Analysis of Nym VPN and its "guaranteed" privacy - Update: 29/07/26

Last updated 29/07/26 - Independent researcher vs. NymVPN:

Last updated 25/07/26 - Independent researcher vs. NymVPN:


I decided to create a new, more direct thread based on the following:
https://discuss.privacyguides.net/t/nymvpn-nym/25085/46

The point here is that I can’t find any real-world evidence backing up the company’s claims regarding their 5 nodes against high-level adversaries. I don’t want whitepapers or lab results; what I want is proof based on reality.

Does anyone in the community have this evidence so we can analyze it?

I left 5 questions for their support team on Telegram. No one has replied to my message, and I gave them a reasonable 5-day window so this wouldn’t drag on forever. If they don’t respond, it’s because they are hiding something.

A warning to those without experience: be careful with pretty words that lack any irrefutable backing.

ANALYZING NYM’S ARGUMENTS

A brief report citing public information.

1 - Basic patterns detected:

While our encryption standards are already extremely strong, we aim to make them post-quantum secure, staying ahead of emerging threats and ensuring digital privacy even in the face of evolving technology.
Source: https://nym.com/nymvpn-litepaper

-> The company trusts its encryption against new emerging threats, but forgets that high-level adversaries possess undisclosed, covert weapons.

c. not to engage in any actions aimed at manipulating network responses in a manner that could compromise the integrity and security of the Nym Mixnet or Nyx Blockchain.
Source: https://nym.com/operators-validators-terms

-> Asking node operators to comply with this is positive, but the NSA, for example, just laughs at Nym. Malicious actors (the NSA, the mafia, etc.) will ignore these rules and infiltrate the network, or are already infiltrated; each will operate according to their own agenda.

2 - Advanced patterns detected:

-> Not applicable. It is not fundamental to this service.

3 - Emerging dangers:

Two words - Privacy “guaranteed”.

-> There are high-level risks in placing blind trust in the Nym service without questioning it. People like me have absolute distrust toward Nym. What does this mean? The word “guaranteed” implies that privacy, in this context, is ensured 24/7, year-round, invisibly, just as Nym claims: “anonymous” based on 5 nodes. However, they forget that with even a single minor error, they will be held fully liable, directly contradicting their own Terms of Service.

Nodes run by “volunteers”.

-> Nym pays people for their work and for operating their nodes so that users can obtain privacy benefits. However, this is an open invitation to greater risks from veteran hackers, the mafia, etc., not only to get easy money but also to carry out operations of higher interest. Even if the network is difficult for attackers or unfamiliar to them at first, they will learn how it works if it’s something new, and will stealthily counterattack.

4 - Deep, multi-level reasoning:

-> Not applicable. It is not worth applying a higher level of analysis to this service.

-– —

I have not been able to find any real evidence backing up their use of the word “guaranteed” that proves the reality of their claims. Without actual, verifiable proof against high-level adversaries, such as those mentioned above, their arguments collapse under their own weight.

Warning: Any company that uses arguments like → “guaranteed privacy”, “guaranteed math”, “we guarantee you…”, etc., and similar phrases, is just using marketing with no basis in real-world facts.

So far, no one has replied to my message on Telegram, but they haven’t deleted it either. The CEO is right there answering basic messages from other people.

1 Like

Am I the only one or do others feel this post is very passive aggressive and that OP is writing this as saying (claiming) all that they are as if they’re the authority on the subject matter?

If you are the authority, then you’d have the maturity to even better and fully explain your claims and statements with how the tech works in more simpler ways as one who is trying to educate and not one who is trying to “get” a company in a lie without proper and more detailed explanation.

There’s an etiquette involved here which I feel you’re ignoring willingly or unknowingly.

12 Likes

What “proof” are you even expecting?

Based on your comments in the other thread, you seem to be expecting some miracle solution that is both capable of providing anonymity while also being very fast. Like, transferring an 8 GB file over any network like this is gonna be slow.

