# What Encryption Modes Are Available in VeraCrypt?

> Discover VeraCrypt's encryption modes. VeraCrypt exclusively uses XTS mode, implemented with OpenSSL or WolfCrypt, for robust data protection. Learn more.

- Repository: [VeraCrypt/VeraCrypt](https://github.com/veracrypt/VeraCrypt)
- Tags: deep-dive
- Published: 2026-07-01

---

**VeraCrypt supports only one encryption mode: XTS (XEX‑based tweaked‑codebook mode with ciphertext stealing), implemented via either OpenSSL or WolfCrypt backends depending on the build configuration.**

The veracrypt/VeraCrypt repository maintains a straightforward approach to disk encryption by standardizing on a single, secure mode across all supported ciphers. When examining the encryption modes available in VeraCrypt, the source code reveals that the implementation focuses exclusively on XTS, with compile‑time options determining the underlying cryptographic library rather than the mode itself.

## XTS: The Exclusive Encryption Mode

VeraCrypt implements **XTS** as its sole encryption mode. This design applies universally to every supported block cipher, including AES, Serpent, and Twofish. While users can select different algorithms for encryption, VeraCrypt always pairs them with XTS mode.

The mode implementation remains independent of the specific cipher algorithm. Whether you configure a volume to use AES‑256 or Serpent, the underlying mode is XTS, as defined in the volume layout registration logic.

## Backend Implementation Classes

Although VeraCrypt offers only one functional mode, the codebase contains two distinct C++ classes that implement XTS. The build system selects the appropriate backend at compile time.

### OpenSSL Backend (Default)

The default configuration utilizes the OpenSSL cryptographic library via the `EncryptionModeXTS` class.

- **Source file**: [`src/Volume/EncryptionModeXTS.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionModeXTS.cpp)
- **Class**: `EncryptionModeXTS`
- **Build condition**: Default when `WOLFCRYPT_BACKEND` is undefined

### WolfCrypt Backend

When compiled with the `WOLFCRYPT_BACKEND` preprocessor definition, VeraCrypt switches to the WolfCrypt library implementation.

- **Source file**: [`src/Volume/EncryptionModeWolfCryptXTS.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionModeWolfCryptXTS.cpp)
- **Class**: `EncryptionModeWolfCryptXTS`
- **Build condition**: When `WOLFCRYPT_BACKEND` is defined

## Mode Enumeration Factory

The static method `EncryptionMode::GetAvailableModes()` serves as the central factory for discovering supported modes at runtime. Located in [`src/Volume/EncryptionMode.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionMode.cpp), this method returns a list containing exactly one mode object:

```cpp
EncryptionModeList EncryptionMode::GetAvailableModes ()
{
    EncryptionModeList l;
#ifdef WOLFCRYPT_BACKEND
    l.push_back (shared_ptr<EncryptionMode>(new EncryptionModeWolfCryptXTS()));
#else
    l.push_back (shared_ptr<EncryptionMode>(new EncryptionModeXTS()));
#endif
    return l;
}

```

This factory pattern ensures that consuming code receives a compatible `EncryptionMode` interface pointer regardless of the backend implementation details.

## Volume Layout Integration

Each volume layout—whether normal or hidden—registers the encryption mode during construction. In [`src/Volume/VolumeLayout.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/VolumeLayout.cpp), the constructors populate the `SupportedEncryptionModes` vector with the appropriate XTS implementation:

```cpp
SupportedEncryptionModes.push_back (shared_ptr<EncryptionMode>(new EncryptionModeXTS()));
// or, when compiled with WolfCrypt:
SupportedEncryptionModes.push_back (shared_ptr<EncryptionMode>(new EncryptionModeWolfCryptXTS()));

```

This registration occurs consistently across all volume layout types, reinforcing that VeraCrypt offers only XTS mode for volume encryption.

## Code Examples

The following examples demonstrate how to interact with the encryption mode system programmatically.

