After updating Brave on Windows 10, all my saved passwords, browsing history and settings disappeared.
The update was downloaded automatically without my consent and applied through the browser interface.
After restarting (following hibernation), Brave created a new profile and encryption key. As a result, my existing data (including the “Login Data” file) is no longer accessible.
There was absolutely no warning that such data loss could occur.
From a user perspective, this is critical:
I am effectively locked out of multiple accounts
Including banking access
All locally stored credentials became unusable overnight
This is not acceptable behavior for a browser that stores sensitive user data.
Questions:
Is there any official way to recover passwords if the Local State encryption key has been replaced?
Why does Brave not warn users that automatic updates may invalidate stored credentials?
How can automatic updates be permanently disabled on Windows?
Additional context:
The data was present and working immediately after the update
It disappeared only after resuming from hibernation
No manual deletion or antivirus action was performed
Conclusion:
Users should not lose access to their own data without warning or recovery options.
This behavior severely undermines trust in the browser.