Also, if this is how you wrote to their support, I’m not surprised they’re ignoring you.

1 Like

I came here expecting an exciting write up about cryptography. I got a rant instead. I’m disappointed.

4 Likes

It reads like OP has made up their mind and is just looking for confirmation. I would call this ‘adversarial skepticism’. :grinning_face_with_smiling_eyes:

1 Like

@anon7180143 :

Are you attacking me personally, or are you trying to figure out if Nym is lying or not?
If I were to explain it in deep, exhaustive detail, who would even read it? They’d ask for a summary, and I don’t do summaries.

@byesun :

So, you’re basically proving my point. If Nym can’t back it up when it’s a matter of life and death, their use of the word “guaranteed” is just hot air. Besides, it’s completely valid to ask tough questions, and they’re entirely justified because fear isn’t an option. And the fact that I was direct about it in public so everyone could see it isn’t something I just made up.

@Shampoo :

The one who has to prove it based on real-world facts is the company Nym, not me, since they’re the ones claiming it’s “guaranteed.”

1 Like

This isn’t a “tough question,” it’s a meaningless question. “What if I need to send 3 TB to someone in 5 seconds? I thought my privacy was GUARANTEED! ! !”

In any case, the performance of the mixnet is poor. They’ve stated this themselves many times, and it’s something they’re working on improving. That does not mean it’s somehow not private. If you yourself choose to swap from the mixnet to the two-hop WireGuard setting, you are the one choosing to reduce your privacy in exchange for a faster transfer rate.

Whether there are enough nodes and whether they are decentralized enough is another story. Maybe they are, maybe they aren’t. But the way you’ve gone about this is ridiculous.

2 Likes

Burden of proof is on the accuser. Even more so in situations like this.

2 Likes

Well, in a sense, they guarantee that they use cutting-edge technologies: far more advanced than those listed in the Privacy Guides’ recommendations (for example, the Amnezia 2.0 protocol). The fact that the NSA can control most nodes doesn’t depend specifically on this provider; it affects all market participants. Don’t use nodes in jurisdictions that are easily controlled from the U.S.

1 Like

I think OP is looking for confirmation bias*

Glad i’m not the only one who noticed the tone and ignorance. I was going to explain the “questions” he had on the nym thread but figured i’d just be losing time considering the mindset of OP here.

1 Like

@byesun :

So, you’re basically implying it yourself between the lines. Ask yourself: what is that word “guaranteed” even doing there? Do you realize the danger of that word, then? Skimming it on a surface level is all well and good, but it goes so much deeper than that. I invite you to revisit point 3 and really analyze it.

@Bumbashirovich :

If that were the case, the Nym team would have told me in under an hour on Telegram, right in their own group, just like you’re explaining its meaning to me now. Why are they still silent, then? Don’t ignore the other high-level threats, either—the NSA is one thing, but there are plenty of others in different countries. Read the context and study it.

@object2598 :

If you know the “answers,” why don’t you just say so directly? Go ahead, I’m all ears. Do you work for Nym? Post it on Telegram along with your “answers” and I’ll read it, because if you were actually on the Nym team, you would have replied to me there.

What are you talking about? I said nothing about answers — my only comment on your post was about how adversarial your tone was, which hasn’t changed in any of your replies. I’m not surprised: every time I’ve interacted with you, you seem to start hostile and become more so.

Sorry, that message wasn’t meant for you; it was for the other person. I made a mistake and I own it.

Let me fix that now.

