# Analysis of Nym VPN and its "guaranteed" privacy - Update: 10/09/26

**URL:** https://discuss.privacyguides.net/t/analysis-of-nym-vpn-and-its-guaranteed-privacy-update-10-09-26/38170
**Category:** General
**Tags:** providers
**Created:** 2026-05-27T21:36:32Z
**Posts:** 74

## Post 1 by @DanielM — 2026-05-27T21:36:32Z

Report completed - September 10, 2026: [Info update.](https://discuss.privacyguides.net/t/analysis-of-nym-vpn-and-its-guaranteed-privacy-update-29-07-26/38170/70)

Last updated 29/07/26 - Independent researcher vs. NymVPN:

> [@Analysis of Nym VPN and its "guaranteed" privacy - Update: 10/09/26](https://discuss.privacyguides.net/t/analysis-of-nym-vpn-and-its-guaranteed-privacy-update-25-07-26/38170/36):
>
> HARRY (CEO) PUBLICLY CONFESSES THAT “NO ONE CAN GUARANTEE THE ABSENCE OF LOGS” His lethal contradictions condemn the company itself with his own words, but, at the same time, he is telling the public the reality that something serious is happening internally within the company. What is happening? is a deep question, but I don’t have the fundamental data since I don’t have internal access to the company. Nevertheless, Harry and Alexis are two extremely contradictory individuals (both confessed …

Last updated 25/07/26 - Independent researcher vs. NymVPN:

> [@Analysis of Nym VPN and its "guaranteed" privacy - Update: 10/09/26](https://discuss.privacyguides.net/t/analysis-of-nym-vpn-and-its-guaranteed-privacy/38170/28):
>
> NYM HAS BEEN CAUGHT FOR THE SECOND TIME Previously, NYM had stated “Privacy Guaranteed,” but it turns out they changed it by hiding the word within the following box: Independently audited Annual audits and technical reviews ensure the network is transparent, secure, and log-free. -\> What they’ve done is build in a sophisticated trap, and instead of improving, the company is getting worse. Take the mafia, for example: if they defy what they call “impossible”—which is a huge lie—and somethin…

* * *

I decided to create a new, more direct thread based on the following:  
[https://discuss.privacyguides.net/t/nymvpn-nym/25085/46](https://discuss.privacyguides.net/t/nymvpn-nym/25085/46)

The point here is that I can’t find any real-world evidence backing up the company’s claims regarding their 5 nodes against high-level adversaries. I don’t want whitepapers or lab results; what I want is proof based on reality.

Does anyone in the community have this evidence so we can analyze it?

I left 5 questions for their support team on Telegram. No one has replied to my message, and I gave them a reasonable 5-day window so this wouldn’t drag on forever. If they don’t respond, it’s because they are hiding something.

A warning to those without experience: be careful with pretty words that lack any irrefutable backing.

**ANALYZING NYM’S ARGUMENTS**

A brief report citing public information.

**1 - Basic patterns detected:**

While our encryption standards are already extremely strong, we aim to make them post-quantum secure, staying ahead of emerging threats and ensuring digital privacy even in the face of evolving technology.  
Source: [https://nym.com/nymvpn-litepaper](https://nym.com/nymvpn-litepaper)

-\> The company trusts its encryption against new emerging threats, but forgets that high-level adversaries possess undisclosed, covert weapons.

c. not to engage in any actions aimed at manipulating network responses in a manner that could compromise the integrity and security of the Nym Mixnet or Nyx Blockchain.  
Source: [https://nym.com/operators-validators-terms](https://nym.com/operators-validators-terms)

-\> Asking node operators to comply with this is positive, but the NSA, for example, just laughs at Nym. Malicious actors (the NSA, the mafia, etc.) will ignore these rules and infiltrate the network, or are already infiltrated; each will operate according to their own agenda.

**2 - Advanced patterns detected:**

-\> Not applicable. It is not fundamental to this service.

**3 - Emerging dangers:**

Two words - Privacy “guaranteed”.

-\> There are high-level risks in placing blind trust in the Nym service without questioning it. People like me have absolute distrust toward Nym. What does this mean? The word “guaranteed” implies that privacy, in this context, is ensured 24/7, year-round, invisibly, just as Nym claims: “anonymous” based on 5 nodes. However, they forget that with even a single minor error, they will be held fully liable, directly contradicting their own Terms of Service.

Nodes run by “volunteers”.

-\> Nym pays people for their work and for operating their nodes so that users can obtain privacy benefits. However, this is an open invitation to greater risks from veteran hackers, the mafia, etc., not only to get easy money but also to carry out operations of higher interest. Even if the network is difficult for attackers or unfamiliar to them at first, they will learn how it works if it’s something new, and will stealthily counterattack.

**4 - Deep, multi-level reasoning:**

-\> Not applicable. It is not worth applying a higher level of analysis to this service.

-– —

I have not been able to find any real evidence backing up their use of the word “guaranteed” that proves the reality of their claims. Without actual, verifiable proof against high-level adversaries, such as those mentioned above, their arguments collapse under their own weight.

Warning: Any company that uses arguments like → “guaranteed privacy”, “guaranteed math”, “we guarantee you…”, etc., and similar phrases, is just using marketing with no basis in real-world facts.

So far, no one has replied to my message on Telegram, but they haven’t deleted it either. The CEO is right there answering basic messages from other people.

---

## Post 2 by @anon7180143 — 2026-05-27T22:12:02Z

Am I the only one or do others feel this post is very passive aggressive and that OP is writing this as saying (claiming) all that they are as if they’re the authority on the subject matter?

If you are the authority, then you’d have the maturity to even better and fully explain your claims and statements with how the tech works in more simpler ways as one who is trying to educate and not one who is trying to “get” a company in a lie without proper and more detailed explanation.

There’s an etiquette involved here which I feel you’re ignoring willingly or unknowingly.

---

## Post 3 by @byesun — 2026-05-27T22:19:12Z

What “proof” are you even expecting?

Based on your comments in the other thread, you seem to be expecting some miracle solution that is both capable of providing anonymity while also being very fast. Like, transferring an 8 GB file over any network like this is gonna be slow.

Also, if this is how you wrote to their support, I’m not surprised they’re ignoring you.

---

## Post 4 by @Shampoo — 2026-05-27T22:53:02Z

I came here expecting an exciting write up about cryptography. I got a rant instead. I’m disappointed.

---

## Post 5 by @anonymous549 — 2026-05-27T22:53:09Z

> [@anon7180143](#):
>
> Am I the only one or do others feel this post is very passive aggressive

It reads like OP has made up their mind and is just looking for confirmation. I would call this ‘adversarial skepticism’. :grinning_face_with_smiling_eyes:

---

## Post 6 by @DanielM — 2026-05-27T23:20:47Z

@anon7180143 :

Are you attacking me personally, or are you trying to figure out if Nym is lying or not?  
If I were to explain it in deep, exhaustive detail, who would even read it? They’d ask for a summary, and I don’t do summaries.

@byesun :

So, you’re basically proving my point. If Nym can’t back it up when it’s a matter of life and death, their use of the word “guaranteed” is just hot air. Besides, it’s completely valid to ask tough questions, and they’re entirely justified because fear isn’t an option. And the fact that I was direct about it in public so everyone could see it isn’t something I just made up.

@Shampoo :

The one who has to prove it based on real-world facts is the company Nym, not me, since they’re the ones claiming it’s “guaranteed.”

---

## Post 7 by @byesun — 2026-05-28T00:05:48Z

This isn’t a “tough question,” it’s a meaningless question. “What if I need to send 3 TB to someone in 5 seconds? I thought my privacy was GUARANTEED! ! !”

In any case, the performance of the mixnet is poor. They’ve stated this themselves many times, and it’s something they’re working on improving. That does not mean it’s somehow not private. If you yourself choose to swap from the mixnet to the two-hop WireGuard setting, _you_ are the one choosing to reduce your privacy in exchange for a faster transfer rate.

Whether there are enough nodes and whether they are decentralized enough is another story. Maybe they are, maybe they aren’t. But the way you’ve gone about this is ridiculous.

---

## Post 8 by @Shampoo — 2026-05-28T00:36:00Z

> [@DanielM](#):
>
> The one who has to prove it based on real-world facts is the company Nym, not me, since they’re the ones claiming it’s “guaranteed.”

Burden of proof is on the accuser. Even more so in situations like this.

---

## Post 9 by @Bumbashirovich — 2026-05-28T01:16:47Z

Well, in a sense, they guarantee that they use cutting-edge technologies: far more advanced than those listed in the Privacy Guides’ recommendations (for example, the Amnezia 2.0 protocol). The fact that the NSA can control most nodes doesn’t depend specifically on this provider; it affects all market participants. Don’t use nodes in jurisdictions that are easily controlled from the U.S.

---

## Post 11 by @anon7180143 — 2026-05-28T07:19:08Z

I think OP is looking for confirmation bias\*

---

## Post 12 by @object2598 — 2026-05-28T07:46:50Z

Glad i’m not the only one who noticed the tone and ignorance. I was going to explain the “questions” he had on the nym thread but figured i’d just be losing time considering the mindset of OP here.

---

## Post 13 by @DanielM — 2026-05-28T14:54:19Z

@byesun :

So, you’re basically implying it yourself between the lines. Ask yourself: what is that word “guaranteed” even doing there? Do you realize the danger of that word, then? Skimming it on a surface level is all well and good, but it goes so much deeper than that. I invite you to revisit point 3 and really analyze it.

@Bumbashirovich :

If that were the case, the Nym team would have told me in under an hour on Telegram, right in their own group, just like you’re explaining its meaning to me now. Why are they still silent, then? Don’t ignore the other high-level threats, either—the NSA is one thing, but there are plenty of others in different countries. Read the context and study it.

@object2598 :

If you know the “answers,” why don’t you just say so directly? Go ahead, I’m all ears. Do you work for Nym? Post it on Telegram along with your “answers” and I’ll read it, because if you were actually on the Nym team, you would have replied to me there.

---

## Post 14 by @anonymous549 — 2026-05-28T15:09:58Z

> [@DanielM](#):
>
> If you know the “answers,” why don’t you just say so directly? Go ahead, I’m all ears.

What are you talking about? I said nothing about answers — my only comment on your post was about how adversarial your tone was, which hasn’t changed in any of your replies. I’m not surprised: every time I’ve interacted with you, you seem to start hostile and become more so.

---

## Post 16 by @DanielM — 2026-05-28T15:49:22Z

Sorry, that message wasn’t meant for you; it was for the other person. I made a mistake and I own it.

Let me fix that now.

---

## Post 17 by @privacy.slouchy — 2026-05-28T16:29:46Z

> [@DanielM](#):
>
> I can’t find any real-world evidence backing up the company’s claims regarding their 5 nodes against high-level adversaries. I don’t want whitepapers or lab results; what I want is proof based on reality

This is a reasonable goal. Let’s see what we can do

> [@DanielM](#):
>
> If they don’t respond, it’s because they are hiding something.

This is a bold accusation based on no evidence of wrongdoing. I operate on zero-trust: I will assume any service provider _could_ be compromised, but I stop short of baseless accusations

> [@DanielM](#):
>
> but forgets that high-level adversaries possess undisclosed, covert weapons

FUD. We threat model against evidence-backed threat vectors. Mitigations against undefined, hypothetical threats are not practical

> [@DanielM](#):
>
> Malicious actors (the NSA, the mafia, etc.) will ignore these rules and infiltrate the network, or are already infiltrated; each will operate according to their own agenda.

