Amazon Changes Kindle Ebook Encryption — Protect Your Library
Amazon has quietly changed the encryption algorithm used for ebook downloads on older Kindle devices, according to reports from multiple outlets including Good e-Reader and PCMag. The change, which appears to have rolled out in mid-July 2026, affects the cryptographic key derivation that protects purchased Kindle books, rendering existing third-party decryption tools — including the widely-used DeDRM plugin for Calibre — unable to process newly downloaded copies.
For anyone who owns a Kindle made before 2020 and relies on Calibre to back up their ebook library, this is the most significant technical change Amazon has made to its ebook ecosystem since the AZW-to-KFX format migration. Here is what changed, which devices are affected, and — most importantly — what you can do right now to protect your digital library.
What Amazon Actually Changed
The change is not a new format or a firmware update pushed to older devices. Instead, Amazon appears to have modified the server-side encryption key derivation that applies when a Kindle ebook file is downloaded from its servers. When a user downloads a purchased book to an older Kindle via Wi-Fi or USB transfer from "Manage Your Content and Devices," the file is now encrypted with a different key structure than previously used.
Existing third-party tools that strip Kindle DRM — including the Calibre DeDRM plugin, which has been the gold standard for ebook backup for over a decade — rely on knowing the precise encryption scheme Amazon uses. With the key derivation changed, newly downloaded files will not decrypt correctly even if the user has their Kindle serial number registered in the tool. Older downloads that were already on a device or previously backed up to a computer remain unaffected; only fresh downloads after the change are encrypted differently.
Multiple ebook community forums have reported the issue since July 15. Users attempting to add recently-purchased books to Calibre for format conversion (e.g., AZW3 to EPUB) report seeing "Error — file not decrypted" or similar failures. The DeDRM plugin's maintainers have not yet released an updated version that accounts for the new key derivation, though the open-source community is actively reverse-engineering the change.
Which Kindle Models Are Affected
The encryption change appears to target older Kindle models — specifically devices manufactured before approximately 2020. Based on community reports, the following models are likely affected:
| Model | Release Year | Last Major Firmware | Risk Level |
|---|---|---|---|
| Kindle Keyboard (3rd Gen) | 2010 | 3.4.3 | High |
| Kindle Touch (4th Gen) | 2011 | 5.3.7 | High |
| Kindle Paperwhite (1st Gen) | 2012 | 5.6.1.1 | High |
| Kindle Paperwhite (2nd Gen) | 2013 | 5.12.2 | High |
| Kindle Voyage | 2014 | 5.13.6 | High |
| Kindle Oasis (1st Gen) | 2016 | 5.13.6 | High |
| Kindle (8th Gen / Basic) | 2016 | 5.15.1 | Medium |
| Kindle Oasis (2nd Gen) | 2017 | 5.16.2.1.1 | Medium |
| Kindle Paperwhite (10th Gen) | 2018 | 5.16.2.1.1 | Low |
| Kindle (10th Gen / Basic) | 2019 | 5.16.2.1.1 | Low |
Newer models — the Kindle Paperwhite 11th Gen (2021), Kindle Scribe (2022), Kindle Oasis 3 (2019+), and Kindle Basic 11th Gen (2022) — do not appear affected. Amazon may have limited the encryption change to devices running firmware versions that can no longer be updated, effectively drawing a line between supported and legacy hardware.
Why This Matters for Your Digital Library
This is the second major Kindle ecosystem change in July 2026. Earlier this month, Amazon made KDP DRM opt-in for self-published authors, a move that was widely praised as a step toward consumer-friendly digital ownership. The encryption change on older devices takes the opposite direction — it makes it harder for long-time Kindle users to back up and convert books they have purchased legally.
If you own one of the older models listed above and regularly use Calibre to convert your Kindle books to EPUB for reading on other devices — or to create DRM-free backups — here is what is at stake:
- Future purchases cannot be backed up via existing DeDRM workflows. Any book you buy starting now will download with the new encryption.
- Previously downloaded books are safe. If you already have a copy on your computer or device that works with Calibre, it will continue to work.
- Re-downloads may trigger the new encryption. If you delete a book from your computer and re-download it from Amazon's servers, the new file may use the updated encryption.
- Cross-device reading gets harder. One of the main reasons Kindle users convert to EPUB is to read on Kobo, PocketBook, or phone apps. New purchases made on an older Kindle may not be convertible.
What You Can Do Right Now
There are several practical steps you can take to protect your library, depending on your situation.
1. Do Not Re-Download Existing Books
If you already have DRM-free copies of your Kindle books backed up in Calibre, keep them as-is. Do not delete and re-download them from Amazon — the re-downloaded file may use the new encryption and break your existing workflow. Your current Calibre library is the gold standard; protect it.
2. Download New Purchases on a Newer Device
If you have a newer Kindle (Paperwhite 11th Gen, Scribe, or later), download new purchases on that device first, then transfer the file to your computer via USB. Newer devices appear to use a different download path that may not trigger the encryption change. Once on your computer, you can process the file with Calibre as usual.
