What teardowns of free VPN apps actually found — and why download counts told you nothing
An analysis of 281 Android VPN apps reported that more than 80% contacted advertising or tracking domains, some leaked traffic outside the tunnel, and some sent their own data unencrypted. Several had over 100 million installs. Here is what the research measured, what it did not, and which trust signals survive it.

Table of contents
Most people pick a mobile VPN the same way they pick anything else in an app store: a lot of downloads, a high star rating, and a green safety label on the listing. It is a reasonable instinct, and for this particular category it measures almost nothing that matters.
The reason is structural. Install counts measure popularity. Ratings measure whether the app worked and felt fast. The store's data-safety section measures what the developer declared about themselves. None of the three inspects where your traffic goes once the tunnel is up — which is the only question a VPN exists to answer.
Several groups have gone and looked. The findings are worth reading carefully, including the parts that are less damning than the headline.
The teardown of 281 Android VPN apps
The most widely cited figure, surfaced recently by AdGuard's security team, comes from an analysis of 281 Android VPN apps. Three findings stand out:
- More than 80% contacted advertising or tracking domains.
- Some allowed traffic to escape the VPN tunnel rather than routing all of it through the encrypted connection.
- Some transmitted their own data without encryption — not the user's browsing, but the app's own traffic, in the clear.
And the detail that reframes the rest: several of the apps involved have more than 100 million downloads. This is not a long tail of obscure software nobody uses. It is the mainstream of the category.
Two caveats, because they matter for how much weight to put on this. First, "contacted a tracking domain" is a broad finding — it covers an analytics SDK counting crashes as well as a genuine data-broker pipeline, and those are not equivalent. Second, the sample is free apps, chosen because that is where the problem was expected; it is not a random sample of all VPNs, and the percentage should not be read across to the paid market.
What survives both caveats is the second and third findings. Traffic escaping the tunnel is not a grey area — it is the product failing at its one job, silently, while the interface shows a connected state. That is the same class of failure we describe in how a kill switch works and where it doesn't: the dangerous case is not the visible disconnection but the invisible one.
The risk is not only in the tunnel — it's in the app
A separate study looked at around 800 free mobile VPNs and shifted the focus from the network to the device. It reported risky permission requests, missing or incomplete privacy disclosures, and apps technically capable of capturing screenshots.
This is the part people consistently under-weight. A VPN app is one of the most privileged things you can install: on Android it holds the system VPN permission, meaning every packet the device sends passes through it by design. Add microphone, camera, contacts or accessibility permissions on top of that, and the question is no longer whether the encryption is sound. The app does not need to break the tunnel to learn about you if it can read the phone directly.
So the practical check is duller than a protocol comparison and far more useful: open the app's permission list and ask what each entry is for. A VPN needs network access. It has a defensible reason to want notification access on some platforms. It does not need your microphone. If you cannot construct the sentence explaining why a permission exists, that is the finding.
When the free app is the product in a more literal sense
The most serious case is not tracking at all. Law enforcement has tied free VPN apps to residential proxy networks: software that quietly enrols the user's own device as an exit point, so that other people's traffic leaves the internet wearing your home IP address.
The mechanics are worth stating plainly, because the harm is not abstract. Bandwidth is resold to whoever pays. If that traffic is used for fraud, credential stuffing or worse, the address it came from is yours — and the first indication is usually not a security alert but your connection behaving strangely, or an account somewhere being blocked.
The documented case is 911 S5, dismantled by an international operation led by the US Justice Department in May 2024 and described by it as likely the largest residential proxy service ever run. The numbers are the point: more than 19 million IP addresses across over 190 countries, of which more than half a million were in the US. The DOJ names six free VPN apps built to connect devices to it — MaskVPN, DewVPN, PaladinVPN, ProxyGate, ShieldVPN and ShineVPN — and states that users who installed them became part of the botnet without knowing. Prosecutors linked the network's traffic to large-scale fraud, bomb threats and child exploitation material.
Nineteen million addresses is not a niche failure. It is a working distribution channel, and the delivery mechanism was an app store listing that looked like every other free VPN.
The user in that arrangement has not merely failed to gain privacy. They have taken on someone else's risk in exchange for a free download.
The economics were always the tell
None of this requires assuming malice, and that is the uncomfortable part. Running a VPN costs real money continuously: servers in each location, transit and bandwidth that scales directly with usage, plus engineering to keep clients working across OS updates.
Bandwidth is the killer, because it is the one cost that grows in proportion to how much people use the thing. A product with meaningful usage and no revenue is not a business; it is a countdown. When the money has to come from somewhere and it is not coming from users, the available options are advertising, data sharing, selling the connection itself, or cutting the costs that are invisible from the outside — audits, security engineering, log hygiene.
We set out the business models and a five-minute vetting routine in free VPNs in 2026: which are safe and which to avoid. The research above is the empirical version of that argument: it is what the "cutting corners elsewhere" option looks like when someone opens up 281 apps and measures it.
The signals that actually survive
If downloads, ratings and self-declared safety labels don't discriminate, three things still do:
- A paid product behind the free tier. It tells you where the revenue comes from, and it means degrading the free users' privacy would damage the paying business. This is the single most useful filter, and it costs nothing to check.
- An independent audit you can actually read. Not the word "audited" on a landing page — the report, its date, and its scope. We cover what a genuine one contains in what a no-logs audit really proves.
- A privacy policy that names things. Vague policies are not an accident of legal drafting; specifics create obligations. How to read a VPN privacy policy covers which clauses carry weight.
None of the three is a guarantee. All three are checkable in about five minutes, which is more than can be said for the star rating.
Where a free tier is still defensible
It would be too neat to end on "never use anything free", and it would also be wrong. A free tier from a company with a paid product, a published audit and a policy that says something is a fundamentally different object from a free app with no visible way of paying for itself — even though the store listing presents them identically.
AdGuard is one of the companies in the first group: an established paid business in ad blocking and DNS filtering, with a VPN that offers a free tier alongside the subscription. That does not exempt it from the checks above — the free tier still has data limits and fewer locations, and it is not automatically the fastest option, which is the sort of thing we get into in our AdGuard VPN review. But the question "who is paying for this" has a visible answer, and that is the distinction the research above is really about.
Bottom line
The uncomfortable finding is not that some free VPNs are bad. It is that the signals most people rely on — installs, ratings, store safety labels — are blind to the specific failure being measured, which is why apps with nine-figure download counts appear in these results.
Replace those signals with three questions: where does the revenue come from, has anyone independent checked the claims, and why does this app want that permission. They take five minutes, and unlike a star rating, they are actually about what the product does with your traffic.
Sources