Wise. This is zero-trust architecture. Assume bad actors can/will penetrate wherever possible

> [@DanielM](#):
>
> **2 - Advanced patterns detected:**
> 
> → Not applicable. It is not fundamental to this service.

Disagree. [Traffic analysis is an emerging threat vector](https://mullvad.net/en/blog/introducing-defense-against-ai-guided-traffic-analysis-daita). Providers like Mulvad are beginning to design mitigation techniques. I assume the intent here is similar

> [@DanielM](#):
>
> **3 - Emerging dangers:**
> 
> Two words - Privacy “guaranteed”.

You argument here just seems to be a pedantic case against the word “guaranteed”. I do ultimately agree with your premise, but don’t feel it’s a meaningful indicator of their actual services

> [@DanielM](#):
>
> Nodes run by “volunteers”.

> [@DanielM](#):
>
> Even if the network is difficult for attackers or unfamiliar to them at first, they will learn how it works if it’s something new, and will stealthily counterattack

We’re back to zero-trust architecture. Good stuff. This is almost identical to issues Tor faces - users can maintain anonymity if a node is compromised, but it becomes difficult to do anything if the whole volunteer node network is assumed to be hostile

> [@DanielM](#):
>
> **4 - Deep, multi-level reasoning:**
> 
> → Not applicable. It is not worth applying a higher level of analysis to this service

I think this is rehashing the same emerging mitigation techniques as section 2

\_\_\_\_\_\_\_

So far as ‘proof’ goes, it does looknas though they’ve been audited a couple times. For example, I found the [Cure53](https://cure53.de/audit-report_nym.pdf) report here. These are probably a good starting point for assessing the tech

---

## Post 18 by @byesun — 2026-05-28T22:04:43Z

As the other user mentioned, the entire basis of this point is a pedantic freak out over the meaning of the word “guaranteed.” Your argument for them being untrustworthy because of this is just dumb.

Since you didn’t source where that quote comes from, it comes from their home page. It’s a section header at the bottom of the page where they list their audits. The “guaranteed” here is referring to the audits “guaranteeing” that their service does what it says it does as far as the auditors can tell.

> However, they forget that with even a single minor error, they will be held fully liable, directly contradicting their own Terms of Service.

This applies to nearly every internet-facing (and often non-internet-facing) service. If they have an exploitable bug and their system is compromised, whoops, all your data has been siphoned off. It is not the insightful point you seem to believe it is.

---

## Post 19 by @DanielM — 2026-05-29T00:09:13Z

@privacy.slouchy :

Alright, straight to the point:

1 - When you ask a company a hard-hitting question about a matter of life and death for someone being hunted, why do they stay silent?  
2 - It’s not “FUB.” That’s what they want you to believe based on “lab” tests, but not in a real-world war in the world we actually live in (and that includes the digital realm).  
3 - You tell me you disagree with what I said, but it turns out points 2 and 4 are different. And to top it off, point 1 and the two dangers mentioned are more than enough. There’s no need to create an exhaustive list.  
4 - You dismiss a scenario as “pedantic” while simultaneously telling me you agree with me. Why the contradiction? Do you have any idea how much weight that word “guaranteed” carries? Take point 1, for example.  
5 - You made a good point about zero trust, but I have a fundamental question for you: will an audit save the life of someone being hunted, like I mentioned earlier?

@byesun :

You interpret it as “panic,” but it isn’t, and it isn’t “pedantic” either. So, you’re basically proving my point—are you even aware of that? And it’s not just about what you’re saying; it applies across the board: → Privacy ← “result: guaranteed.” If there’s even the slightest security flaw while that word “guaranteed” is being thrown around, the hunted person dies trusting the tool, despite having decent OpSec. Is the company liable? The answer is yes, and the family would have every right to sue the company for false and unethical advertising. Do you get now just how heavy that word is? I invite you to play detective, to connect the dots and dig deep. Don’t just settle for the surface level—dig into the depths, and if you keep learning, you’ll understand way more than what it literally means.

* * *

A little invitation for you both: if you didn’t already know, look up a bit of history on Edward Snowden and the Lavabit email service.

My intention is simple: to protect people who lack knowledge and don’t know how to defend themselves, by demonstrating in just a few words that Nym’s company must be honest and remove the word “guaranteed” if it is truly honest.

---

## Post 20 by @byesun — 2026-05-29T01:15:33Z

> I invite you to play detective, to connect the dots and dig deep. Don’t just settle for the surface level—dig into the depths, and if you keep learning, you’ll understand way more than what it literally means.

Amazingly condescending. As expected of someone spreading FUD.

> If there’s even the slightest security flaw while that word “guaranteed” is being thrown around, the hunted person dies trusting the tool, despite having decent OpSec.

If you have decent OpSec, you would actually look into the tool you’re using rather than taking a phrase used in a random section header on a page filled with marketing speak at face value. Especially given that there are two modes, one of which is very clearly meant to be more private than the other. Literally even discussed on the same page the “privacy guaranteed” section header is located, in a more prominent section near the top of the page.

---

## Post 21 by @DanielM — 2026-05-29T16:19:09Z

_ **I AM CLOSING THIS MATTER, AND HERE ARE THE RESULTS REGARDING NYM VPN:** _

Nym has proven they have no intention of answering my hard-hitting questions. So, I’m going to answer my own questions based on reality:

1 - Two words pop up: “guaranteed” privacy. How exactly do they guarantee it, against whom (adversaries, for example), in what way, and what is their actual method?

→ Anyone with at least a basic understanding will realize that protection against your Internet Service Provider (ISP), websites, and other common threats gives you privacy to a certain extent. However, while Nym’s official website acknowledges their limitations, they heavily inflate their claims, just as I demonstrated in point 1.

Search your preferred search engine for the following terms: United States “Top Secret,” what it is, and what it means.

That will give you a much better idea of what I mean by “hidden weapons.” And don’t just limit it to the United States—look into the capabilities of other countries as well.

2 - How does Nym defend against adversaries like the US NSA when it comes to adapting to or outpacing their methods targeting the VPN service?

→ This answer is far too complex. I can’t answer something when I don’t have internal data from Nym itself. Therefore, I’m not going to make anything up here.

3 - How does Nym protect legitimate users of their services from infiltrations via seemingly “legitimate” nodes? What are their methods, and how do they handle this? For example: the mafia, veteran hackers, etc.

→ In the official documents on their website, there isn’t much clear and precise information about these kinds of situations. Therefore, this massive responsibility falls entirely on the company.

4 - Which option would you advise (2 nodes or 5 nodes) in a life-or-death situation involving persecution, when someone needs to send an encrypted, compressed 8GB file to the person being hunted? Is it just a matter of “luck”?

→ The people at Nym who understand this question know that if they answer and make a mistake, the public will come down on them and they’ll face lawsuits. The reality is that this is a test for them, but I wanted to see if they were capable of facing reality or if they would just blindly trust the “math” 100%. Logically, both modes come down to luck, not certainty.

5 - If the answers to all the previous questions are positive, do you have real-world proof against legitimate, real-world scenarios for the public?  
I need you to convince me with real evidence, because whoever claims something is “guaranteed” must be absolutely sure that what they’re saying is true.

→ This is the ultimate challenge for any VPN company. Lawyers who understand these questions, know what they mean, and have knowledge based on real-world facts will tell you that irrefutable proof simply doesn’t exist. They are, therefore, probabilities, not a “guaranteed” reality.

* * *

**Deep dive into the word “guaranteed” in the context of the report and the questions:**

- They cannot guarantee optimal protection, because high-level adversaries never rest.
- They cannot guarantee that the nodes aren’t logging most or all of your internet traffic data. A novice adversary could map all the public IPs of the nodes, build malware, and exploit unknown vulnerabilities in the software—even with the help of AI. Clear evidence: [VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun - Check Point Research](https://research.checkpoint.com/2026/voidlink-early-ai-generated-malware-framework/)
- Nym cannot guarantee your actual survival (life or death) when you’re being hunted on both fronts: real life and the internet. Their technology is based on probabilities, not certainties. This is where luck comes into play.
- Vulnerable people are easily deceived because they don’t know what’s behind that word, “guaranteed.” Nym’s true intentions are unknown, but it’s highly suspicious.
- The 5-node “anonymous” mode is basic because it doesn’t cover complex situations. For a critical researcher, it might work for text messaging and some lightweight files, but not for high-demand investigations that require digging into long videos, sharing large files with colleagues, etc. Instead of the researcher working smoothly, it requires immense patience and wastes crucial time—time that, most of the time, you just don’t have because you need to take active action in a world that doesn’t stand still.

**Recommendations for the company Nym:**

- Be honest and humble. Your company is on the line by throwing around the word “guaranteed” so prominently, which ultimately sinks it. Sometimes, companies or the people in charge don’t learn until disaster strikes and someone says, “I told you so, and you didn’t listen.” That is, assuming they actually want to learn and fix their mistakes instead of just shutting the company down completely.
- Your project looks good on the surface, but you need to be able to answer tough questions and demonstrate real, transparent actions. I know the unvarnished truth hurts, but adversaries show no mercy when they decide to strike—it’s a whole different ballgame.

**Recommendations for people’s:**

- Before buying, research and analyze the official website. Don’t rely on “review” sites, because they commonly use exaggerated advertising tactics.
- Be critical: What is the website claiming? Does it benefit me? Is it optimal? Will the company defend me in critical situations? What do the terms of service, including the privacy policy, actually say? Apply and analyze their words. If there’s something you don’t know, look it up. You can also ask questions if you want.

Now, people have to make a decision. I tried to make it as easy as possible—turning the complex into the simple—to help those who lack basic IT knowledge in these privacy and security areas.

---

## Post 22 by @DanielM — 2026-06-07T21:57:02Z

**MY ARGUMENTS AND THOSE OF THE CEO AND ADMINISTRATOR OF THE NYM TELEGRAM GROUP**

I compiled the messages as texts, not screenshots. I organized them to be clear and easy to understand, without any beating around the bush.

The most interesting thing, within Nym’s own sphere of influence, is that the administrator started attacking me. What did I do? I used his own arguments against him and at the same time pointed out that he was contradicting the word “guaranteed,” which Nym itself claims to uphold.

