# Nym VPN Is it trustworthy?

**URL:** https://discuss.privacyguides.net/t/nym-vpn-is-it-trustworthy/23142
**Category:** Questions
**Created:** 2024-12-12T23:08:35Z
**Posts:** 28

## Post 1 by @TheG — 2024-12-12T23:08:35Z

I have found nothing about Nym VPN on reddit, privacy guides or any other website. Is it a honeypot?

They say it is a mixnet etcetera.

Their site:

> **[Nym | the world's most private VPN for desktop & mobile](https://nym.com)**
>
> Stay truly anonymous online. Nym’s decentralized mixnet prevents surveillance, shields metadata, and delivers private, high-speed browsing.

And Bisq mentions it in their video of Bisq2 announcement:

> **[Introducing Bisq 2](https://www.youtube.com/watch?v=T583ogprpkM&source_ve_path=OTY3MTQ)**
>
> 00:00: what Bisq 2 is00:42: new codebase00:49: new user interface01:06: multiple privacy networks01:21: multiple user profiles01:52: multiple trade protocols...

---

## Post 2 by @anon29374801 — 2024-12-13T00:52:32Z

It looks like they were audited by Cure 53 in July 2024 but [none of their audits have been published.](https://nymvpn.com/en/trust-center/security-audits)

Other Notes:

- [Chelsea Manning](https://www.politico.eu/article/chelsea-manning-crypto-token-nym-technologies-privacy/) is their Chief Security Officer.
- Nym’s cofounder George Danezis, [briefly left the project](https://www.startupticker.ch/en/news/andreessen-horowitz-leads-investment-in-nym) to help design Facebook’s digital currency Libra.

Not sure if those are massive red flags or not. I also have no clue what the privacy implications of a blockchain-based solution is. Hopefully a more informed user can provide some info on that.

I would probably tell you to wait until they publish their audits at the very least, especially as it seems you have to trust Nym’s ability to vet the node operators.

EDIT: removed the bit about VC funding. It seemed to be a different company.

---

## Post 3 by @Jayapapaya — 2024-12-18T11:37:53Z

Hi good people,

Jaya here, I am CSO of Nym and work with Chelsea and the rest of the team. Thought I’d answer a few of your questions:

- Cure53 have audited and we have just completed the fixes and are about to publish the full report. We have also had audits by JP Aumasson and OAK which are also about to be published.
- Nym and NymVPN is open source and we will rolling out a bug bounty in the new year
- The blockchain is only used to organise the topology of the mixnet and for rewarding operators. The mixnet itself is otherwise separate and no user traffic or information ever touches the blockchain. In short, we use the blockchain for what needs to be public and transparent aka the infrastructure itself, in order to guarantee strong anonymity and privacy for end users.

Hope that helps!

---

## Post 4 by @jerm — 2025-02-08T18:39:02Z

> **[Security audits of the Nym network and apps 2023–2024](https://nym.com/blog/Nym-security-audits-2023-2024)**
>
> Bulletproofing the network behind the world’s first Noise Generating Mixnet

---

## Post 5 by @anon36940904 — 2025-02-08T19:14:39Z

I have yet to give this a try but am wary.

I hope others who have tried can provide context on their experience with this tool.

I too want to know if this is another legitimate option like the current recommendations by PG (even though it is not officially recommended by PG - yet).

---

## Post 6 by @TheG — 2025-02-08T19:28:16Z

They are currently currently offering free 30 day accounts, you can create an account from [here](https://nym.com/account/create) and try it out.

Also there is [Snowden](https://www.youtube.com/watch?v=YnyscVTygOs) in the video on Nym if want to watch it.

---

## Post 7 by @anon36940904 — 2025-02-08T19:33:19Z

Yes, I know I can try it myself - was hoping to get more insight on other people’s experiences first before I forgo my current VPN set up just to experiment with something new.

---

## Post 8 by @TheG — 2025-02-08T19:52:15Z

It is not very stable currently.