### Listing Available Modes at Runtime

To retrieve the list of supported encryption modes programmatically, call the factory method:

```cpp
#include "Volume/EncryptionMode.h"

int main ()
{
    auto modes = VeraCrypt::EncryptionMode::GetAvailableModes();

    for (const auto &mode : modes)
    {
        // All modes derive from EncryptionMode and expose a name
        std::cout << "Supported mode: " << mode->GetName() << std::endl;
    }
    return 0;
}

```

This code instantiates mode objects via `GetAvailableModes()` and outputs their names, which will be `"XTS"` for both backend implementations.

### Querying an Opened Volume's Mode

Once a volume is mounted, inspect which encryption mode it utilizes:

```cpp
VeraCrypt::Volume volume;               // Assume the volume is already opened
auto mode = volume.GetEncryptionMode(); // Returns a shared_ptr<EncryptionMode>
std::cout << "Volume uses mode: " << mode->GetName() << std::endl;

```

The `Volume::GetEncryptionMode()` method returns the mode stored in the volume header. As VeraCrypt exclusively uses XTS, this will always return the XTS implementation regardless of the underlying cipher.

### Key Source Files

- **[`src/Volume/EncryptionMode.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionMode.cpp)**: Contains the `GetAvailableModes()` factory and the base `EncryptionMode` class implementation.
- **[`src/Volume/EncryptionModeXTS.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionModeXTS.cpp)**: Implements the OpenSSL‑based XTS mode.
- **[`src/Volume/EncryptionModeWolfCryptXTS.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionModeWolfCryptXTS.cpp)**: Implements the WolfCrypt‑based XTS variant.
- **[`src/Volume/VolumeLayout.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/VolumeLayout.cpp)**: Registers the supported mode for each volume layout type.

## Summary

- VeraCrypt supports exactly **one encryption mode: XTS**, regardless of the selected cipher algorithm (AES, Serpent, Twofish, etc.).
- The codebase provides **two backend implementations**: `EncryptionModeXTS` for OpenSSL and `EncryptionModeWolfCryptXTS` for WolfCrypt, selected at compile time via the `WOLFCRYPT_BACKEND` flag.
- The factory method `EncryptionMode::GetAvailableModes()` in [`src/Volume/EncryptionMode.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/EncryptionMode.cpp) returns a singleton list containing the configured XTS implementation.
- All volume layouts register XTS as their supported mode during construction in [`src/Volume/VolumeLayout.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/VolumeLayout.cpp).

## Frequently Asked Questions

### Does VeraCrypt support CBC or other encryption modes?

No. According to the veracrypt/VeraCrypt source code, the `GetAvailableModes()` factory explicitly returns only the XTS implementation. Unlike some other disk encryption tools, VeraCrypt does not offer CBC, LRW, or other historical modes, having standardized exclusively on XTS for its security properties regarding disk encryption.

### What is the difference between EncryptionModeXTS and EncryptionModeWolfCryptXTS?

The difference is purely the underlying cryptographic library, not the mode itself. `EncryptionModeXTS` utilizes the OpenSSL backend by default, while `EncryptionModeWolfCryptXTS` interfaces with the WolfCrypt library when VeraCrypt is compiled with the `WOLFCRYPT_BACKEND` flag. Both implement the same XTS mode specification and provide identical security guarantees.

### Can I change the encryption mode of an existing VeraCrypt volume?

No. The encryption mode is determined at volume creation time and stored in the volume header. To change modes, you would need to create a new volume and migrate data, as VeraCrypt only supports XTS mode and does not provide mechanisms to convert between different modes (nor would this be meaningful since only one mode is available).

### Why does VeraCrypt use XTS mode exclusively?

XTS mode is specifically designed for disk encryption and provides protection against targeted ciphertext manipulation attacks that could occur with simpler modes like CBC. By standardizing on XTS across all ciphers in [`src/Volume/VolumeLayout.cpp`](https://github.com/veracrypt/VeraCrypt/blob/main/src/Volume/VolumeLayout.cpp), VeraCrypt ensures consistent security semantics regardless of whether the user selects AES, Serpent, or Twofish as the underlying block cipher.