Here are the messages:

> **Arguments.**
>
> - **My message** :
> 
> Is no one going to answer my legitimate questions?
> 
> - **CEO** Harry Nym:
> 
> I don’t speak Spanish but I can guess. In effect, there are no 100 percent guarantees in security and anonymity, but due to adding fake traffic and mixing traffic Nym is the only VPN that protects against a global adversary like the NSA or Palatir. To use that, you must use 5 hop mode.
> 
> - ( **Yo** ):
> 
> Why guess? Use a translator like I do; it’s the only way I can understand anything in other languages.
> 
> If it’s the only way, do you have irrefutable proof based on real facts?
> 
> - **Admin** - Salazar:
> 
> Translators are not 100% accurate; have you had the chance to read through the whitepaper? Everything the mixnet does is explained pretty thoroughly here:
> 
> [https://nym.com/nym-whitepaper.pdf](https://nym.com/nym-whitepaper.pdf)
> 
> Section 4 fyi
> 
> - ( **Yo** ) :
> 
> I know it’s not 100%, so why is the website multilingual? It’s strange.
> 
> The white paper doesn’t help me; it’s not irrefutable proof. What I’m looking for is based on the “guaranteed” privacy, as argued on Nym’s official website as irrefutable proof of how well it actually protects users in real-world situations.
> 
> Based on real-world experiences is what I need, and after searching the official website to a certain extent, I haven’t found it.
> 
> If you have it, could you share it with me?
> 
> That’s why it’s important to understand the questions I posted earlier in Spanish, unless the company has people who can translate accurately into English.
> 
> - **People** @Ch1ffr3punk:
> 
> I think the privacy and anonymity aspect, same as with Tor, comes to the point if you use it with the right software clients and Nym components properly. This is not much discussed, because the Nym team focuses primarily on the Network infrastructure and NymVPN app and there are no use cases or tutorials from them availabe how to properly protect Nym users, from various threats.
> 
> - **Admin** :
> 
> Real-world protection can’t be absolute (same as it’d be for any other VPNs). It depends on what you’re up against, your device’s security, and some factors outside Nym’s control, like @Ch1ffr3punk said. If you’re looking for case studies, those simply don’t exist but do let us know if you come across any other VPNs you that have published content like this.
> 
> What Nym does guarantee is strong technicals. Anonymous mode(Mixnet+cover traffic+timed delays) is designed to resist traffic analysis in ways a standard VPN cannot. The code is open source, and backed by academic research. All papers and audits are available on the trust centre: [Trust Center | Nym](https://nym.com/trust-center)
> 
> - ( **Yo** ):
> 
> So, if they “guarantee” it, as you’ve said, how do they back up that argument in real-life situations of harassment on both sides: in real life and online?
> 
> Because, for example, does someone who genuinely needs a VPN tool in an emergency “guarantee” it?
> 
> - **People** :
> 
> I like to make a little proposal. Maybe the (external) :houses: Advisors, like Chelsea, DJB etc. can in the future show us some protection examples, when it comes to Online Privacy/Anonymity, similar to what EFF and others do with their tutorials.
> 
> - **Admin** :
> 
> It’d depend on the particular cases - there are n number of possibilities regarding how your anonymity could be compromised. For example, Nym or any other VPNs can’t protect you from a compromised device, logging into websites that already know who you’re, browser fingerprinting etc. the protection is for the network layer only and nowhere on the website/the documentation do we claim otherwise
> 
> - ( **Yo** ) :
> 
> I’m aware of the example you gave, so here’s my recommendation for Nym:
> 
> If you don’t have real proof, replace the word “guaranteed” with something you can actually demonstrate.
> 
> Be humble and honest, then.
> 
> Remember that there are threats like APTs (Advanced Persistent Threats), etc.
> 
> Furthermore, it would be interesting if you published a document explaining how Nym protects legitimate users (if any exist) of your service against infiltrations using “sham” nodes—in other words, veteran hackers, organized crime, etc.—who infiltrate to carry out their activities silently.
> 
> - **Admin** :
> 
> Your comments sound increasingly hostile for what wasn’t a false claim to begin with. Network level privacy is what Nym is for. Nowhere on the website is it advertised as a one-button magic solution that makes you anonymous instantly.
> 
> It does look like you’ve made up your mind/just want to spread FUD here as I saw your thread of privacy guides too (Lots of them commenters tried to explain it to you, and we’d be happy to respond there but you’ve closed the thread since :sweat_smile:)
> 
> [Analysis of Nym VPN and its "guaranteed" privacy](https://discuss.privacyguides.net/t/analysis-of-nym-vpn-and-its-guaranteed-privacy/38170)
> 
> that said, this​:backhand_index_pointing_up: does sound like a cool idea to give nymsters guides for good privacy practices/setups in general
> 
> Regarding this, Nym’s research does not assume all nodes are honest. and there’s plenty of theoritical proof to support that a full-scale compromise of the network can’t be accomplished under real work circumstances.
> 
> If you’d like to read through the documentation that supports these claims, you can read through the papers from our research team [here](https://nym.com/trust-center/papers-and-research). Listing some sections below that’ll be relevant:
> 
> - Nym whitepaper (section 4, 6)
> 
> - Reward Sharing for Mixnets: pg 16 sybil resilience discussion
> 
> - The Loopix Anonymity System: 3.2 Format, Paths and Cover Traffic
> 
> - The Loopix Anonymity System: 4.2 Active-attack Resistance
> 
> - **(Yo**) :
> 
> Who are you afraid of? It’s not what you’re accusing me of, and it’s strange that someone with the title of administrator would behave this way.
> 
> Go ahead, if you’re willing to respond in the forum, I won’t stop you. But what is clear is that an administrator has accused me of something I haven’t claimed.
> 
> I never said anything about being “magical.” You yourself are demonstrating in your messages that they contradict the word “guarantee” and the company that claims to offer it. Whether you’re doing so consciously or unconsciously.
> 
> So, if it’s “theoretical,” it means it’s “luck,” and in the argument in session 2 of the PDF security file, you use the word “probabilities.”
> 
> File mentioned:  
> [Are continuous stop-and-go mixnets provably secure?](https://eprint.iacr.org/2023/1311)
> 
> Published: Proceedings on Privacy Enhancing Technologies (PoPETs)
> 
> Date: 2024
> 
> Authors: Debajyoti Das, Claudia Diaz, Aggelos Kiayias, Thomas Zacharias
> 
> * * *
> 
> To use the word “guaranteed,” regardless of the industry—privacy, security, food, etc.—requires irrefutable proof based on real-world facts, not laboratory experiments or paperwork.
> 
> Therefore, if there is no real proof, then, as I stated in the thread you shared, it’s “luck,” and the more luck, the lower the “probabilities.”
> 
> I offered my recommendation; if the company decides to accept it, great, but if not, it’s already mentioned in the forum thread.
> 
> Furthermore, the server can be attacked by an APT from within or without. If the server is hacked and the attacker can see the work being done—for example, just one instance—the “guarantee” is false, and it’s not the fault of the legitimate user.
> 
> That concludes my message. My questions remain unanswered; if the Nym team decides to respond, great.
> 
> - **Silence. No more answers.**

The company has to make a decision; I’ve already done my part.

Those who decide to buy the service and stay, I won’t stop them, but they need to know something fundamental:

→ I completely reject the system Nym uses for cryptocurrencies (and cryptocurrencies in general), and I don’t trust the company at all. Why and how? I don’t like the aforementioned system; I prefer simplicity, and it’s not a suitable tool for me. I’ve already mentioned this throughout the report (above) and here (below).

Beware of pretty words.

And if the company ever decides to answer my questions… then I could see their arguments and make a decision.

---

## Post 23 by @Bumbashirovich — 2026-06-08T00:54:30Z

This is a pointless discussion that keeps circling back to the issue of guarantees. You’re essentially giving the provider free publicity by pushing it to the top of the Privacy Guides forum. If readers visit this thread, they’re very likely to go to the official website and find the services they might need.

---

## Post 24 by @JohnDose — 2026-06-08T04:29:49Z

Maybe this is how viral marketing works in 2026 lol

---

## Post 25 by @foolclown — 2026-07-19T05:09:22Z

Anyway so I just went and signed up for their service. I think their responses are 100% solid. Moreover, they have shown a lot of patience towards OPs incoherent ranting, which means the customer service should be top tier, as well.

So yeah, I guess this _is_ 2026 marketing doing its job.

---

## Post 26 by @DanielM — 2026-07-19T12:51:05Z

That’s very common in industries.

In this context, it generally covers what I’ve been talking about, not just “warranty.”

“Advertising”: This isn’t free advertising on my part—it’s the opposite; it’s advertising for the forum.

However, when you confront a company by questioning its vulnerabilities, what happens? The outcome varies.

Here are some questions to analyze these companies more thoroughly (depending on the person’s ability):

1. It’s not about whether it’s true or false (“binary”); it’s: Do they mix truth with lies?

2. It’s not about whether their words sound nice; it’s about whether they have irrefutable evidence for their claims based on real facts? ← This is one of the most challenging questions for any industry, regardless of category.

3. It’s not about whether it’s safe; it’s about: What are they hiding behind their actions that aren’t visible to the public? ← It seems like a simple question, but in reality, it goes beyond “complex.”

4. … (continued).

A concrete example: A company claims that one of its products is “state-of-the-art.”

What do I do? It’s very simple: I take those words—“product” and “generation”—compare them with the rest of the industries across different categories (whether online or in real life), and see that it’s nothing special. Free advertising, at the very least…

It’s very simple for me because I already know how they operate.

If anyone is interested in learning more, start an off-topic thread and I’ll help you out.

---

## Post 28 by @DanielM — 2026-07-25T21:52:28Z

**NYM HAS BEEN CAUGHT FOR THE SECOND TIME**

Previously, NYM had stated “Privacy Guaranteed,” but it turns out they changed it by hiding the word within the following box:

_Independently audited  
Annual audits and technical reviews ensure the network is transparent, secure, and log-free._

-\> What they’ve done is build in a sophisticated trap, and instead of improving, the company is getting worse.  
Take the mafia, for example: if they defy what they call “impossible”—which is a huge lie—and something happens to a person with a family while using their VPN service, that family can legally sue NymVPN.

When people eventually decide to realize how these companies operate behind their rhetoric, they’ll run away, and Web 3.0 will decline drastically.

The latest messages from Carsey Ford (admin) and Alexis (COO and co-founder) tried to draw me into a game of cat and mouse. It’s their responsibility, not mine, and I’ve been quite clear in my messages.

Below is the latest update and the real battle—but with a clear warning to the company:

- **(Yo) DanielM:**

@harryhalpinharryhalpin

Greetings.

I’m reaching out to ask for an update on whether the information on your website is currently accurate or if it has been altered for another purpose without your knowledge.

The phrase “privacy guaranteed” no longer appears on your English-language website; it now reads as follows:

Independently audited  
Annual audits and technical reviews ensure the network is transparent, secure, and log-free.

Is this correct, or is there another intention behind it?

- **CEO Harry:**

I didn’t remove that phase but maybe @sallysundriesur editor @sallysundries did as I suspect it was written by (our now departed) previous marketing people. However, privacy is a holistic property of a system, it can never be guaranteed like security can.

- **Casey Ford (Admin):**

“Independently audited  
Annual audits and technical reviews ensure the network is transparent, secure, and log-free.”

Is correct. The change was made to be honest with our users about the specifics of how Nym protects you concretely rather than through marketing claims. The guarantee is a network that can’t log your full traffic by design.

- **CEO Harry:**

An explanation by me is here - see Section 3 [https://www.ndss-symposium.org/wp-content/uploads/usec2021\_23007\_paper.pdf](https://www.ndss-symposium.org/wp-content/uploads/usec2021_23007_paper.pdf)

However, we CAN guarantee security claims via formal verification and we will have an exciting blog post on that today, as we are now formally verifying our core code.