From my experience unfortunately I occasionally lose VPN connection, and sometimes some regions become unavailable.

---

## Post 9 by @ihateKYC — 2025-02-08T19:52:18Z

Would like to know how they plan on dealing with unbearably slow speeds. If my connection is being routed through 4 rented vps’s with bare minimum specs then exiting through Switzerland that’s gonna be very slow. Slower than TOR.

---

## Post 10 by @TheG — 2025-02-08T19:57:07Z

Fast mode (Wireguard) routes through 2 servers. It is fast.

Anonymous mode may be slower because it routes through 5 servers but it is faster than Tor.

---

## Post 11 by @anon36940904 — 2025-02-08T19:58:02Z

Stability is a priority for me equally as much as the privacy and security aspects of the VPN.

So, not for me for now then. Thanks for the context.

---

## Post 12 by @nym-product — 2025-02-18T13:14:45Z

Thanks everyone.

> before I forgo my current VPN set up just to experiment with something new.

Feel free to give it a try. NymVPN is free to test while in beta. Head to our site to [get a 30-day credential](https://nym.com/account/create).

> Would like to know how they plan on dealing with unbearably slow speeds.

We’re working with our community of operators on minimum servers specs, so to ensure a good UX for end users.

Happy to hear your thoughts on our Project Showcase [thread](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072).

---

## Post 13 by @Cincinnatus — 2025-02-19T19:52:31Z

I recently took them up on their offer for the free 30 days and am using it now. I’m not an expert or anything on vpn’s, but I was using Nordvpn before this one, and it seems to work great on Wireguard. On the anonymous mode, however, it’s definitley slow. They seem to be legit imo though. I’m glad to see a company trying to change things for the better in the privacy realm. That’s always a good thing.

---

## Post 14 by @nym-product — 2025-03-18T22:05:56Z

> [@anon29374801](#):
>
> It looks like they were audited by Cure 53 in July 2024 but [none of their audits have been published.](https://nymvpn.com/en/trust-center/security-audits)

Just FYI that we have published our audits here: [Independently audited](https://nym.com/trust-center/independently-audited). Happy reading!

---

## Post 15 by @anon91547797 — 2025-03-19T07:07:25Z

I’m interested but can’t even test it fully without [support for LAN](https://github.com/nymtech/nym-vpn-client/issues/2288) and a CLI interface for Linux, to use on my headless P2P server.

Definitely one to follow as they develop through. They have a [public roadmap](https://trello.com/b/qVhBo3e2/nymvpn-public-roadmap) if you’re wondering if they plan to support a specific feature.

---

## Post 16 by @nym-product — 2025-03-19T15:22:38Z

> [@anon91547797](#):
>
> without [support for LAN](https://github.com/nymtech/nym-vpn-client/issues/2288)

We’re adding this :+1:

> [@anon91547797](#):
>
> a CLI interface for Linux

You can use the builds in [Release nym-vpn-core-v1.5.3 · nymtech/nym-vpn-client · GitHub](https://github.com/nymtech/nym-vpn-client/releases/tag/nym-vpn-core-v1.5.3). But we can definitely better market this.

---

## Post 17 by @Cyber-Typhoon — 2025-03-26T22:20:50Z

They are starting to make some more appearance

> **["THINGS WILL GET WORSE!" Interview with Harry Halpin - the CEO of Nym...](https://www.youtube.com/watch?v=dVtw-4Eox2E)**
>
> Talking with Harry Halpin about state power, surveillance, authoritarianism and NYM - a new anti-surveillance tool in the making.Support my independent work:...