3. Use USB Transfer, Not Wi-Fi Sync
For older Kindles, downloading books directly to the device via Wi-Fi seems to trigger the server-side encryption change. If you download a book on your computer via "Manage Your Content and Devices" and transfer it via USB, the file may still use the older encryption scheme. Test this with a single low-cost purchase before relying on it.
4. Keep Your Calibre Library Offline
Your existing Calibre library — with its converted EPUB files, metadata, and cover art — is already future-proof. EPUB is an open standard that no vendor can lock down. The encryption change only affects Kindle-format files (AZW3, KFX) downloaded from Amazon's servers. Your EPUB library is immune to this change.
5. Monitor the DeDRM Plugin Updates
The open-source community is actively working on an updated DeDRM plugin that accounts for the new key derivation. Check the Apprentice Alf / Apprentice Harper forums or the NoDRM repository on GitHub for updates. A fix typically arrives within weeks of encryption changes like this.
Comparing Amazon's Two July 2026 DRM Moves
It is worth stepping back and looking at the two Amazon DRM-related changes in July 2026 side by side:
| Change | Date | Impact on Users | Direction |
|---|---|---|---|
| KDP DRM opt-in | July 14 | Self-published authors can now publish DRM-free by default | Pro-consumer |
| Older Kindle encryption change | mid-July | Legacy device owners lose ability to back up new purchases | Anti-consumer |
These two changes send conflicting signals. On one hand, Amazon is making it easier for new self-published ebooks to be DRM-free — a clear win for authors and readers who value open formats. On the other hand, the company is quietly tightening technical controls on older devices, effectively pushing legacy users toward upgrading to newer hardware if they want to keep their current backup workflows alive.
For the broader ebook ecosystem, the net effect is clear: the window for backing up Kindle books purchased on older devices is closing. If you own a legacy Kindle, now is the time to ensure your existing purchases are properly archived in an open, future-proof format.
How to Convert Your Kindle Library to EPUB Now
If this news has you thinking about future-proofing your library, here is the workflow that still works today:
- Download your Kindle books to your computer via "Manage Your Content and Devices" on Amazon's website.
- Import them into Calibre with the current DeDRM plugin installed and your device's serial number configured.
- Convert to EPUB using Calibre's built-in conversion tools. Calibre handles AZW3, MOBI, and older KFX formats reliably.
- Verify the output by opening each converted EPUB in Calibre's viewer or a dedicated EPUB reader app.
- Store your EPUB files in a separate backup location — cloud storage, an external drive, or a self-hosted Calibre Content Server.
Once your books are in EPUB format, they are vendor-independent. You can read them on a Kobo, a PocketBook, an iPad, a phone, or even transfer them back to a newer Kindle via the Send to Kindle service. EPUB is the format that lasts.
If you only need to convert a few files right now, you can also use converter-epub.com for quick browser-based conversion. It is client-side, private, and requires no upload — ideal for sensitive ebook files.
The Bottom Line
Amazon's quiet encryption change on older Kindles is a reminder that digital book ownership is conditional. When you buy a Kindle book, you are buying a license, not a file — and the technical terms of that license can change without notice. The encryption change does not break your existing library, but it does put a deadline on future backup capability for anyone using older hardware.
The safest long-term strategy remains the same as it has always been: convert your purchases to open formats like EPUB while conversion is still possible, and store your library independently of any vendor's servers. The Calibre library you build today is the only copy you truly own.
Frequently Asked Questions
Will my existing Kindle books stop working?
No. Books you already downloaded before the encryption change will continue to work normally on your Kindle and in Calibre. Only newly downloaded or re-downloaded files after the change use the different encryption key.
Can I still use Calibre to convert my Kindle books to EPUB?
For books you already downloaded and imported into Calibre before the encryption change, yes — those files will continue to convert to EPUB without issues. For new purchases, you may need to wait for an updated DeDRM plugin or use a newer Kindle device to download them first.
Which Kindle models are affected by the encryption change?
Older Kindle models released before approximately 2020 are affected, including the Kindle Keyboard, Kindle Touch, Kindle Paperwhite 1st and 2nd Gen, Kindle Voyage, and Kindle Oasis 1st Gen. Newer models like the Paperwhite 11th Gen (2021) and Kindle Scribe do not appear to be affected.
Was this change announced by Amazon?
No. Amazon has not issued any official statement about the encryption change. The news was first reported by Good e-Reader and confirmed by community reports from Kindle users who found their DeDRM tools suddenly failing. This appears to be a server-side change with no public announcement.
Is there a fix or updated tool available yet?
As of July 17, 2026, the DeDRM plugin maintainers have not yet released an update. However, the open-source community is actively reverse-engineering the new key derivation. Historically, similar encryption changes have been resolved within weeks. Monitor the NoDRM GitHub repository and Apprentice Alf forums for updates.