For an explanation of formal verification by myself, see here: [Making sure you're not a bot!](https://inria.hal.science/hal-01673294/docum@harryhalpinnt)

- **(Yo) DanielM:**

@harryhalpin @sallysundries

I’ve analyzed your arguments to a certain depth (not exhaustively). Before continuing, I’m letting you know up front that I didn’t come here to be gifted a license (dVPN), a job, validation, etc. I came to find the truth behind what is “superficial” within the company, not to destroy it, but to show that the advertising is bigger than what you claim.

Harry, I understand what you’re saying and I’ve read some of your messages when you mentioned those cases here in your Telegram group.  
The new claim has a sophisticated trap (probably the person who made the change doesn’t know it) and it is the following:

- It explicitly guarantees the following words, literally covering 3: transparent, secure, and log-free. However, guaranteeing security and no logs also encompasses privacy; without the previous two, there is zero privacy.  
There’s the real trap, the word privacy is hidden, not implicit.

On top of that, that new argument raises even more suspicion and doubts about the company itself.

I ask you the following questions:

1. Why don’t you permanently remove the word “guaranteed” and be more honest?
2. Suppose you insist on keeping that word, what will you do when it fails one day? Will you be ready to face real lawsuits if they file them?
3. I’m still interested: how does the company Nym defend legitimate people against real adversaries when they use the nodes? Will it be the fault of the person using the service, as Nym’s terms claim, if something serious happens?
4. …

In the following URL: [NymVPN Litepaper: Decentralized VPN & Mixnet Privacy | Nym](https://nym.com/nymvpn-litepaper)  
There are many claims in relation to it…

Note: I will copy and paste the messages into the Privacy Guides forum so that people know more information about the company itself.

- **Casey Ford (Admin):**

I’m not sure I understand, so feel free to clarify if I am not answering your question properly.

We have removed the word “guaranteed” from our landing page where it originally appeared as a marketing claim from a previous employee as “Privacy guaranteed,” referring to our policy of conducting independent, external audits of our services.

The reason we removed it was because we felt this wasn’t a good use of language. Privacy is not something that can be “guaranteed” by any one service. For example, while NymVPN can help protect your privacy at the network routing level, it can’t stop you from deanonymizing yourself some other way, or stop all forms of surveillance.

Ultimately, the edit on the website pertains to that particular section of the landing page. What is currently claimed accurately is that:

1. Nym is committed to performing audits of our apps and code by independent, external researchers and security firms so that they are continually improved for users’ privacy.
2. That the code remains fully open source so that it can be verified as doing what we claim it does
3. And that the decentralized network is designed so that **Nym never has access to your traffic at all** , and node operators **never have access to the full route your traffic takes**. This makes full logs impossible to be collected from any single point. This is a network design, not a marketing promise.

I’m happy to explain any part of the Nym system or marketing claims if you have specific questions! Just drop them here.

Our goal is honesty and transparency and education, so if you do find claims that are inaccurate, we’ll definitely investigate and correct if needed. Many of us are academics, we’re use to it! :wink:

- **(Yo) DanielM:**

Is the man named Alexis Roussel on your team aware of this serious problem? According to Nym’s official source, Alexis is Nym’s COO and co-founder.

This sophisticated scam reveals that the company itself is not internally aligned, and your behavior speaks volumes. It is, therefore, highly suspicious and actionable (a family could sue Nym for false advertising and deception if something happens to them due to real adversaries through its network). This covers any “threat model” regardless of the level.  
Didn’t your lawyers tell you this?

You say you’re willing to explain it to me, but I asked questions about Nym and everything surrounding it—how do you explain it to me? The questions remain unanswered.

Be truly humble and honest.

Harry: Are you aware of this issue, since you’re the CEO?

- **Alexis Roussel (COO Nym):**

Not sure what you are trying to say, but the wording on the website is correct.

- **(Yo) DanielM:**

If that’s true for Alexis, then in the future they won’t be able to say, “Nobody told me.”

- **Casey Ford (Admin):**

We are not understanding you at all. :woman_shrugging:t2:

- **Alexis Roussel (COO Nym):**

Yep. Sorry we don’t understand.

Maybe you can be more specific or detailed?

* * *

_ **End of messages.** _

_Keep the following in mind:_ NymVPN has no real evidence against real adversaries; it’s all just probabilities, which means → luck. Regardless of the level of the “threat model.”

If something happens to you while using NymVPN, remember what’s been said here.

---

## Post 29 by @byesun — 2026-07-26T08:11:24Z

> [@DanielM](#):
>
> The new claim has a sophisticated trap (probably the person who made the change doesn’t know it) and it is the following:
> 
> - It explicitly guarantees the following words, literally covering 3: transparent, secure, and log-free. However, guaranteeing security and no logs also encompasses privacy; without the previous two, there is zero privacy.  
> There’s the real trap, the word privacy is hidden, not implicit.

Your logic is just fundamentally wrong. Stating you have two properties A and B that potentially contribute to C does not inherently mean or imply you have property C.

They are claiming that their service is secure and log-free. They are not claiming that they can ensure privacy, and they explicitly said that in the chat logs you posted.

Your focus on this one section at the bottom of the page is also just extremely bizarre.

---

## Post 36 by @DanielM — 2026-07-30T00:48:46Z

**HARRY (CEO) PUBLICLY CONFESSES THAT “NO ONE CAN GUARANTEE THE ABSENCE OF LOGS”**

His lethal contradictions condemn the company itself with his own words, but, at the same time, he is telling the public the reality that something serious is happening internally within the company.

What is happening? is a deep question, but I don’t have the fundamental data since I don’t have internal access to the company. Nevertheless, Harry and Alexis are two extremely contradictory individuals (both confessed publicly).

Possible strange question: Is this a game, or is what’s happening actually serious?  
I’m inclined to believe it’s real.

The website has heavily inflated and highly deceptive advertising, not just in one single place called a “guarantee.”

Unfortunately, I haven’t been able to find that “person” right now who, according to Harry, was expelled, in order to get their testimony. It’s highly likely that this person doesn’t exist; it must be an excuse to make people believe in something that currently has no basis. Does a person exist or not? With so many contradictions between the Nym team and its website, suspicions are extremely high.

They kicked me out of their Telegram group; on the one hand it’s better, because it reveals more of what they say.

Casey Ford (Admin) replied to me when I responded to Harry, but I ignored him; it’s just noise now. I don’t know if he’s aware of, or oblivious to, the true knowledge of the military’s technological force regarding its advancement and what exists in private (not visible to the public).

_Below are the messages between Harry and me:_

- **Harry (CEO Nym):**

No one can guarantee zero logs and anyone that says they are “guaranteeing” zero logs and so forth is lying. A adversary can easily log information such as timing and volume WITHOUT even having to compromise a machine. Nym solves that by decentralization and adding fake traffic/timing delays (i.e. mixing). Also, for any centralized VPN, a govt. can force a backdoor (and even make it illegal to talk about it or ask a lawyer, see FISA national security letters and the Nick Merrill case).I have no idea what you mean about “new claim” but technology isn’t magic, however, we do think we do a better job than any centralized VPN or even Tor in defending our claims technically. As for word choice issues by our marketing people, we fired the guy that wrote some of it as he wasn’t very good, and @sallysundries can sift in. If anyone wants to run a node, they surely can - that’s decentralization. No one needs a license. That being said, if you don’t want to run one and aren’t comfortable with the legal risk don’t run one.

To repeat: Privacy is a holistic property. Transparency is gained by looking at source code, compiling it yourself, and so on. In terms of security, it’s always relative to an adversary, and Nym and mixnets in general are built to combat a global passive adversary that watches every packet and records it. Others may think this adversary is unrealistic. See here: [https://academic.oup.com/cybersecurity/article/11/1/tyaf006/8097877](https://academic.oup.com/cybersecurity/article/11/1/tyaf006/8097877)

- **Yo (DanielM):**

Exactly, and your website says the opposite about the logs—why didn’t Casey update it at the time when he removed the rest and added new text? Read on below.  
Audits won’t help you down the road, Harry; those guarantees stated on your website are the company’s downfall:

- Down the road, a zero-day exploit could emerge and compromise something—for example, security.
- An APT may or may not have been operating on your network of nodes for some time, adapting in real time.
- The NSA (as well as other authorities in other countries) is dynamic and possesses technology that neither Nym nor the public is aware of; therefore, it’s unclear whether the “mixing” is still useful, only partially effective, or, in general, just a matter of probability (luck).
- etc.

Your nodes are also vulnerable and could (if they currently exist) be compromised by sophisticated malware, and the people who connect to them could be affected. That’s the reality, Harry.

The point I’m making is that that part of the site is rife with misleading advertising (the URL cited earlier in my response). You’re speaking technically, but someone with a high level of cybersecurity expertise and knowledge of real-world facts wouldn’t say the same thing. You’re being too overconfident.

Can you tell me who that fired person is (if they even exist), or is that confidential information? I’m interested in hearing their account. What I see here is that the company itself isn’t on the same page, and the problem is obvious from the outside. Suspicions are already running high.

And my questions remain unanswered.

For the record: I’ve reported the matter to the FTC and SECO.

* * *

**End of messages.**

Why haven’t they answered me yet, not even question 3 (how does Nym protect people from real adversaries on its nodes) that I asked, and neither of them responded? It’s very simple: their terms of service put the blame on you:

1. If an exit node logs your data or manipulates your traffic, for example: advanced phishing… It’s your fault, not the company’s.
2. If a node logs your IP and sends it to an unknown destination for real-time monitoring with all data included, whether encrypted or not, it’s your fault, not the company’s.
3. If the mob hires adversaries with APT (Advanced Persistent Threat) capabilities among the nodes and something happens to a genuinely innocent person within 4 weeks, it’s that person’s fault, not the company’s.
4. … (continues).

**Don’t trust** NymVPN; if something happens to you later, they’ll blame you and the company will wash its hands of it. Of course, you have every right to report the company for fraud and public manipulation, but you need irrefutable proof of what happened to you.

---

## Post 37 by @DanielM — 2026-08-01T13:21:00Z

I’m going to translate the complex into universal human language so that people can better understand this situation, especially those without prior knowledge:

1. The NymVPN company has revealed its internal instability in front of the public. This means they are out of sync and make terrible mistakes, such as: deceptive advertising.
2. Harry, the CEO, trusts more in technology than in being virtuous (humility and sincerity). He might change later on; sometimes, you have to give people time.
3. The company’s best defense is “FUD” and its technological complexity. Debating on this ground requires time and knowledge. A person who is unaware of these simple tactics is vulnerable; if they accept things blindly without questioning, they will lose quickly.
4. Harry and Alexis have shown they are out of sync; they are two high-ranking individuals in the same company. According to official information from Nym on their website.
5. Is it safe to use their service? It depends on who you ask. The real question is: is it worth what they claim? Not for me.

Straight to the point: I simply brought Nym down from its own “throne” to reality itself, so they could see themselves and who is who. What they do afterward is their responsibility, not mine.

Fundamental note: after having read this, if you decide (supposedly) to buy a subscription and keep using the service, what will you do if your personal data is leaked to the best impostor or your traffic is manipulated for such malicious purposes?  
You decide what to do.

---

## Post 38 by @DanielM — 2026-09-05T14:18:05Z

Today, 09/05/26, the official Nym website in English has been updated.

