macOS Tahoe 26.4 locked the login keychain to one Mac's Secure Enclave (September 10, 2026)

Chapters
What broke
You copy login.keychain-db off a Mac, add it in Keychain Access on a different Mac, type the correct login password, and it is refused. There is no second prompt and no route to the contents. Johnson's line is blunt: "Your login keychain file cannot be decrypted on another device, even with your login password."
Der Flounder had described the same failure two days earlier, on September 8, 2026, with the exact log line: "SecKeychainLogin failed: -2147413984, password was supplied". The destination Mac then automatically creates a new login keychain, which is the part that makes this quiet. The visible result is not an error you chase, it is an empty keychain you might assume is yours.
TL;DR
A login keychain file copied off one Mac can no longer be opened on another Mac, even with the correct login password, a change that went into macOS Tahoe 26.4 and was published on September 10, 2026 by Lapcat Software. The keys that decrypt it are held in the source Mac's Secure Enclave, so the file is bound to the hardware it came from. Nothing fails in daily use, which is why this only appears at the worst possible moment: when the original Mac is gone.
- Jeff Johnson's summary: "You do not and cannot have a reliable backup of your login keychain."
- The failure in the log is "SecKeychainLogin failed: -2147413984, password was supplied".
- The destination Mac quietly creates a fresh login keychain instead of opening the copied one.
- The change landed in the macOS 26.4 update of March 2026 and is not in the 26.4 release notes.
- No Apple acknowledgement and no published manual workaround as of September 10, 2026.
Why the file cannot travel
The keys are in a place that does not move. Der Flounder ties the failure to the source machine's Secure Enclave and quotes Apple's own documentation: "The metadata key is protected by the Secure Enclave but is cached in the Application Processor to allow fast queries of the keychain." A key held inside one Mac's Secure Enclave is not a key a second Mac can be handed.
That makes the copied file a pile of ciphertext with no way in. Der Flounder scopes the problem to Secure Enclave Macs running macOS Tahoe, and Johnson dates the change to the 26.4 update, which means every Tahoe release since carries it, 26.6.2 included.
It only bites at recovery time
Day to day, nothing is wrong. Your Mac unlocks its own login keychain exactly as it always did, and no app reports a problem. The defect surfaces when the Mac is lost, stolen, dead or replaced, which is the moment you are relying on a backup instead of testing one.
Time Machine does not rescue this. Johnson reports it can restore the login keychain to the same Mac and is useless for restoring it to another. That sentence deserves a second read: a backup that only restores to the machine that is gone is not a backup of that data at all.
And the change was never announced. Johnson: "To my knowledge, Apple did not even publicize the change in Tahoe." The public release notes for macOS 26.4 do not mention it, so what a login keychain file can do changed in March 2026 with nothing said about it.
No workaround published as of September 10
Der Flounder gives no manual workaround, and neither report published one. That is the honest state of it on September 10, 2026: the behavior is documented, the cause is understood, and the remedy is missing. I will not dress that up, and I will not invent a command that opens the file, because none is published.
What did change on this day is how many people know. A submission to Hacker News at 22:33:45Z on September 10, 2026 reached 71 points and 64 comments, pointing at the Der Flounder post. An identical link submitted the previous day at 13:14:10Z had drawn 4 points and one comment, so September 10 is the day this stopped being a niche finding among Mac administrators.
Who is affected: anyone on macOS Tahoe 26.4 or later on a Mac with a Secure Enclave. This is not a beta problem and not a developer problem.
What to do today
In order: 1. Stop counting a copy of login.keychain-db as a backup of your passwords. On Tahoe 26.4 or later it opens nowhere except the Mac it came from. 2. Test today that you can reach the credentials you would need if this Mac died: sign in to two or three of the accounts you would panic about from a different device, using something other than the keychain to do it. 3. Move anything you cannot afford to lose out of the login keychain and into a store you can open on other hardware.
4. Keep the old Mac running and reachable until you have confirmed on the replacement that everything you need is actually there. While the source Mac still boots, its own login keychain still opens, and that is the only copy of those keys. 5. If a Mac has already gone and all you hold is a copied keychain file, treat those credentials as lost and start resetting them, rather than spending a weekend looking for a tool. No published method opens that file.
For administrators: check any migration or recovery runbook that says to copy the login keychain, because that step no longer does anything useful on Tahoe 26.4 or later. The cost of leaving it in place is a migration that looks complete and quietly is not.
Frequently asked questions
Does the same password stop working on my own Mac?
No. The login keychain on the Mac that created it keeps unlocking with your login password. The failure is specific to opening that file on different hardware.
Has Apple said anything about this?
Not as of September 10, 2026. Johnson writes that to his knowledge Apple did not publicize the change, and the macOS 26.4 release notes do not mention it. There is no support document and no fix.