This is a reasonable goal. Let’s see what we can do

This is a bold accusation based on no evidence of wrongdoing. I operate on zero-trust: I will assume any service provider could be compromised, but I stop short of baseless accusations

FUD. We threat model against evidence-backed threat vectors. Mitigations against undefined, hypothetical threats are not practical

Wise. This is zero-trust architecture. Assume bad actors can/will penetrate wherever possible

Disagree. Traffic analysis is an emerging threat vector. Providers like Mulvad are beginning to design mitigation techniques. I assume the intent here is similar

You argument here just seems to be a pedantic case against the word “guaranteed”. I do ultimately agree with your premise, but don’t feel it’s a meaningful indicator of their actual services

We’re back to zero-trust architecture. Good stuff. This is almost identical to issues Tor faces - users can maintain anonymity if a node is compromised, but it becomes difficult to do anything if the whole volunteer node network is assumed to be hostile

I think this is rehashing the same emerging mitigation techniques as section 2

_______

So far as ‘proof’ goes, it does looknas though they’ve been audited a couple times. For example, I found the Cure53 report here. These are probably a good starting point for assessing the tech

6 Likes

As the other user mentioned, the entire basis of this point is a pedantic freak out over the meaning of the word “guaranteed.” Your argument for them being untrustworthy because of this is just dumb.

Since you didn’t source where that quote comes from, it comes from their home page. It’s a section header at the bottom of the page where they list their audits. The “guaranteed” here is referring to the audits “guaranteeing” that their service does what it says it does as far as the auditors can tell.

However, they forget that with even a single minor error, they will be held fully liable, directly contradicting their own Terms of Service.

This applies to nearly every internet-facing (and often non-internet-facing) service. If they have an exploitable bug and their system is compromised, whoops, all your data has been siphoned off. It is not the insightful point you seem to believe it is.

@privacy.slouchy :

Alright, straight to the point:

1 - When you ask a company a hard-hitting question about a matter of life and death for someone being hunted, why do they stay silent?
2 - It’s not “FUB.” That’s what they want you to believe based on “lab” tests, but not in a real-world war in the world we actually live in (and that includes the digital realm).
3 - You tell me you disagree with what I said, but it turns out points 2 and 4 are different. And to top it off, point 1 and the two dangers mentioned are more than enough. There’s no need to create an exhaustive list.
4 - You dismiss a scenario as “pedantic” while simultaneously telling me you agree with me. Why the contradiction? Do you have any idea how much weight that word “guaranteed” carries? Take point 1, for example.
5 - You made a good point about zero trust, but I have a fundamental question for you: will an audit save the life of someone being hunted, like I mentioned earlier?

@byesun :

You interpret it as “panic,” but it isn’t, and it isn’t “pedantic” either. So, you’re basically proving my point—are you even aware of that? And it’s not just about what you’re saying; it applies across the board: → Privacy ← “result: guaranteed.” If there’s even the slightest security flaw while that word “guaranteed” is being thrown around, the hunted person dies trusting the tool, despite having decent OpSec. Is the company liable? The answer is yes, and the family would have every right to sue the company for false and unethical advertising. Do you get now just how heavy that word is? I invite you to play detective, to connect the dots and dig deep. Don’t just settle for the surface level—dig into the depths, and if you keep learning, you’ll understand way more than what it literally means.


A little invitation for you both: if you didn’t already know, look up a bit of history on Edward Snowden and the Lavabit email service.

My intention is simple: to protect people who lack knowledge and don’t know how to defend themselves, by demonstrating in just a few words that Nym’s company must be honest and remove the word “guaranteed” if it is truly honest.

1 Like

I invite you to play detective, to connect the dots and dig deep. Don’t just settle for the surface level—dig into the depths, and if you keep learning, you’ll understand way more than what it literally means.

Amazingly condescending. As expected of someone spreading FUD.

If there’s even the slightest security flaw while that word “guaranteed” is being thrown around, the hunted person dies trusting the tool, despite having decent OpSec.

If you have decent OpSec, you would actually look into the tool you’re using rather than taking a phrase used in a random section header on a page filled with marketing speak at face value. Especially given that there are two modes, one of which is very clearly meant to be more private than the other. Literally even discussed on the same page the “privacy guaranteed” section header is located, in a more prominent section near the top of the page.