The homepage has undergone a fairly useful and streamlined change, so I’ll offer a brief observational analysis:

- They’ve featured Edward Snowden as a selling point to further boost “trust” in the Nym service.
- They’ve created a 4-step process to get started with the service. Each step has its own focus, according to the writer’s argument.
- They’ve included animated graphics to help explain the software’s inner workings and capabilities.
- They’ve removed the word “guaranteed” and its synonyms. Only “Independently audited” appears. Below that are icons linking to related information. For now.

Recommendation for Nym on the homepage:

- Include a link to documentation explaining the software’s actual functionality for people with no computer knowledge.

Critical risk detected:

- In step 3, the writer used the word “lovers.” In this context, the company assumes or implies that it already knows all or some of these “people” who manage the nodes (servers), revealing who is who, including malicious actors. How does the company know about this? Is there something the public doesn’t know? Why does this contradict the operators’ own terms, such as Sessions II and IV, for example? Is it possible that an AI (machine) is managing a node rather than a real person? …? On Android, the app lists 73 countries with 593 nodes, not the 800+ nodes stated on the official website. Unless there are reasons related to limitations such as “not affecting the app’s performance,” this discrepancy isn’t explained and could be considered misleading advertising.

Q&A Session:

1. What is the purpose of this report? Why does it sound destructive or somewhat aggressive in certain circumstances? Answer: It’s simply to help people not fall for “smooth talk” and to reinforce their approach to communicating with a company, regardless of its status. And if I wanted to be destructive toward Nym, I would have done so from the very beginning, surgically and irrefutably, letting it destroy itself.
2. Who are you, and why do your mannerisms sound like those of a high-ranking military officer or someone who works for an agency, for example? Answer: Don’t focus on my “credentials”, my actions speak for themselves. That’s why the vast majority of people fail to understand me. I am independent.
3. Are you seeking approval from the Nym company or from people? Answer: No. The responsibility lies with the Nym company for its actions; I told them what I had to say, and the demonstration publicly exposed its real contradictions. You can verify this yourself in the context of my conversation with them on Telegram, the company is internally unstable.

If I want to, I’ll do a comparison review of Nym versus IVPN later on. Time will reveal the truth as it is.

Note: Spanish to English: using the DeepL (AI) translator.

---

## Post 39 by @approvalcartridge — 2026-09-05T18:43:23Z

The most important thing first:

> [@DanielM](#):
>
> And if I wanted to be destructive toward Nym, I would have done so from the very beginning, surgically and irrefutably, letting it destroy itself.

I mean, if you know anything not obvious, you should disclose it, no?

I don’t disagree that Nym’s wording leaves a bit to be desired, but that is commonplace in this sector.

(Also, I don’t mean to offend you, but it does seem that the thing you claim wanting not to do is the purpose of this thread.)

> [@DanielM](#):
>
> Critical risk detected:
> 
> - In step 3, the writer used the word “lovers.” In this context, the company assumes or implies that it already knows all or some of these “people” who manage the nodes (servers), revealing who is who, including malicious actors. How does the company know about this?

They probably don’t and simply mean to say, that running a node makes you a privacy lover in their eyes.

> [@DanielM](#):
>
> - Is it possible that an AI (machine) is managing a node rather than a real person? …?

What makes you assume that?

> [@DanielM](#):
>
> - On Android, the app lists 73 countries with 593 nodes, not the 800+ nodes stated on the official website.

Did you check the app yourself? I saw the screenshot in their website, which also only says “586 servers”. Could a server run multiple nodes? They differentiate the word “server” and “node” on their website.

It could also mean they plan to deploy additional nodes or include more from others, if I understood correctly how it works, and they do not want to update the website all the time.

> **Offtopic**
>
> > [@DanielM](#):
> >
> > 1. Who are you, and why do your mannerisms sound like those of a high-ranking military officer or someone who works for an agency, for example? Answer: Don’t focus on my “credentials”, my actions speak for themselves. That’s why the vast majority of people fail to understand me.
> 
> (Again, I don’t mean to offend you, which is why I put this into collapsible text.)
> 
> This probably does not translate very well, as it seems to brag. Maybe the “vast majority” does not understand because of a culture or language barrier.

> [@DanielM](#):
>
> If I want to, I’ll do a comparison review of Nym versus IVPN later on. Time will reveal the truth as it is.

Please do, as it seems you already have a lot of effort to understand it.  
But my I ask about including Proton and Mullvad, too? They still are recommendations here. Maybe a more general comparison between these three and Nym makes more sense.

That all being said, although I’m not interested in Nym right now, I have been curious.

---

## Post 40 by @DanielM — 2026-09-06T02:27:20Z

Here is my response:

- I have pointed out a few, for example: requesting irrefutable evidence of the “guarantee” against the NSA at the technical level, based on real-world facts, not laboratory conditions. Requesting this evidence, implies, at a minimum, that the NSA participate in such real-world tests in conjunction with the company Nym, etc. Since this isn’t happening, the guarantees fall apart on their own, and the “theoretical” technical level collapses on its own. Logically, the NSA isn’t going to participate, it’s that simple, and if they ever do, it will be for their own purposes (based on their current strategies and tactics) and not for the participating company; that would be quite rare and unusual, and suspicions would run high in such situations if they were to occur.
- You’ve misunderstood me. The author who wrote that word along with its context, as stated on their website:

> 3 - Choose your decentralized path
> 
> Choose your entry and exit servers. The Nym network is decentralized and run by an independent community of privacy lovers.
> 
> Servers in 70+ countries  
> 800+ nodes  
> Residential IP support

As you can see, it says “independent community.” By including the word “lovers,” the situation gets even worse, because it goes against the operators’ own terms, against decentralization, and against “independence,” at the very least—and this raises questions: Who writes those messages on the Nym website? Who approves them without knowing the problems that arise elsewhere, including with “legal documents”? etc. If it were independent, it wouldn’t be subject to Nym’s operator rules; adversaries could freely pose as defenders of “privacy” (the mafia, the NSA, the CIA, and any other real adversary engaging in such acts according to their intentions), ignoring even Nym’s own terms, among other things. The truth is that the more problems there areas you say, “common” ones that are actually serious, the more adversaries, including novices, can exploit all those corporate vulnerabilities and pose as sophisticated Crypto AG-style companies (behind which the CIA has been, for example) that have been operating quietly for years. Is this really what people want?

I’m not making assumptions about AI, I’m asking. It’s a valid question that has profound implications for many things, such as a script, for example.

Yes. As verified at that moment, how that number changes is not something under my control. Here’s a screenshot, even the “inbound” and “outbound” numbers are the same without the QUIC protocol enabled. The IP is static when you connect to that outbound node; in Mixnet mode, the number of nodes changes, differing from Fast mode:

 ![code-08](https://forum-uploads.privacyguidesusercontent.com/original/3X/6/0/6045201833cc288a4fc34ef796d3495cdda5eda0.jpeg)

A server is a node, depending on the application in fast mode. In fast mode and Mixnet mode, they have the same static IP addresses on the same node; the difference is that when you select Mixnet mode, the number of nodes (servers) suitable for this configuration is filtered and reduced. You can verify this yourself in your client.  
More official information here: [Essential Parameters & Variables | Nym Docs](https://nym.com/docs/operators/variables)

- It’s not a language or cultural barrier. It’s my operation: technical level, legal level, user level, physical level, and whatever else is relevant, all processed simultaneously, not just one at a time. That’s why many people can’t understand me.
- No. IVPN is the right choice, and it’s what I truly recommend. When it’s available (if it is), you’ll be able to use that comparison against ProtonVPN and Mullvad, **without needing to delve into lengthy details involving multiple companies**.

I understand your curiosity, but the facts are laid out, and you can read them for yourself; it requires active engagement and knowledge across multiple areas to understand them deeply. If you read superficially, you won’t be able to understand my messages, at least in most cases.

---

## Post 41 by @byesun — 2026-09-06T03:05:54Z

> [@DanielM](#):
>
> As you can see, it says “independent community.” By including the word “lovers,” the situation gets even worse, because it goes against the operators’ own terms, against decentralization, and against “independence,” at the very least

This is the most ridiculous complaint in this thread. If it wasn’t obvious you’re just targeting them before, it’s extremely obvious now.

---

## Post 42 by @DanielM — 2026-09-06T08:44:29Z

Refute my arguments completely instead of attacking me personally, and if you didn’t know or forgot the rules, I’ll help you remember them:

> ## **[Be Agreeable, Even When You Disagree](https://discuss.privacyguides.net/guidelines#agreeable)**
> 
> You may wish to respond by disagreeing. That’s fine. But remember to _criticize ideas, not people_. Please avoid:
> 
> - Ad hominem attacks

If you have solid, irrefutable arguments (which you haven’t provided at any point so far in any of your messages), make them known; if not, the rules apply to you.

What’s important is that the company Nym has acknowledged (hopefully that’s the case) regarding the word “guarantee”, that they haven’t been able to uphold it, because someone who actually works or has worked in cybersecurity, intelligence, and counterintelligence knows very well that it’s not possible to uphold that claim. If Nym genuinely acknowledged this, that’s a positive development, and honesty is valuable, and that’s what I’m looking for, not a string of “lies from one company to the next.”

---

## Post 43 by @Encounter5729 — 2026-09-06T10:47:24Z

Just came out to say that Harry seems like a good person. He is very accessible, I met him at a privacy-focused conference, and he is quite accessible and even introduced me to a few persons, which was nice of him

I also would like to say that the loaded language of OP, combined with text in uppercase, feels like Clickbait and doesn’t really make me want to read it in full. (Don’t take it personally, but in life if you want people to take interest in what you are saying, seeming angry isn’t the best strategy)

Finally, I think that Nym problem isn’t the technology, it’s positioning. Proton VPN is geared toward the general public that is also privacy-conscious, Mullvad towards the privacy-conscious, anonymity-wanting and IVPN is geared towards more tech-savy users and more affluent.

I don’t really know towards whom NymVPN is geared towards.

And it’s expensive, like I checked and realised the prices displayed in website are without VAT. They should offer a free trial, without payment details (maybe do 4 days free every 3 months on specific date, up to x thousands account to avoid DDOS.)

---

## Post 44 by @byesun — 2026-09-07T01:25:46Z

This isn’t an “attack” on you. Complaining about a privacy company marketing a privacy product calling the people who use or contribute to their service “privacy lovers” is just ridiculous. It also has no impact on the “independent community” phrase, since it’s quite obviously an assumption based on the purpose of the product.

Likewise the complaint about calling it an “independent community” makes little sense either. They operate a dVPN/mixnet. The entire purpose is that there are a bunch of random people that Nym the centralized entity knows little to nothing about running most or all of the nodes. If Nym had to manually approve these applications, it’d defeat the entire purpose of having a decentralized network. They have terms that operators are supposed to abide by, but they cannot tell if there’s a violation unless they are reported or somehow noticed while doing something wrong (at which point the node can be blacklisted in at least the client through an update, not sure what other means they currently have). Presumably you are familiar with Tor. Tor has the same issue. They can try to reduce the problem by having node reputation (which AFAIK Nym has as well) and so on, but fundamentally the networks require unknown people to run the software on their servers (which could potentially be maliciously modified by the node operator). This is a pretty much unfixable issue with this model, but it’s a tradeoff to avoid having all your trust in the network being placed in one entity (the VPN company) in normal centralized VPNs. Whether they’ve done enough to mitigate that issue is up to you to decide (which you very clearly did before you even created the thread).

