
What makes a free VPN risky: what the research says
A free VPN app looks like a gift: download it, press one button, everything works. The question worth asking at that moment is boring but to the point: what does it earn money on? Servers, bandwidth and addresses cost money, and the costs grow with the number of users — there is no economy of scale here that would make you cheap to serve.
What follows is an answer to the question of whether free VPNs are safe — not scare stories but what has been measured and documented: peer-reviewed research, court decisions and confirmed investigations. Where the data is imprecise, or where a figure is habitually distorted, that is flagged.
Why a free VPN is risky by its very design
When you allow an app to act as a VPN, the operating system creates a virtual network interface and all of the device’s traffic goes through it. Researchers put it bluntly: that permission lets an app intercept, modify and forward all of your traffic to a server of its own choosing. The usual protection, under which one app cannot see another’s data, stops working at that moment — one app receives the traffic of all the others.
So the question is not whether the app “encrypts” the channel, but who you handed all your traffic to and what that someone does with it.
What free VPNs actually collect: the research data
The most cited work is a measurement of 283 apps with VPN permission, selected from 1.4 million apps in the catalogue (Internet Measurement Conference, 2016). Ten years later the measurement was repeated on 281 popular free apps with more than 2.4 billion installs between them (NDSS conference, 2026). The picture changed less than one would hope:
| What was measured | Result | Study |
|---|---|---|
| Third-party tracking libraries in the app | 75% — while 67% promised “better privacy” | IMC, 2016 |
| A tunnel with no encryption at all | 18% | IMC, 2016 |
| Requests for site names travelling outside the tunnel | 66% | IMC, 2016 |
| Certificate substitution, that is, reading secure traffic | 4 apps from 3 developers | IMC, 2016 |
| Traffic outside the tunnel, including requests for site names | 29 apps, 24 of them with around 360m installs | NDSS, 2026 |
| Contacting advertising and tracking servers | 246 apps out of 281 | NDSS, 2026 |
| Outdated or weak ciphers in the configuration | about 19% of the configurations examined | NDSS, 2026 |
The most popular figure deserves a separate word. From that same 2016 work came the claim that “38% of free VPNs contain malware”. In the original that is the share of apps for which at least one antivirus engine out of several dozen fired; at a strict threshold of five engines, 4% remain. We give the precise wording because exaggeration here works against trust in the rest of the data.
What the user pays with
The monetization models are not hypothetical — each is backed by documents or court decisions:
- Traffic as the product. The Hola service sold its free users’ bandwidth through a separate commercial network; in 2015 that network was used to attack a third-party site. The model is not hidden: it is written into the user agreement, and the only way to opt out is to become a paying customer.
- Selling market analytics. According to a 2020 investigation, the company Sensor Tower secretly owned at least two dozen apps, including VPNs and ad blockers, with more than 35 million downloads between them. Users were asked to install a root certificate — a file that opens access to the contents of secure connections.
- Data for the parent company. The Onavo app belonged to Facebook and collected information about which apps a person used. In 2018 it was removed from Apple’s store, in 2019 it was shut down, and in 2023 the Federal Court of Australia fined two related companies 10 million Australian dollars each for misleading promotion.
- Your device as somebody else’s exit node. In 2024, 28 programs were found in the app catalogue that turned phones into nodes of a commercial proxy network; 17 of them posed as free VPNs. That same year the US Department of Justice announced the takedown of a network of more than 19 million infected addresses in nearly two hundred countries — the malicious code was distributed inside free VPN apps among other things, and its administrator earned about 99 million dollars selling access to other people’s addresses.
The last point is worth following to its conclusion: if your device works as an exit node, then other people’s actions online look as if they came from your home address.
VPN data leaks: what has already spilled
A separate matter is how safely all that collected data is kept. The two largest confirmed cases:
- July 2020. Researchers found an exposed database belonging to seven services that shared infrastructure — about 1.2 terabytes in total. One service alone held more than 20 million log records: passwords in plain text, users’ addresses, timestamps, geolocation, device models. All seven claimed to keep no logs.
- May 2023. An app with more than a hundred million downloads was found with an exposed 133-gigabyte database: over 360 million records including users’ original addresses, geolocation, keys and the sites they visited — under a publicly stated policy of “we store nothing.”
The conclusion is not that everyone lies but something duller: the promise “we do not store” can only be checked when something breaks — and by then checking is too late.
Who actually owns the app
Another feature of this market: outwardly independent brands often belong to the same people. In research published in September 2025, 32 apps with more than a billion downloads between them, distributed under the names of 21 formally independent providers, turned out to share infrastructure, code and identical hard-coded passwords — the kind that let anyone who knew them decrypt any user’s traffic.
A separate 2025 investigation showed that one in five of the hundred most popular free VPN apps in the American catalogue belongs to Chinese companies, and five of them are linked to a corporation placed on a US Department of Commerce restricted list. This is not about “the Chinese being bad” — it is about the fact that the owner of a service is usually unknown to the user at all.
Why “best free VPN” rankings do not help
Searching brings up dozens of reviews with tables and scores. Trusting them is hard after a 2022 study in which the authors interviewed nine providers: places in such rankings are sold, some review sites are affiliated with the services themselves or owned by them, and the income comes from affiliate referrals. An earlier survey of the market reached the same conclusion: with no independent assessment available, users are forced to rely on reviews that are knowingly partial.