1 Like

I AM CLOSING THIS MATTER, AND HERE ARE THE RESULTS REGARDING NYM VPN:

Nym has proven they have no intention of answering my hard-hitting questions. So, I’m going to answer my own questions based on reality:

1 - Two words pop up: “guaranteed” privacy. How exactly do they guarantee it, against whom (adversaries, for example), in what way, and what is their actual method?

→ Anyone with at least a basic understanding will realize that protection against your Internet Service Provider (ISP), websites, and other common threats gives you privacy to a certain extent. However, while Nym’s official website acknowledges their limitations, they heavily inflate their claims, just as I demonstrated in point 1.

Search your preferred search engine for the following terms: United States “Top Secret,” what it is, and what it means.

That will give you a much better idea of what I mean by “hidden weapons.” And don’t just limit it to the United States—look into the capabilities of other countries as well.

2 - How does Nym defend against adversaries like the US NSA when it comes to adapting to or outpacing their methods targeting the VPN service?

→ This answer is far too complex. I can’t answer something when I don’t have internal data from Nym itself. Therefore, I’m not going to make anything up here.

3 - How does Nym protect legitimate users of their services from infiltrations via seemingly “legitimate” nodes? What are their methods, and how do they handle this? For example: the mafia, veteran hackers, etc.

→ In the official documents on their website, there isn’t much clear and precise information about these kinds of situations. Therefore, this massive responsibility falls entirely on the company.

4 - Which option would you advise (2 nodes or 5 nodes) in a life-or-death situation involving persecution, when someone needs to send an encrypted, compressed 8GB file to the person being hunted? Is it just a matter of “luck”?

→ The people at Nym who understand this question know that if they answer and make a mistake, the public will come down on them and they’ll face lawsuits. The reality is that this is a test for them, but I wanted to see if they were capable of facing reality or if they would just blindly trust the “math” 100%. Logically, both modes come down to luck, not certainty.

5 - If the answers to all the previous questions are positive, do you have real-world proof against legitimate, real-world scenarios for the public?
I need you to convince me with real evidence, because whoever claims something is “guaranteed” must be absolutely sure that what they’re saying is true.

→ This is the ultimate challenge for any VPN company. Lawyers who understand these questions, know what they mean, and have knowledge based on real-world facts will tell you that irrefutable proof simply doesn’t exist. They are, therefore, probabilities, not a “guaranteed” reality.


Deep dive into the word “guaranteed” in the context of the report and the questions:

  • They cannot guarantee optimal protection, because high-level adversaries never rest.
  • They cannot guarantee that the nodes aren’t logging most or all of your internet traffic data. A novice adversary could map all the public IPs of the nodes, build malware, and exploit unknown vulnerabilities in the software—even with the help of AI. Clear evidence: VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun - Check Point Research
  • Nym cannot guarantee your actual survival (life or death) when you’re being hunted on both fronts: real life and the internet. Their technology is based on probabilities, not certainties. This is where luck comes into play.
  • Vulnerable people are easily deceived because they don’t know what’s behind that word, “guaranteed.” Nym’s true intentions are unknown, but it’s highly suspicious.
  • The 5-node “anonymous” mode is basic because it doesn’t cover complex situations. For a critical researcher, it might work for text messaging and some lightweight files, but not for high-demand investigations that require digging into long videos, sharing large files with colleagues, etc. Instead of the researcher working smoothly, it requires immense patience and wastes crucial time—time that, most of the time, you just don’t have because you need to take active action in a world that doesn’t stand still.

Recommendations for the company Nym:

  • Be honest and humble. Your company is on the line by throwing around the word “guaranteed” so prominently, which ultimately sinks it. Sometimes, companies or the people in charge don’t learn until disaster strikes and someone says, “I told you so, and you didn’t listen.” That is, assuming they actually want to learn and fix their mistakes instead of just shutting the company down completely.
  • Your project looks good on the surface, but you need to be able to answer tough questions and demonstrate real, transparent actions. I know the unvarnished truth hurts, but adversaries show no mercy when they decide to strike—it’s a whole different ballgame.