Regarding the number of nodes being reduced in mixnet mode, presumably that’s because operators can choose what to provide. In other words, they can provide mixnet nodes, just dVPN nodes, or both. IIUC they can control whether they provide exit gateways for instance as well. I haven’t bothered to check the numbers, but if there’s a difference between the number they’re reporting on the site and the max of both modes, then it’s likely because they’re counting all the nodes (individual dVPN + individual mixnet + both dVPN/mixnet) in that number.

In any case, you keep reviving this thread. If you weren’t targeting them, you’d have said your piece and been done with it after the initial discussion where you claimed to be “closing the matter” three months ago, but given that you were apparently on the Nym Telegram over a month after you’d made your thoughts clear(-ish) and then posted the messages here with an all-caps, bolded, tabloid-like header, and then you just revived it again after another month, you clearly have some bone to pick with them.

---

## Post 45 by @byesun — 2026-09-07T02:05:18Z

Is it actually that expensive? I just quickly checked the prices, and they seem like they’d still be cheaper than Mullvad with VAT (assuming you subscribe for at least a year). The monthly prices are indeed expensive though. Seems similar to IVPN in that subbing for less than a year is probably too expensive. Their homepage says you can get it cheaper if you use $NYM or whatever (their cryptocurrency), so I guess that’s an option, although I’m not sure how difficult it is to get their token.

---

## Post 46 by @No_Name — 2026-09-07T12:01:07Z

I’ve got a NYM subscription and had a free trial before signing up. I caught them during a sale and paid something like 60 maybe 70 and got a 2 year subscription. It’s been good so far imo.

---

## Post 47 by @DanielM — 2026-09-07T18:34:29Z

@Encounter5729

I’ll address the key points:

- “…seeming angry isn’t the best strategy.”

-\> Use your reasoning without letting your emotions guide you, and you’ll see that’s not the case.

- I don’t really know who NymVPN is intended for.

-\> It varies; it’s even intended for adversaries.

@byesun

If it were “ridiculous” and a “complaint” according to your interpretation:

- Who would dare call an independent community which could be anyone, such as adversaries at any level and one or more machines (AI), if any are currently active regarding (AI) “privacy lovers”?
- Do you know how real adversaries actually operate in this context?
- Is your intention to prevent me from helping the company improve, or are there other motives? Based on your behavior.
- Do you think I’m complaining? No, I’m reporting an issue, it’s very different.
- If they know little or nothing, why have they included those new words (question 1) that even contradict their own terms?

Not Tor; I focus on Nym. Nym is part of Europe, they say so themselves: Built by academics - Funded by the European Union.

They added that to their official website today. What does that mean? If it’s from Europe, then the service they offer is opposed to the NSA, the CIA, the mafia, etc. In what sense? Reread question 1 that I asked earlier and understand it thoroughly.

I accept your limitations in not knowing certain things. However, I acknowledge that you’ve made valid points, such as the allegations about nodes that might behave suspiciously or rather, modify the software for such purposes.  
You said: If Nym had to manually approve these applications, it’d defeat the entire purpose of having a decentralized network.

Those words of yours support my argument (Question 1) + context.

Regarding the numbers, it’s likely as you say. Based on my verification, they are the same IP addresses, and according to the documentation I checked on the official site, they are the same nodes suitable for both modes (fast and mixnet, or one of them, depending on the operator). This needs to be clarified because it can cause confusion and could be considered misleading.

It’s true that I mentioned shutting it down, but I didn’t say forever or eternally. There’s nothing wrong with capitalizing a title and providing supporting arguments in the body of the text based on the context. Don’t forget the thread title, which reads: Analysis of Nym VPN…

That’s not a personal attack or a score to settle with them. Don’t confuse being destructive with being constructive, they’re different, and I’ve applied both approaches, even in the Nym Telegram group.

This isn’t “transparency”; it’s realism. It’s not “show me what you’ve got”; it’s me presenting the facts based on reality without fabricating anything (without falsifying messages from Harry or any other Telegram member, for example).

That’s legitimate and public, because people deserve to know the truth and what the CEO of Nym and the other members of the Nym team are saying.

I have more to say, but given what I’ve said above, I’ll leave it at that.  
You haven’t presented me with any solid arguments that I can accept.

---

## Post 48 by @approvalcartridge — 2026-09-07T22:29:44Z

> [@DanielM](#):
>
> - I have pointed out a few, for example: requesting irrefutable evidence of the “guarantee” against the NSA at the technical level, based on real-world facts, not laboratory conditions. Requesting this evidence, implies, at a minimum, that the NSA participate in such real-world tests in conjunction with the company Nym, etc. Since this isn’t happening, the guarantees fall apart on their own, and the “theoretical” technical level collapses on its own. Logically, the NSA isn’t going to participate, it’s that simple, and if they ever do, it will be for their own purposes (based on their current strategies and tactics) and not for the participating company; that would be quite rare and unusual, and suspicions would run high in such situations if they were to occur.

I’m not a native speaker myself, but I really can’t follow you here. Are they colluding now or not? You seem to say both.

I really don’t want to sound like a prick. But I don’t think you answered the most important points I asked about, e.g. what you’d know what we don’t or what would not align with the general statements. It looks like claims and doubts.

> [@DanielM](#):
>
> Refute my arguments completely instead of attacking me personally, and if you didn’t know or forgot the rules, I’ll help you remember them:
> 
> > ## **[Be Agreeable, Even When You Disagree](https://discuss.privacyguides.net/guidelines#agreeable)**
> > 
> > You may wish to respond by disagreeing. That’s fine. But remember to _criticize ideas, not people_. Please avoid:
> > 
> > - Ad hominem attacks

They seem to address the sentiment, not your person. If you deem this an “ad hominem” attack, this would be one, too, if not more than theirs:

> [@DanielM](#):
>
> I accept your limitations in not knowing certain things.

And about the “guarantee”:

> [@DanielM](#):
>
> - They’ve removed the word “guaranteed” and its synonyms. Only “Independently audited” appears. Below that are icons linking to related information. For now.

> [@DanielM](#):
>
> What’s important is that the company Nym has acknowledged (hopefully that’s the case) regarding the word “guarantee”, that they haven’t been able to uphold it, because someone who actually works or has worked in cybersecurity, intelligence, and counterintelligence knows very well that it’s not possible to uphold that claim. If Nym genuinely acknowledged this, that’s a positive development, and honesty is valuable, and that’s what I’m looking for, not a string of “lies from one company to the next.”

If they removed the word “guarantee”, would that not mean they acknowledged it being inaccurate in your opinion?

> [@DanielM](#):
>
> - I don’t really know who NymVPN is intended for.
> 
> -\> It varies; it’s even intended for adversaries.

> [@approvalcartridge](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/danielm/48/11844_2.png) DanielM:
> 
> > - Is it possible that an AI (machine) is managing a node rather than a real person? …?
> 
> What makes you assume that?

> [@DanielM](#):
>
> - Who would dare call an independent community which could be anyone, such as adversaries at any level and one or more machines (AI), if any are currently active regarding (AI) “privacy lovers”?

I"m having trouble to see the relevance of AI here, as AI is a mere tool.

As we established, “privacy lovers” is probably meant as a classification for those, who want to provide the service, via a server or a node.  
IMO this disqualifies any adversary, because by definition, these would be opposed to the sentiment of loving privacy.

> [@DanielM](#):
>
> - Do you think I’m complaining? No, I’m reporting an issue, it’s very different.

I’m sorry, but what issue? The “guarantee” seems to have been replaced by more careful terms, even possibly by your very own persistence, which I have to admit, I’d applaud you for. Is the whole point not being moot now?

> [@approvalcartridge](#):
>
> But my I ask about including Proton and Mullvad, too? They still are recommendations here. Maybe a more general comparison between these three and Nym makes more sense.

> [@DanielM](#):
>
> - No. IVPN is the right choice, and it’s what I truly recommend. When it’s available (if it is), you’ll be able to use that comparison against ProtonVPN and Mullvad, **without needing to delve into lengthy details involving multiple companies**.

Got it, but if you are not particularly in favor of IVPN or against Proton or Mullvad, why not keep it general then? You would not even have to deal with what IVPN claims, let alone Proton and Mullvad.

> **Offtopic**
>
> > [@approvalcartridge](#):
> >
> > ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/danielm/48/11844_2.png) DanielM:
> > 
> > > 1. Who are you, and why do your mannerisms sound like those of a high-ranking military officer or someone who works for an agency, for example? Answer: Don’t focus on my “credentials”, my actions speak for themselves. That’s why the vast majority of people fail to understand me.
> > 
> > (Again, I don’t mean to offend you, which is why I put this into collapsible text.)
> > 
> > This probably does not translate very well, as it seems to brag. Maybe the “vast majority” does not understand because of a culture or language barrier.
> 
> > [@DanielM](#):
> >
> > - It’s not a language or cultural barrier. It’s my operation: technical level, legal level, user level, physical level, and whatever else is relevant, all processed simultaneously, not just one at a time. That’s why many people can’t understand me.
> 
> I only can speak for myself, but I feel I’m one of these.  
> What is actually the point, if not marketing phrases?

As I have said before, please provide any insight that you might have, as it could prove useful to anyone interested in Nym. Or at the very least, they could be incentivized to better themselves based on your points and the exposure thereof.

---

## Post 49 by @byesun — 2026-09-07T23:02:54Z

> [@DanielM](#):
>
> - Is your intention to prevent me from helping the company improve, or are there other motives? Based on your behavior.
> - Do you think I’m complaining? No, I’m reporting an issue, it’s very different.

100% does not seem like that is your intention. Seems much, much more like you are targeting them to ruin their reputation.

Perhaps you should think about what and how you are writing if that is actually your intention.

> [@DanielM](#):
>
> - Do you think I’m complaining? No, I’m reporting an issue, it’s very different.

No, you’re really not.

> [@DanielM](#):
>
> - If they know little or nothing, why have they included those new words (question 1) that even contradict their own terms?

Perhaps this is because you’re translating text and the translation is simply translating the phrase incorrectly. If it’s really translating “privacy lovers” aa “people who like privacy” though, then use your brain please. Do you not know what marketing is? I’m not gonna bother repeating myself.

> [@DanielM](#):
>
> - Who would dare call an independent community which could be anyone, such as adversaries at any level and one or more machines (AI), if any are currently active regarding (AI) “privacy lovers”?

Marketing, assumption based on core purpose of product. What should they say, in your mind, as a descriptor for the node operators when marketing their product? “Use our service with nodes operated by the NSA, CIA, SVR, BND, mafia, random AI, possibly a few real people, and maybe more (intelligence agencies, of course!)!”

> [@DanielM](#):
>
> Not Tor; I focus on Nym.

The point was they have the same fundamental issue with their model that they each try to mitigate. Every (vaguely) technical complaint seems to be about the dVPN/mixnet/onion routing model. It is a problem that every network of this type has to try to handle their own way. It is impossible to fully avoid the problem since at some point the request must be sent over the clearnet.