---

## Post 18 by @anon39279085 — 2025-03-26T22:27:14Z

They literally invited Edward Snowden in their first live launch event remember:  
[https://inv.nadeko.net/watch?v=YnyscVTygOs](https://inv.nadeko.net/watch?v=YnyscVTygOs)  
and they did 3 already, with the third one premiering in 15 hours as of the time writing

> **[- YouTube](https://www.youtube.com/watch?v=e5Ak7UQdybc)**
>
> Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

honestly I daresay they might be putting alot of budget into marketing which might be concerning…

_btw rip no js nadeko invidious, gonna report it on the post that was made on the PG forum_

---

## Post 19 by @bitosi — 2025-03-26T22:55:15Z

> they might be putting alot of budget into marketing which might be concerning…

Yeah. Screw em right? Nobody should know about their product. Imagine having a website even.

---

## Post 20 by @anon39279085 — 2025-03-26T22:55:58Z

I didn’t say screw em, it’s just the rate of it, it _might_  
not _is_

---

## Post 21 by @bitosi — 2025-03-26T22:58:12Z

If you’re 50/50 on if its an issue or not, then im confused why you’d even call it out.

---

## Post 22 by @anon39279085 — 2025-03-26T23:00:30Z

I ask you something similar, why do you obsess about what I said?  
I could be right, I could be wrong that heavy focus on marketing will affect their product. There’s no black and white here in this situation and I would love to be proven wrong.

---

## Post 23 by @bitosi — 2025-03-26T23:09:05Z

> obsess about what I said?

What are you even talking about?

> I would love to be proven wrong.

Since you made no claim theres nothing to prove wrong. I just think its kinda stupid to imply marketing is an issue and then back off by saying “yeah bro idk after all”. Everyone can say “idk man” to anything but then their purpose is to question.

---

## Post 24 by @Nightingale — 2025-03-27T09:57:08Z

Very true. Even if they market it to the moon, I wouldn’t use it until it has been proven in real life like Mullvad. Beautiful animations and big words mean nothing. It could even be a honey pot. Who knows? It might be comparable to something like mullvad after ~10 years of proven track record but as of now, not even close. I would prefer Nord over it, as in that case at least I know what I am getting.

---

## Post 25 by @nym-product — 2025-04-01T17:13:18Z

> [@anon39279085](#):
>
> and they did 3 already, with the third one premiering in 15 hours as of the time writing

To clarify: The April 14, 2022 launch was for the mixnet (i.e. the network infrastructure). This March 13, 2025 launch was for the NymVPN apps / service (i.e. one app / service built on top of said infrastructure).

---

## Post 26 by @dud1337 — 2025-05-26T04:55:57Z

**Not confident (2025-05)**

Are the people’s intentions trustworthy? I strongly believe so.

**I’m not confident there has been pragmatic security talent at Nym thus far.**

- Mad respect to Chelsea; her push for cryptography over tokenisation & perhaps other things she might’ve done.
- Good job outsourcing audits, not having one appsec wizard who quits and suddenly no one knows
- Good job announcing a bug bounty program will start soon
- Fantastic job genuinely giving a shit about privacy.

3 small points that raise enough of an eyebrow for me to pass for now. Juiciest is 3rd.

**1. Bug Bounty Program**

It’s common responsible disclosure programs say already-reported bugs are not rewarded. Yet, Nym want to wait until the Cure53 findings have been fixed (from a Dec 2024 blog).

That’s odd, not crazy-odd, but: Huh? Takes a day to whip up an initial program. Audits can be in remediation, list your scope, responsible disclosure process, contact email, etc. You want to build a community of testers who like your program - the earlier the better.

It’s not a huge deal. It’s a slightly bigger deal they’ve been running for 5+ years without one.

Look up MullVad & iVPN’s reporting pages, on the footer of their main websites. Minimal, sufficient.

**2. No DKIM (at the time of writing)**

- Check dmarcian (website) for nym com & nymtech com _(As a new user, I can only post two links)_

I won’t detail why this is a problem. It has cost other web3 companies significantly in the past.

Again, 5 years in, tech startup, emphasis on security, pretty odd.

