# Security of volume encryption after DSM 7.3.2 update

**URL:** <https://forums.spacerex.co/t/security-of-volume-encryption-after-dsm-7-3-2-update/3560>\
**Category:** Synology\
**Tags:** encryption\
**Created:** [January 31, 2026, 6:52am UTC](https://forums.spacerex.co/t/security-of-volume-encryption-after-dsm-7-3-2-update/3560 "2026-01-31T06:52:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gusifang](https://forums.spacerex.co/letter_avatar_proxy/v4/letter/g/aeb1de/32.png) [@gusifang](https://forums.spacerex.co/u/gusifang)\
**Post date:** [January 31, 2026, 6:52am UTC](https://forums.spacerex.co/t/security-of-volume-encryption-after-dsm-7-3-2-update/3560/1 "2026-01-31T06:52:54Z")

</div>

Hi,

After upgrading to DSM 7.3.2 and the new encryption key vault, my encrypted volume is now auto-unlocked after a normal reboot (no vault password or recovery key required). It also seems impossible to fully disable the local vault anymore.

In the past, there were public demos showing data access from a powered-off NAS by manipulating the system/reset process and extracting encryption material.

Does anyone know if DSM 7.3.2 actually fixes this class of attacks, or if the new “lock on manual reset” option only mitigates admin-reset scenarios while the vault is still auto-unlocked at boot and potentially exploitable?

Thanks!

---

<div class="post-metadata">

**Author:** ![Paul](https://forums.spacerex.co/user_avatar/forums.spacerex.co/paul/32/93_2.png) [@Paul](https://forums.spacerex.co/u/Paul)\
**Post date:** [February 1, 2026, 3:15pm UTC](https://forums.spacerex.co/t/security-of-volume-encryption-after-dsm-7-3-2-update/3560/2 "2026-02-01T15:15:07Z")

</div>

From which DSM version did you upgrade to DSM 7.3.2? When I looked into the Synology knowledge base, I could only find a change in behavior for unlocking an encrypted volume in DSM 7.3.0.

This is the KB article I am referring to: [What are the benefits of upgrading and resetting the encryption key vault, and how can I do it? - Synology Knowledge Center](https://kb.synology.com/en-us/DSM/tutorial/How_to_upgrade_encryption_key_vault)

---

<div class="post-metadata">

**Author:** ![gusifang](https://forums.spacerex.co/letter_avatar_proxy/v4/letter/g/aeb1de/32.png) [@gusifang](https://forums.spacerex.co/u/gusifang)\
**Post date:** [February 1, 2026, 7:40pm UTC](https://forums.spacerex.co/t/security-of-volume-encryption-after-dsm-7-3-2-update/3560/3 "2026-02-01T19:40:06Z")

</div>

Hi Paul, I recall that full volume encryption was introduced in 7.2. It had a major flaw because the data could be accessed with a soft reset.

So in 7.3 a new feature was introduced which erases the vault in case of a soft reset. But the key is still stored on the NAS, so how difficult is it to access it?

There was a previous exploit which managed to do it. SpaceRex mentions it here (7m15s) without giving the details:

[![](https://forums.spacerex.co/uploads/default/original/2X/a/a9eb61cc6a34e91cfdd406648660616e5caeb486.jpeg "Full Volume Encryption - The MOST Exciting Feature on Synology DSM 7.2") ](https://www.youtube.com/watch?v=lyKXldHPAOU&t=7m15s)
