Analysis of Nym VPN and its "guaranteed" privacy - Update: 10/09/26

NYM HAS BEEN CAUGHT FOR THE SECOND TIME

Previously, NYM had stated “Privacy Guaranteed,” but it turns out they changed it by hiding the word within the following box:

Independently audited
Annual audits and technical reviews ensure the network is transparent, secure, and log-free.

-> What they’ve done is build in a sophisticated trap, and instead of improving, the company is getting worse.
Take the mafia, for example: if they defy what they call “impossible”—which is a huge lie—and something happens to a person with a family while using their VPN service, that family can legally sue NymVPN.

When people eventually decide to realize how these companies operate behind their rhetoric, they’ll run away, and Web 3.0 will decline drastically.

The latest messages from Carsey Ford (admin) and Alexis (COO and co-founder) tried to draw me into a game of cat and mouse. It’s their responsibility, not mine, and I’ve been quite clear in my messages.

Below is the latest update and the real battle—but with a clear warning to the company:

  • (Yo) DanielM:

@harryhalpinharryhalpin

Greetings.

I’m reaching out to ask for an update on whether the information on your website is currently accurate or if it has been altered for another purpose without your knowledge.

The phrase “privacy guaranteed” no longer appears on your English-language website; it now reads as follows:

Independently audited
Annual audits and technical reviews ensure the network is transparent, secure, and log-free.

Is this correct, or is there another intention behind it?

  • CEO Harry:

I didn’t remove that phase but maybe @sallysundriesur editor @sallysundries did as I suspect it was written by (our now departed) previous marketing people. However, privacy is a holistic property of a system, it can never be guaranteed like security can.

  • Casey Ford (Admin):

“Independently audited
Annual audits and technical reviews ensure the network is transparent, secure, and log-free.”

Is correct. The change was made to be honest with our users about the specifics of how Nym protects you concretely rather than through marketing claims. The guarantee is a network that can’t log your full traffic by design.

  • CEO Harry:

An explanation by me is here - see Section 3 https://www.ndss-symposium.org/wp-content/uploads/usec2021_23007_paper.pdf

However, we CAN guarantee security claims via formal verification and we will have an exciting blog post on that today, as we are now formally verifying our core code.

For an explanation of formal verification by myself, see here: Making sure you're not a bot!

  • (Yo) DanielM:

@harryhalpin @sallysundries

I’ve analyzed your arguments to a certain depth (not exhaustively). Before continuing, I’m letting you know up front that I didn’t come here to be gifted a license (dVPN), a job, validation, etc. I came to find the truth behind what is “superficial” within the company, not to destroy it, but to show that the advertising is bigger than what you claim.

Harry, I understand what you’re saying and I’ve read some of your messages when you mentioned those cases here in your Telegram group.
The new claim has a sophisticated trap (probably the person who made the change doesn’t know it) and it is the following:

  • It explicitly guarantees the following words, literally covering 3: transparent, secure, and log-free. However, guaranteeing security and no logs also encompasses privacy; without the previous two, there is zero privacy.
    There’s the real trap, the word privacy is hidden, not implicit.

On top of that, that new argument raises even more suspicion and doubts about the company itself.

I ask you the following questions:

  1. Why don’t you permanently remove the word “guaranteed” and be more honest?
  2. Suppose you insist on keeping that word, what will you do when it fails one day? Will you be ready to face real lawsuits if they file them?
  3. I’m still interested: how does the company Nym defend legitimate people against real adversaries when they use the nodes? Will it be the fault of the person using the service, as Nym’s terms claim, if something serious happens?

In the following URL: NymVPN Litepaper: Decentralized VPN & Mixnet Privacy | Nym
There are many claims in relation to it…

Note: I will copy and paste the messages into the Privacy Guides forum so that people know more information about the company itself.

  • Casey Ford (Admin):

I’m not sure I understand, so feel free to clarify if I am not answering your question properly.

We have removed the word “guaranteed” from our landing page where it originally appeared as a marketing claim from a previous employee as “Privacy guaranteed,” referring to our policy of conducting independent, external audits of our services.

The reason we removed it was because we felt this wasn’t a good use of language. Privacy is not something that can be “guaranteed” by any one service. For example, while NymVPN can help protect your privacy at the network routing level, it can’t stop you from deanonymizing yourself some other way, or stop all forms of surveillance.

Ultimately, the edit on the website pertains to that particular section of the landing page. What is currently claimed accurately is that:

  1. Nym is committed to performing audits of our apps and code by independent, external researchers and security firms so that they are continually improved for users’ privacy.
  2. That the code remains fully open source so that it can be verified as doing what we claim it does
  3. And that the decentralized network is designed so that Nym never has access to your traffic at all, and node operators never have access to the full route your traffic takes. This makes full logs impossible to be collected from any single point. This is a network design, not a marketing promise.

I’m happy to explain any part of the Nym system or marketing claims if you have specific questions! Just drop them here.

Our goal is honesty and transparency and education, so if you do find claims that are inaccurate, we’ll definitely investigate and correct if needed. Many of us are academics, we’re use to it! :wink:

  • (Yo) DanielM:

Is the man named Alexis Roussel on your team aware of this serious problem? According to Nym’s official source, Alexis is Nym’s COO and co-founder.

This sophisticated scam reveals that the company itself is not internally aligned, and your behavior speaks volumes. It is, therefore, highly suspicious and actionable (a family could sue Nym for false advertising and deception if something happens to them due to real adversaries through its network). This covers any “threat model” regardless of the level.
Didn’t your lawyers tell you this?

You say you’re willing to explain it to me, but I asked questions about Nym and everything surrounding it—how do you explain it to me? The questions remain unanswered.

Be truly humble and honest.

Harry: Are you aware of this issue, since you’re the CEO?

  • Alexis Roussel (COO Nym):

Not sure what you are trying to say, but the wording on the website is correct.

  • (Yo) DanielM:

If that’s true for Alexis, then in the future they won’t be able to say, “Nobody told me.”

  • Casey Ford (Admin):

We are not understanding you at all. :woman_shrugging:t2:

  • Alexis Roussel (COO Nym):

Yep. Sorry we don’t understand.

Maybe you can be more specific or detailed?


End of messages.

Keep the following in mind: NymVPN has no real evidence against real adversaries; it’s all just probabilities, which means → luck. Regardless of the level of the “threat model.”

If something happens to you while using NymVPN, remember what’s been said here.

1 Like