Back to the IVPN review

Research record

What the public record says about IVPN privacy and security

We read what auditors, courts, security researchers and the press have published about IVPN, then kept only the claims that two separate sources back. This is a record of what is published, not a lab test.

Claims researched
30
Cleared for this page
8
Separate sources behind them
5
Research completed
October 3, 2026

What the evidence supports

Claims that two or more separate sources back

Each statement below is followed by the sources it rests on. A verdict describes what the sources say. It is not our endorsement.

Security reviews

Penetration tests and code reviews of the apps and servers.

Sources agree

Cure53's November and December 2019 white-box pentest of IVPN's VPN service, internal servers and web servers (21 person-days, 6 testers) found nine issues (3 High, 2 Medium, 3 Low, 1 Info); IVPN says all were resolved, and Cure53 notes it verified the fix on 8 of the 9.

2 separate sources: Cure53 and IVPN

Sources and caveats (2)
  1. Cure53 (cure53.de) · Audit report · Published January 14, 2020

    The presence of nine issues on the IVPN scope cannot be taken lightly

    Counts toward the two-source rule

    Conflict of interest: Commissioned and paid for by IVPN; IVPN published a redacted copy (vulnerability details removed)

  2. IVPN (ivpn.net blog) · Provider own statement · Published January 23, 2020

    A total of 9 issues (3 high, 2 medium, 3 low, 1 info) were discovered, all of which were either immediately resolved or have since been resolved.

    Counts toward the two-source rule

Researcher notes

The three High issues: IVP-02-005 account takeover through missing CSRF protection (IVPN says the CSRF middleware was commented out and pushed to production by a developer debugging staging); IVP-02-006 vulnerable CRM add-on modules (legacy system reachable only from IVPN's internal network with 2FA); IVP-02-008 SSH-agent use could lead to full network takeover. Also IVP-02-003 'Swap space can lead to unintentional logging' (Info, fixed and verified): a privacy-relevant finding. Cure53 gave a fix note of 'addressed by IVPN and the deployed fix was verified' on 8 of 9; IVP-02-009 (RADIUS weak hashing, Low) carries no fix note. Cure53 also positively rated the VPN topology and OpenVPN configuration. Scope limits stated by IVPN: no access to production VPN servers; a dedicated audit environment replicated production. The published report has vulnerability details removed. IVPN's blog first mis-added the Low count as 1; a comment on the post corrected it to 3 in April 2020.

Sources agree

Cure53's February and March 2021 pentest of IVPN's new desktop apps, daemon and mobile apps (18 person-days, 5 testers) found 14 items: 2 Critical (both root privilege escalation in the daemon), 1 High, 5 Medium, 3 Low, 3 Info; Cure53 notes it verified IVPN's fix on 11 of the 14, including both Criticals.

2 separate sources: Cure53 and IVPN

Sources and caveats (2)
  1. Cure53 (cure53.de) · Audit report · Published March 3, 2021

    parses commands originating there for execution, this Critical problem can be used to escalate privileges to root.

    Counts toward the two-source rule

    Conflict of interest: Commissioned and paid for by IVPN; IVPN published with internal hostnames and code snippets removed

  2. IVPN (ivpn.net blog) · Provider own statement · Published March 12, 2021

    A total of 4 vulnerabilities (2 critical, 2 medium) were discovered, all in the new unreleased desktop app and which were immediately resolved.

    Counts toward the two-source rule

Researcher notes

The two Criticals: IVP-03-007 root escalation via a race on the OpenVPN management port and IVP-03-013 root escalation via unsanitised input into a WireGuard config run with wg-quick. IVPN says all four 'vulnerabilities' (the report's own split: 2 Critical, 2 Medium) were in a desktop app not yet released to customers; Cure53 lists the other 10 items as miscellaneous (including a High, IVP-03-002 buffer overflow in the WiFi notifier, and three more Medium). Of the 14, 11 carry a fix-verified note; IVP-03-004 (Medium, allowedClients bypass on Linux), IVP-03-009 (Info) and IVP-03-010 (false alert) do not, and IVPN's blog says two low-risk items were still being investigated at publication. IVP-03-012 'Firewall allows deanonymization for eavesdropper' (Medium) is a privacy-relevant finding, fixed. Cure53 praised the mobile apps (no insecure logging, encrypted storage). No access to production servers was granted.

Sources agree

Cure53's February and March 2022 pentest of IVPN's apps and daemon found 20 items: 1 High (IVP-04-019, privileged file disclosure via theme icons), 8 Medium, 4 Low, 7 Info, no Critical; Cure53 notes it verified IVPN's fix on 17 of the 20, including the High.