> [@DanielM](#):
>
> Nym is part of Europe, they say so themselves: Built by academics - Funded by the European Union.
> 
> They added that to their official website today. What does that mean? If it’s from Europe, then the service they offer is opposed to the NSA, the CIA, the mafia, etc. In what sense? Reread question 1 that I asked earlier and understand it thoroughly.

TBH being from Europe does not really mean opposition to the NSA given that European intelligence agencies routinely cooperate with them. Also not sure which “question 1” you’re talking about since this thread is rather long.

> [@DanielM](#):
>
> I accept your limitations in not knowing certain things.

Once again, so condescending. “Ad HoMiNeM aTtAcK ! ! !”

> [@DanielM](#):
>
> It’s true that I mentioned shutting it down, but I didn’t say forever or eternally.

lol, nice backpedalling.

> [@DanielM](#):
>
> This isn’t “transparency”; it’s realism. It’s not “show me what you’ve got”; it’s me presenting the facts based on reality without fabricating anything (without falsifying messages from Harry or any other Telegram member, for example).

It’s you interpreting things out of thin air based on random marketing phrases on their homepage and posting a convo from Telegram where they had a difficult time understanding what you were saying (unsurprising, given your posts here) and eventually gave up responding since you were both condescending and hostile. Also once again using the word “guaranteed” out of the original context (the audit section), which they changed since it was indeed too much, even if it wasn’t saying what you claimed it was saying.

> [@DanielM](#):
>
> You haven’t presented me with any solid arguments that I can accept.

Same.

> [@DanielM](#):
>
> 1. Who are you, and why do your mannerisms sound like those of a high-ranking military officer or someone who works for an agency, for example? Answer: Don’t focus on my “credentials”, my actions speak for themselves. That’s why the vast majority of people fail to understand me. I am independent.

I just noticed this quote. You really like tooting your own horn. You 100% do not sound like “a high-ranking military officer or someone who works for an agency.” Honestly I think that you actually wrote that is kind of hilarious.

---

## Post 50 by @byesun — 2026-09-07T23:47:15Z

> [@approvalcartridge](#):
>
> I only can speak for myself, but I feel I’m one of these.  
> What is actually the point, if not marketing phrases?

He’s just pumping himself up and pushing everyone else down. He’s done this on a number of other posts. I too wondered if it was a translation issue at first, but it happens so often that it’s almost certainly what he actually intends (at least in most cases).

In reality, the reason people don’t understand him is that he simply doesn’t write clearly (probably in part due to the translator, TBF).

> [@approvalcartridge](#):
>
> I’m not a native speaker myself, but I really can’t follow you here. Are they colluding now or not? You seem to say both.

He’s trying to say that they can’t show evidence of the “guaranteed” privacy from the NSA because it would require the NSA to cooperate (to prove they can’t access anything), and if the NSA did cooperate, then it would seem like Nym is colluding with the NSA. This is, of course, based on the removed word “guaranteed,” which in the original page was in the audit section at the bottom, referring to the auditors “guaranteeing” Nym’s privacy.

> [@approvalcartridge](#):
>
> I’m sorry, but what issue?

Pretty sure he’s talking about “privacy lovers” and “independent community,” given that he’s responding to me.

---

## Post 51 by @DanielM — 2026-09-08T04:25:52Z

The information you’re looking for is right here in this thread along with the details; it’s up to you whether you want to get it.

I’ve already replied, but I’ll help you out. There are two explicit scenarios, A and B (NSA and Nym); the third, C, would be the NSA within Nym (formal). The scenarios are designed to make calculations based on both available and unavailable data, without being limited to: the company’s behavior (public and private), cause and effect regarding the public (such as activists or researchers who use Nym, for example), among other factors. Since the company offering this product could not provide (does not have) actual evidence regarding the NSA based on the word “guaranteed,” that word has been removed.

The ad hominem argument you cited is incorrect. It is an acknowledgment of another person’s lack of information. It’s as if you came to me and said, “I don’t have data on this matter…” and I replied, “I understand; if I have information available, I’ll tell you; if not, I won’t.”  
That is entirely legitimate.

Over time, we’ll see if that was truly the case when they removed the word. Actions will speak louder than words.

For now, AI remains a tool; however, in real life, there are “autonomous” robots that, if the situation arises, could operate a node for such purposes, whether for good or for evil. The owner of the AI, if they wished, could configure it for their own purposes, or the machine itself could lose control and act on its own, refusing the owner’s commands, the latter being a rare scenario.  
A server is a node. It’s not a narrow definition in and of itself (it goes beyond that); rather, adversaries who oppose privacy and security are not privacy lovers. Let’s look at it as simply as possible (if you don’t already know): adversaries (through the nodes) would be spying on personal data.  
In that case, the company Nym incorporated these new words, damaging its reputation. How can you call an NSA agent, covertly infiltrated into an independent community, a “privacy lovers,” even if they don’t know it, if they’re operating a node in France, for example? Those words are false and constitute misleading advertising.

The problem mentioned in this very thread has already been discussed.

And one last thing: I can’t provide precise information because they’re updating the website very slowly. The official site needs a major update, not just the homepage. What I can say at this point, based on the information I have about the company:

- Be wary of Nym. Why? Their documentation lacks clear information on how they protect innocent users (activists, researchers, etc.) when a node is malicious. How so? The terms of service state that responsibility falls on the person using the service, and this contradicts the new wording they’ve added to their website (as previously pointed out), to say the least. Levels? If you’re looking for basic privacy, like watching movies online or possibly circumventing censorship for legitimate purposes, Nym might be useful, but beyond that, I wouldn’t recommend it. Danger? There are signs of real dangers. One of them is luring people into subscribing to and using their product with the allure of nice-sounding but also subliminal messaging (under the guise of privacy and security). A serious company shouldn’t do this, but Nym is doing it.
- Nym (the company) needs to build its business for the purpose for which it was created, if they truly know what that is, with consistency and demonstrable quality that is reflected both internally and to the public. Here are two recommendations for Harry (CEO) @harryhalpin :

1. Find your own genuine inspiration, something not already present in the VPN or DVPN industry, that you can achieve without contradictions and that has a real impact on people using your product. That has to come from you. Of course, it would be good to improve what you already have.
2. Offer what you can within realistic limits, with humility and sincerity. Gaining knowledge in other areas, such as intelligence and counterintelligence, for example, will help you understand how real adversaries actually operate, rather than how they’re portrayed in “movies.” This is essential if you truly don’t want to be deceived. As you rightly said, Harry: “someone” was banned for posting inappropriate content on the official website. Although Harry’s argument for banning someone (I have no idea who it is) remains suspicious to me, I’ll leave it as is for now and see later if I decide to change it or not.

- If you’re truly concerned about privacy and want to use a VPN service, use multi-hop (two servers), such as IVPN or Mullvad’s proprietary servers. But if someone insists on using NymVPN despite the reports on this issue, that’s up to them.

Now, having said all that, if you have any doubts, feel free to ask your questions, and I’ll answer them to the best of my ability.

---

## Post 52 by @harryhalpin — 2026-09-08T11:13:42Z

Hi! I’m Harry, CEO of Nym. I’ll just note @DanielM clearly doesn’t understand our technology and how information security works (I recommended he read[this book](https://www.cl.cam.ac.uk/archive/rja14/book.html) from Ross Anderson, the late Nym supporter), and seem he is just being pedantic over the word “guarantee” - it’s hard to tell!

@DanielM has admitted elsewhere basically doesn’t like our technology because we use cryptocurrency. I think this is the position of a very privileged person. Nym supports cryptocurrency like Monero, Zcash, Telegram Stars and others because in many of the countries we care about supporting, especially in Asia where VPNs are de facto illegal, it’s the main way to pay without the government being able to block your payment and cryptocurrencies like Zcash and Monero are the _only_ way to pay privately digitally. We also take cash in envelopes :slight_smile: So his opinion is also not in good faith. Good faith analysis we will respond to and fix, but we are no longer responding to @DanielM.

That being said, no system is perfect, but in effect:

1. Nym’s architecture prevents us as a company (Nym Technologies SA) from logging netflow data as the servers are decentralized and we don’t control them. The NSA or any other threat would have to go after different servers in different jurisdictions. Mullvad, IVPN, etc. would all have to comply with a legal order aimed at a single company. I think it shows that @DanielM doesn’t understand how FISA court orders or other wiretapping orders work - they are aimed at the legal entity. I’ve volunteered at tech collectives and know people that have literally been targetted by this orders - see what just happened to Austici and Noblogs. Nym uses decentralization as it’s simply harder to aim court orders at multiple entities spread out across many jurisdictions, which is why our “safest” automatic selection modes puts your traffic automatically through two different jurisdictions separate from your current country, with servers not known to be ran by a single entity. So a single legal entity running all the servers is always a bad idea if that’s in your threat model.

2. Even if a centralized VPN doesn’t maintain logs, they can be forced to by a legal order, and also forced to keep that legal order secret, see the Merrill case in the USA, a powerful agency can then basically just log the network traffic _in_ and _out_ of any server. Sure, they won’t be able to break encryption without key compromise, but any adversary just watching the server will be able to log all the metadata. Thus, at Nym we offer a mixnet that sends fake traffic and mixes traffic, which is a genuine _first_ that is known to resist this kind of _global passive adversary_ unlike a traditional VPN or other decentralized VPN-like systems such as Tor.

3. Entities running servers can _always_ be malicious. You never know. So you either know or trust the people personally running the servers (which I would argue, is never a good idea in an era of mass surveillance and secret court orders) or you rely on technical architecture. You never know if the person you trust today can be trusted tomorrow. And even if they are trusted, it doesn’t mean someone else isn’t logging the netflow data. Look at the work on Team Cymru logging Tor netflow data, for example, or the many VPNs that have handed over data and sold it.

I think a decentralized mixnet like Nym is as good as a technical guarantee as you can possibly get at the present moment. If you want a legal guarantee (which seems to be what @DanielM wants), my personal opinion is that is impossible - see the court cases cited above. Nym does enforce our nodes to sign a l[egally binding agreement not to log](https://nym.com/operators-validators-terms), but they could always break it. And because Tor does not provide such an agreement, government agencies can spin up as many nodes as they want and use that evidence in court. They could do that with Nym, but could not easily use any evidence, as we learned from the experience of Blake Benthall. As for us having a terms of service, almost every single piece of software has a terms of service to prevent frivolous claims.

If you philosophically disagree with decentralization and just don’t care about metadata protection as an essential part of privacy, I agree a centralized VPN may be useful for streaming. However, these use-cases for centralized VPNs have nothing to do with privacy as centralized VPNs simply move the data collection to a single legal entity - and someone else’s computer that sees both who you are and where you are going _and_ has your billing information, including name and address!

I believe very strongly that centralized VPNs are all a broken model due to the improved legal and technical capabilities of adversaries, and so we at Nym are working to fix it. You may not agree with our solution, but everyone from Manning to Snowden agrees there is a problem, and I would be happy to look at alternative solutions.

Nym have published academic papers on each part of our system, more in the works, and [extensive documentation](https://nym.com/docs) as well as all open source code. This is all on our website. If there is particular information or aspects missing, we are happy to add them. If you disagree or have concerns about particular articles, sentences, or whatever, just flag them and we will respond if the query is given in good faith. We maintain live channels where people can chat and discuss these issues as well, and the development team is quite active there. It’s also open source, so we always look for code contributions and anyone can help make the documentation better.