Recommendations for people’s:

  • Before buying, research and analyze the official website. Don’t rely on “review” sites, because they commonly use exaggerated advertising tactics.
  • Be critical: What is the website claiming? Does it benefit me? Is it optimal? Will the company defend me in critical situations? What do the terms of service, including the privacy policy, actually say? Apply and analyze their words. If there’s something you don’t know, look it up. You can also ask questions if you want.

Now, people have to make a decision. I tried to make it as easy as possible—turning the complex into the simple—to help those who lack basic IT knowledge in these privacy and security areas.

2 Likes

MY ARGUMENTS AND THOSE OF THE CEO AND ADMINISTRATOR OF THE NYM TELEGRAM GROUP

I compiled the messages as texts, not screenshots. I organized them to be clear and easy to understand, without any beating around the bush.

The most interesting thing, within Nym’s own sphere of influence, is that the administrator started attacking me. What did I do? I used his own arguments against him and at the same time pointed out that he was contradicting the word “guaranteed,” which Nym itself claims to uphold.

Here are the messages:

Arguments.
  • My message:

Is no one going to answer my legitimate questions?

  • CEO Harry Nym:

I don’t speak Spanish but I can guess. In effect, there are no 100 percent guarantees in security and anonymity, but due to adding fake traffic and mixing traffic Nym is the only VPN that protects against a global adversary like the NSA or Palatir. To use that, you must use 5 hop mode.

  • (Yo):

Why guess? Use a translator like I do; it’s the only way I can understand anything in other languages.

If it’s the only way, do you have irrefutable proof based on real facts?

  • Admin - Salazar:

Translators are not 100% accurate; have you had the chance to read through the whitepaper? Everything the mixnet does is explained pretty thoroughly here:

https://nym.com/nym-whitepaper.pdf

Section 4 fyi

  • (Yo) :

I know it’s not 100%, so why is the website multilingual? It’s strange.

The white paper doesn’t help me; it’s not irrefutable proof. What I’m looking for is based on the “guaranteed” privacy, as argued on Nym’s official website as irrefutable proof of how well it actually protects users in real-world situations.

Based on real-world experiences is what I need, and after searching the official website to a certain extent, I haven’t found it.

If you have it, could you share it with me?

That’s why it’s important to understand the questions I posted earlier in Spanish, unless the company has people who can translate accurately into English.

  • People @Ch1ffr3punk:

I think the privacy and anonymity aspect, same as with Tor, comes to the point if you use it with the right software clients and Nym components properly. This is not much discussed, because the Nym team focuses primarily on the Network infrastructure and NymVPN app and there are no use cases or tutorials from them availabe how to properly protect Nym users, from various threats.

  • Admin:

Real-world protection can’t be absolute (same as it’d be for any other VPNs). It depends on what you’re up against, your device’s security, and some factors outside Nym’s control, like @Ch1ffr3punk said. If you’re looking for case studies, those simply don’t exist but do let us know if you come across any other VPNs you that have published content like this.

What Nym does guarantee is strong technicals. Anonymous mode(Mixnet+cover traffic+timed delays) is designed to resist traffic analysis in ways a standard VPN cannot. The code is open source, and backed by academic research. All papers and audits are available on the trust centre: Trust Center | Nym

  • (Yo):

So, if they “guarantee” it, as you’ve said, how do they back up that argument in real-life situations of harassment on both sides: in real life and online?

Because, for example, does someone who genuinely needs a VPN tool in an emergency “guarantee” it?

  • People:

I like to make a little proposal. Maybe the (external) :houses: Advisors, like Chelsea, DJB etc. can in the future show us some protection examples, when it comes to Online Privacy/Anonymity, similar to what EFF and others do with their tutorials.