- Check dmarcian (website) for mullvad and ivpn

**3. Cure53 July 2024 audit summary (:beverage_box: THE JUICE YOU SEEK :beverage_box:):**  
Available here [here](https://cure53.de/audit-report_nym.pdf).) Hope to see another engagement this year - Good job for organising it & publicising it, Nym team! Props.

> [@Cure53 Team Member](#):
>
> In general, the inspected codebase contains several critical security oversights, including  
> improper signature verification, and inconsistent credential checks. This suggests a need for  
> more rigorous security practices, and code reviews focused on cryptographic  
> implementations. Also, issues such as centralized gateway fetching and hard-coded “fast  
> nodes” indicate some architectural decisions that could limit the system’s resilience and  
> scalability from a holistic perspective. There seems to be a need for more decentralized and  
> dynamic approaches to the overall network design and implementation.
> 
> The lack of such a holistic approach to the system’s overall engineering is also evident from  
> the presence of security checks in some code paths but not others (e.g., Bloom filter  
> checks), as this indicates an inconsistent application of security measures. This suggests  
> the need for more systematic and uniform application of security controls throughout the  
> codebase.  
> Nym’s decentralized approach to servers hopes to mitigate the risk of centralized logging  
> rather than depend on the possibly misleading assurance given by a no-log audit of a  
> centralized entity. However, even decentralized servers can not be meaningfully subjected  
> to a no-logs audit.

**In summary for me:**  
Nym respect security and privacy without question from me. That said, it perhaps has the plague of several academic-led crypto-startups in terms of how to approach security pragmatically.

If I knew someone targeted by the state specifically, I wouldn’t recommend most centralised VPNs. Some do respond to government requests. I would rather recommend a logless mixnet, however, with the little time I’ve devoted to sniffing the current security stature, I wouldn’t recommend this person Nym.

Or I’d say: Check again, after the next major audit.

For the less-targeted, I’d recommend MullVad/iVPN (Never worked for them or any VPN company).

Also of note: Potential ipv6 leaks here (ctrl+F privacy):

- Techradar Nymvpn Review Oct 2024

**Unrelated Old-Man-Yells-At-Cloud Rant:**  
Web3 is largely dog-brained at “Web2” security, and is consistently compromised due to this. Even if your code audits are golden and you’re layer 1: Don’t throw the baby out with the bathwater & don’t end up on rekt.news

---

## Post 27 by @nym-product — 2025-06-12T13:38:02Z

Thanks @dud1337 for the detailed feedback.

**On the bug bounty program** : You’re right, this should be standard practice. We’ve been handling security reports through GitHub/support channels, but a formal program has been ready since March - we just held off due to resource concerns while fixing connectivity issues. It’s launching very soon.

**On DKIM** : Our emails originate from [nymtech.net](http://nymtech.net) with DKIM enabled, so that should be working properly.

**On the Cure53 audit** : Fair point. The team has implemented many of the recommended fixes and we’re continuously improving our security practices. We recently hired a cryptographic engineer to implement new cryptographic protocols securely, optimize existing code, and strengthen our overall security posture.

> however, with the little time I’ve devoted to sniffing the current security stature, I wouldn’t recommend this person Nym.

Regarding ths overall recommendation against Nym - what would you need to see to change that assessment? Always interested in honest feedback from the community!

> Also of note: Potential ipv6 leaks here

That review appears to be from September 2024. The apps have evolved significantly since then, so I’d encourage testing our current versions from [Download NymVPN for macOS | Nym](http://nym.com/download) if you’re interested in a fresh evaluation. Or checking more recent reviews (such as [https://www.zdnet.com/article/nymvpn-review/](https://www.zdnet.com/article/nymvpn-review/)).

---

## Post 28 by @nym-product — 2025-07-07T10:10:20Z

For [@discussion\_moderators](/groups/discussion_moderators) can we consolidate this thread with [Nym and NymVPN - Next-gen privacy with mixnet and VPN service](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072) Thanks!