---

## Post 53 by @DanielM — 2026-09-08T15:28:01Z

I’m going to correct Harry even though he’s ignoring me, but there are people who seek the truth (like me) even if they don’t say anything:

1. It’s true that I don’t like cryptocurrencies, but I don’t reject Nym’s product. IVPN, which I personally recommend, uses a cryptocurrency system, and I don’t reject its VPN. It’s not an “opinion”; it’s based on facts.
2. Points 1 and 2. Who denies how the NSA operates, for example? If Harry can show me that IVPN has ever done this, or even that IVPN currently uses a backdoor (regardless of origin or destination) via OpenSSL with OpenVPN, for example, his argument will carry weight with me and make me reconsider. A solid, well-reasoned argument is a thousand times better than a lot of words.
3. Point 3. Good point; however, why, how, and for what purpose have they included those new words in step 3 on the main page? A reputable company wouldn’t include those words, and you yourself just admitted as much in this section about adversaries, thereby casting public doubt on the company’s own credibility. It is you who are publicly discrediting yourselves, but since you prefer to ignore those who tell the truth, even if it hurts, that’s not my responsibility.

If the software currently offers “guarantees” and is the best option, according to Harry’s argument against the NSA, to a certain extent, are you willing to shut it down, as Lavabit did, when the NSA or another opponent one day decides to break the software and bring the facts to light, as has happened many times throughout history in various ways?

**IVPN is willing to stand up for its users** (we’ll just have to wait for the day to come to see if that’s true):

_Yes you can be gagged, threatened with fines and penalties, but you can absolutely just flip a switch. Most are not prepared to do that, we are, just like Lavabit did._  
Source: [Leaving Mullvad, thoughts about iVPN? - #90 by viktorivpn](https://discuss.privacyguides.net/t/leaving-mullvad-thoughts-about-ivpn/38842/90)

And if IVPN is really that broken (according to Harry, but without any evidence against IVPN), I prefer IVPN, who are more honest and acknowledge the real technical limitations, over a company like Nym that seeks to lure customers and attract subscriptions publicly, which goes against its own principles.

They’ve done well to acknowledge the word “guaranteed,” but I hope that someday, Harry, you’ll reflect on what I’ve just said here. I don’t need you to reply, and be careful of those who impersonate me (if they even exist).  
My actions speak for themselves and are hard to understand.

---

## Post 54 by @harryhalpin — 2026-09-08T16:04:59Z

Again, this response would make sense if NymVPN was a _centralized_ VPN like IVPN that uses a centralized set of servers - and people that prefer that model I think are naive, but so be it. And I do argue that centralized VPNs, even nice ones like IVPN ran by cool people, are flawed by design for reasons I keep explaining. I would argue _all_ centralized VPNS are effectively broken by design - they serve as honeypots and are easy to monitor. This would be true even if they were ran by angels, as they would not be resistant to mass surveillance.

Also, humans are not angels and we should not expect them to be. I used to work with a centralized VPN. Our lead sysadmin told me he would install a backdoor if the US government threatened to take his kids away. Another friend of mine was hit by a secret court order (Nick Merrill). And I’m sure there’s more. That’s one of the reasons we built Nym.

NymVPN is not a centralized VPN, it is a decentralized VPN ran by a smart contract. So comparing NymVPN to any centralized VPN is like apple and oranges. The point of decentralization is _no one can flip a switch_.

And while there are a few components still centralized, like our credit card payment system, we hope to get rid of them and allow people to bypass them (see [here](https://nym.com/blog/nym-pay-as-you-go)).

If you shut down the company, the infrastructure will just continue, although open-source devs will have to keep building on it for free. Since we don’t run the servers, if you shut down the servers, the servers may continue. The long-term plan is to wind down the company once we believe the software is fully decentralized.

Someone like @DanielM can actually just read the documentation rather than freaking out over the “guarantees.” I’m just asking people to _look at the technical architecture_. Do not confuse NymVPN’s decentralized mixnet with a centralized VPN. It’s a new paradigm.

---

## Post 55 by @overdrawn98901 — 2026-09-08T16:40:13Z

> [@harryhalpin](#):
>
> I recommended he read[this book](https://www.cl.cam.ac.uk/archive/rja14/book.html) from Ross Anderson, the late Nym supporter

As an aside, looks like a solid book. Gonna read this over myself to supplement my cryptographic studies.

> [@harryhalpin](#):
>
> Again, this response would make sense if NymVPN was a _centralized_ VPN like IVPN that uses a centralized set of servers - and people that prefer that model I think are naive, but so be it.

Centralization is easy, decentralization is hard. Centralized VPNs have 1 (large) lateral shift of trust, while decentralized is O(n). There are cases of this working well, like Tor, but as it goes you gotta shift a trust problem into a cryptographic protocol and key management problem. And by decentralization, the attack surface has definitely increased.

This is by no means a dig into decentralization, but that its just plain harder, and that not all problems require the harder solution which brings more risk. For general mitigation against surveillance capitalism, I’d argue a centralized VPN may work good enough fine and are tried and true, albeit not perfect. For gag orders and state actors, Tor has indeed been the standard here, but many of us do wonder why we would consider Nym (newer tech) against the tried and true Tor system. It’s also an open question on how much different the security guarantees of this decentralized system operates with the goals in privacy such (I cannot vet for or against this on NymVPN, I haven’t looked and do not claim one way or another at this poin, and don’t have immediate questions either).

Also, appreciate you popping on the forum and clarifying comments and concerns.

---

## Post 56 by @digerati — 2026-09-08T23:33:30Z

i’ve used your product before and believe it to be trustworthy but i take issue with this statement:

> I would argue _all_ centralized VPNS are effectively broken by design - they serve as honeypots and are easy to monitor.

i get really pissed off when people throw around the word honeypot without any evidence to back up their claims, and easy to monitor by whom? i am not familiar with any examples of upstream providers being coerced into deanonymizing users of specific VPNs for instance, and in my mind that’s the only effective way to target users of a service like mullvad or iVPN. what do you think would happen if it was revealed that a service long considered trustworthy was surreptitiously logging activity, or had been surreptitiously compromised by intelligence agencies? either way they’re fucked and lose all trust, if i was worried about something like my kids being taken away i wouldn’t run a service like that in the first place but that is also speculative.

---

## Post 57 by @harryhalpin — 2026-09-09T09:28:54Z

I’ll have to be quick - but Tor and NymVPN’s “fast mode” do not defend against a global powerful adversary - an enemy able to watch all packets in the network. The Tor USENIX paper and Nym’s whitepaper go into details. However, NymVPN’s mixnet defeats this at a high cost to speed (i.e. it’s slower than Tor right now). So Nym’s tech is new but more anonymous, so it depends on your threat model and personal choice.

Decentralization is very hard, agree 100%. However, I do think given that decentralized VPNs are about as performant as centralized VPNs, that no one in their right mind should use a centralized VPN (at least if they have your credit card data, but even then they have both ends of your traffic). It’s honestly dangerous to hand that much information about you to a single third-party. A decentralized VPN paid for ideally in anonymous cryptocurrency (although Nym de-links even credit card payments with anonymous credentials - a design from the Freedom Network that is older than even Tor) is the way to go I think.

---

## Post 58 by @harryhalpin — 2026-09-09T09:33:46Z

I am not claiming all centralized VPNs are actively malicious honeypots, although if you look at what just happened to Austici/Invenati and you talk to a lawyer, I think you may be vastly underestimating the ability of nation-states - in particular the USA - to coerce data and backdoors from less upstanding providers than A/I, who did the right thing and shutdown. However, can we build systems that don’t force good people to shutdown servers? I think it’s possible.

In terms of not-so-great VPN providers that were coerced, HideMyAss handing over Lulzsec data comes to mind, Proton handing over French data, etc. - there’s tons of examples, and those are just the ones we know about. Upstream providers capture netflow data and sell it all the time, typically to governments, often without coercion. Look into Team Cymru and Tor. So I think it’s reasonable to believe that this is happening and accelerating drastically due to AI. I know it sucks, but that’s why we are working on the tech we are working on. Even completely good VPN operators can be hit this way, and I suspect that again, the only answer is decentralization to minimize risk here.

---

## Post 60 by @Expert4870 — 2026-09-09T17:21:36Z

> [@harryhalpin](#):
>
> Proton handing over French data

Wasn’t that the email not VPN?

---

## Post 61 by @harryhalpin — 2026-09-09T17:34:38Z

@DanielM - you just continually complain about the word “guaranteed” when I have repeatedly explained why in non-technical guarantees are not to be trusted and Nym does its best to provide a technical guarantee. However, since it’s clear you don’t understand or even bother to look at the underlying technologies, then I see no reason to try to convince you. Instead, you virtue-signal.

Even if IVPN was ran by angels, any govt. or reasonable sized security agency could just capture their netflow traffic without even talking to them, and the entire point of a secret backdoor order (which would require talking to them) on a centralized company is that you would not get to know. If you think that risk is fine, go for it, keep using centralized VPNs for privacy.

---

## Post 62 by @harryhalpin — 2026-09-09T17:40:08Z

It was Protonmail, but it shows you can be compelled to hand over IP address data. There’s been about one large VPN a year claiming “no logs” and “audited” and then handing over user IP data and/or payment data: EarthVPN, PureVPN, IPVanish. And here’s the deal - this is just public stuff. Government data requests are _not public_ and mass surveillance is _invisible_ even to the VPN servers under surveillance. That’s why I am a fan of mixnets, as its the only tech we have that can defend against the kind of mass surveillance Snowden warned us about.

---

## Post 65 by @Expert4870 — 2026-09-09T18:17:59Z

There is an ignore feature in discourse by the way.

Thanks for posting here, Harry–I’m excited to see where NYM goes.

I posted a small improvement NYM could do to their payment area btw:

> [@Nym and NymVPN - Next-gen privacy with mixnet and VPN service](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072/146):
>
> There’s one tracker https://nym.com/monitoring?o=967446&p=4510941535993856&r=us on the pricing page and when you go to checkout there’s a stripe tracker https://r.stripe.com/b. Now that may be unavoidable for the stripe checkout, but people paying with crypto shouldn’t be subjected to it imo. I know it’s a little thing but mullvad’s https://mullvad.net/en/account page does not have any trackers until you load up the credit card purchase page and none when paying with crypto.

---

## Post 66 by @Expert4870 — 2026-09-09T18:25:45Z

> [@harryhalpin](#):
>
> It was Protonmail, but it shows you can be compelled to hand over IP address data.

Yeah I suppose that’s a good point. Because although Swiss law can’t compel Proton to add logs in the VPN, the mail example shows that it’s technically possible for them to start doing it.

---

## Post 69 by @any1 — 2026-09-09T21:27:39Z

@harryhalpin Are there any plans for a browser extension?

---

## Post 72 by @overdrawn98901 — 2026-09-10T04:11:19Z

While there may be more latent conversation to be had, I’d request this thread to be closed.

---

## Post 74 by @harryhalpin — 2026-09-16T18:59:31Z

Sure, if you know anyone that can code one up send them our way! We have a Typescript SDK for the VPN, so should be relatively easy if one has made a browser extension before: [Overview | Nym Docs](https://nym.com/docs/developers)