  • Admin:

It’d depend on the particular cases - there are n number of possibilities regarding how your anonymity could be compromised. For example, Nym or any other VPNs can’t protect you from a compromised device, logging into websites that already know who you’re, browser fingerprinting etc. the protection is for the network layer only and nowhere on the website/the documentation do we claim otherwise

  • (Yo) :

I’m aware of the example you gave, so here’s my recommendation for Nym:

If you don’t have real proof, replace the word “guaranteed” with something you can actually demonstrate.

Be humble and honest, then.

Remember that there are threats like APTs (Advanced Persistent Threats), etc.

Furthermore, it would be interesting if you published a document explaining how Nym protects legitimate users (if any exist) of your service against infiltrations using “sham” nodes—in other words, veteran hackers, organized crime, etc.—who infiltrate to carry out their activities silently.

  • Admin:

Your comments sound increasingly hostile for what wasn’t a false claim to begin with. Network level privacy is what Nym is for. Nowhere on the website is it advertised as a one-button magic solution that makes you anonymous instantly.

It does look like you’ve made up your mind/just want to spread FUD here as I saw your thread of privacy guides too (Lots of them commenters tried to explain it to you, and we’d be happy to respond there but you’ve closed the thread since :sweat_smile:)

Analysis of Nym VPN and its "guaranteed" privacy

that said, this​:backhand_index_pointing_up: does sound like a cool idea to give nymsters guides for good privacy practices/setups in general

Regarding this, Nym’s research does not assume all nodes are honest. and there’s plenty of theoritical proof to support that a full-scale compromise of the network can’t be accomplished under real work circumstances.

If you’d like to read through the documentation that supports these claims, you can read through the papers from our research team here. Listing some sections below that’ll be relevant:

  • Nym whitepaper (section 4, 6)

  • Reward Sharing for Mixnets: pg 16 sybil resilience discussion

  • The Loopix Anonymity System: 3.2 Format, Paths and Cover Traffic

  • The Loopix Anonymity System: 4.2 Active-attack Resistance

  • (Yo) :

Who are you afraid of? It’s not what you’re accusing me of, and it’s strange that someone with the title of administrator would behave this way.

Go ahead, if you’re willing to respond in the forum, I won’t stop you. But what is clear is that an administrator has accused me of something I haven’t claimed.

I never said anything about being “magical.” You yourself are demonstrating in your messages that they contradict the word “guarantee” and the company that claims to offer it. Whether you’re doing so consciously or unconsciously.

So, if it’s “theoretical,” it means it’s “luck,” and in the argument in session 2 of the PDF security file, you use the word “probabilities.”

File mentioned:
Are continuous stop-and-go mixnets provably secure?

Published: Proceedings on Privacy Enhancing Technologies (PoPETs)

Date: 2024

Authors: Debajyoti Das, Claudia Diaz, Aggelos Kiayias, Thomas Zacharias


To use the word “guaranteed,” regardless of the industry—privacy, security, food, etc.—requires irrefutable proof based on real-world facts, not laboratory experiments or paperwork.

Therefore, if there is no real proof, then, as I stated in the thread you shared, it’s “luck,” and the more luck, the lower the “probabilities.”

I offered my recommendation; if the company decides to accept it, great, but if not, it’s already mentioned in the forum thread.

Furthermore, the server can be attacked by an APT from within or without. If the server is hacked and the attacker can see the work being done—for example, just one instance—the “guarantee” is false, and it’s not the fault of the legitimate user.

That concludes my message. My questions remain unanswered; if the Nym team decides to respond, great.

  • Silence. No more answers.

The company has to make a decision; I’ve already done my part.

Those who decide to buy the service and stay, I won’t stop them, but they need to know something fundamental:

→ I completely reject the system Nym uses for cryptocurrencies (and cryptocurrencies in general), and I don’t trust the company at all. Why and how? I don’t like the aforementioned system; I prefer simplicity, and it’s not a suitable tool for me. I’ve already mentioned this throughout the report (above) and here (below).

Beware of pretty words.

And if the company ever decides to answer my questions… then I could see their arguments and make a decision.

1 Like