement.

Is there a fix or updated tool available yet?

As of July 17, 2026, the DeDRM plugin maintainers have not yet released an update. However, the open-source community is actively reverse-engineering the new key derivation. Historically, similar encryption changes have been resolved within weeks. Monitor the NoDRM GitHub repository and Apprentice Alf forums for updates.