The risk is higher in Russia: well-known services are blocked in the stores
The context adds risks. Since July 2024 the apps of well-known services have been removed from the Russian Apple catalogue: by the end of April 2026, 116 services were unavailable there. Recognizable brands leave, and their place is taken by little-known apps and installs from unofficial sources — precisely the class the cases above belong to.
In May 2026 the cybercrime directorate of the interior ministry warned that a banking trojan was being distributed under the guise of a VPN service: the app gains access to messages and notifications, including transaction confirmation codes, and downloads further malicious modules. The statement named no apps and gave no number of victims.
Russian research published in February 2026 examined the 87 most downloaded free apps: 16 of them sent data to servers located in Russia. The authors note honestly that part of the traffic could not be decrypted, so the full set of what is collected is not proven.
Meanwhile an April 2026 survey found that 40% of Russians use a VPN, and nearly half of them choose free options. So this is not a marginal topic: it is a choice made by one adult in five in the country.
A paid service and your own server: what actually changes
The honest answer: technically, in all three cases whoever runs the exit node sees the same service data — who connected, when, and which addresses they contacted. The difference is not in the technology but in the incentive and in what can be verified.
- A free app. The income does not come from you, so the product is either your attention, or your data, or your traffic. The owner is often hidden.
- A paid service. The incentive is different and there is a reputation at stake. But the technical defects do not go anywhere: a 2022 study found leaks on connection drops in 26 of 80 desktop services tested.
- Your own server. The questions “who owns the app” and “what does it earn money on” disappear. In exchange, trust moves to the hosting provider, and the crowd your traffic blends into consists of you alone. The authors of a 2024 paper on an attack in which a neighbour on a shared VPN server can interfere with someone else’s connection recommend a private server for exactly this reason.
Liberum VPS is that third option: a separate server with your own access, rather than a shared free app. You can see how it works and what it costs in the Telegram bot — there is a free 7-day trial with no card required. If what you need is access to Russian services from abroad, there is a separate page for that: a VPN with a Russian IP.
How to read the promises
- “No-logs audit.” A check on a particular date, on selected servers, paid for by the service itself. An argument, but not proof of “we never store anything.”
- “Military-grade encryption.” A marketing phrase: the same algorithm protects any secure connection to your bank.
- “Complete anonymity.” What changes is the address a request comes from. A site still recognizes you by your login, your cookies and your browser settings.
- “Free forever.” The question is not generosity but which of the three income models is switched on. If none is named outright, then none is named.
The short version
- By the way the system is built, a VPN app receives all of a device’s traffic — trust here is not a metaphor.
- Measurements from 2016 and 2026 give a similar picture: trackers, requests leaking outside the tunnel, weak ciphers and advertising.
- The documented ways of making money: advertising and data, selling analytics, and selling users’ traffic itself.
- The promise “we keep no logs” has twice been disproved by leaks — one of a terabyte, one of 360 million records.
- Outwardly independent apps can be one family sharing keys, and the owner is usually unknown.
- Paying and running your own server change the incentive and remove some of the questions, but they do not remove the need to look at the technical detail.
Frequently asked questions
Is it true that free VPNs contain malware?
The wording is often distorted. In a 2016 study 38% of apps triggered at least one antivirus engine — but at a strict threshold of five engines, 4% remained. That is still a lot for a class of app you hand all your device traffic to, but “one in three is infected” is a misreading of the number.
What exactly does a free app earn money on?
Three models are documented: advertising and sharing data with ad networks, selling market analytics gathered from devices, and selling the traffic itself — when your phone becomes an exit node in someone else’s proxy network. Rates for the last one were measured in a 2021 study: about 50 thousand dollars a month to a developer per million active users.
Does the app store not check what it publishes?
It does, but the check covers the app, not the business model or the owner. Sensor Tower worked around store limits by asking people to install a root certificate from an external site; the apps in a 2025 investigation lived happily in the catalogues. The “independent security review” badge in Google Play is voluntary and reveals nothing about who owns the app.
Is a paid service automatically safer?
No. A 2022 study found traffic leaks on connection drops in 26 of 80 desktop services tested, most of them paid. Paying changes the economic incentive — you stop being the product — but it does not remove technical defects and does not make a service’s claims verifiable.
What is a no-logs audit and can it be trusted?
It is a check by an independent firm that, at a particular moment and on selected servers, no logs are kept. Its limits are clear: it is a snapshot on a date, the auditor is chosen and paid by the service itself, and the scope is set by the client. An audit is an argument, not proof of the phrase “we never store anything.”
How is your own server different from a shared service?
Two questions disappear: who owns the app and what it earns money on. Others appear in their place: trust moves to the hosting provider and the payment trail, and the crowd your traffic blends into consists of you alone. The authors of a 2024 paper on an attack against a shared VPN server recommend a private server precisely as protection from your neighbours on that server.
Get back into Russian services with LIBERUM VPS
A server in Russia and fast servers abroad in one subscription. The first 7 days are free, no card required.