2 separate sources: Cure53 and IVPN

Sources and caveats (2)
  1. Cure53 (cure53.de) · Audit report · Published March 30, 2022

    with one sole High-rated exception unearthed during the IVPN daemon assessment

    Counts toward the two-source rule

    Conflict of interest: Commissioned and paid for by IVPN

  2. IVPN (ivpn.net blog) · Provider own statement · No publication date stated

    We’re pleased to announce that an independent security audit of the IVPN apps conducted by Cure53 has concluded.

    Counts toward the two-source rule

Researcher notes

Cure53 called the overall impression 'mixed', and the mobile apps strong (hardware-backed key storage, no clear-text HTTP). Unmarked as fixed: IVP-04-014 (Medium, VPN manipulation via trust weaknesses), IVP-04-007 and IVP-04-018 (Info). Cure53 said the Medium findings were mostly deep-link, phishing and hardening items. Report text read: index, per-finding fix notes, conclusion; findings bodies not read in full.

Sources agree

Cure53's February 2023 pentest of IVPN's gateway servers and server setup (two testers) found 8 items: 1 Medium (a malformed DNS response crashes the dnsfilter process), 6 Low, 1 Info, and no Critical or High; Cure53 called the security 'in a quite solid state'.

2 separate sources: Cure53 and IVPN

Sources and caveats (2)
  1. Cure53 (cure53.de) · Audit report · Published March 13, 2023

    Cure53 concludes that the inspected IVPN aspects and components appear to already be in a quite solid state of security.

    Counts toward the two-source rule

    Conflict of interest: Commissioned and paid for by IVPN

  2. IVPN (ivpn.net blog) · Provider own statement · No publication date stated

    We’re pleased to announce that an independent security audit of the new IVPN gateway infrastructure has concluded.

    Counts toward the two-source rule

Researcher notes

Scope: the gateway servers and related Go apps (DNS filtering, port forwarding, WireGuard key distribution), Puppet deployment, OS configuration. Findings include IVP-05-004 Go dependencies with CVEs dating to 2019 (Low), IVP-05-005 secret keys present in Git repositories (Low), IVP-05-001 world-readable config template reveals an API key (Low). Cure53 says IVPN fixed several issues during the test; this report has no per-finding fix-verification notes.

Sources agree

Cure53's March 2024 eight-day pentest of IVPN's customer website and API found 4 items (3 titled Low, 1 Info; Cure53 counts two Low vulnerabilities plus two general weaknesses), none higher; the report calls the posture substantially secure.

2 separate sources: Cure53 and IVPN

Sources and caveats (2)
  1. Cure53 (cure53.de) · Audit report · Published April 8, 2024

    the testing team detected minimal security concerns during this engagement, attesting to a framework that is effectively capable of resisting the vast majority of breach and threat circumstances.

    Counts toward the two-source rule

    Conflict of interest: Commissioned and paid for by IVPN

  2. IVPN (ivpn.net blog) · Provider own statement · No publication date stated

    We’re pleased to announce that a sixth annual independent security audit has concluded.

    Counts toward the two-source rule

Researcher notes

Findings: IVP-06-001 VPN config generator query parameters unsanitised (Low), IVP-06-003 world-readable config file reveals a private key (Low), IVP-06-002 no Content-Security-Policy header (Info), IVP-06-004 no email confirmation for user accounts (Low). Cure53 itself notes the small scope and minimal attack surface contributed to the low count. No fix-verification notes in this report.

Incidents and vulnerabilities

Breaches and published software flaws, and how they came to light.

Sources agree

BTCPay Server, open-source payment software, disclosed on 7 August 2026 a critical flaw (all versions before 2.4.2) that let an unauthenticated attacker read LND Lightning credentials; attackers exploited it before disclosure and stole merchants' funds.

2 separate sources: BTCPay Server Blog and CoinDesk

Sources and caveats (2)
  1. BTCPay Server Blog (BTCPay Server project) · Provider own statement · Published August 7, 2026

    We have confirmed that attackers exploited this vulnerability. Users were affected and funds were stolen.

    Counts toward the two-source rule

    Conflict of interest: Software vendor describing its own flaw; does not name IVPN or any other merchant

  2. CoinDesk · Press report · Published August 8, 2026

    BTCPay confirmed funds were stolen and told anyone running LND, the most widely used software for operating a Lightning node, to update immediately to version 2.4.2 or take the server offline.

    Counts toward the two-source rule

    Conflict of interest: None seen. Quotes BTCPay's X post and two named victims (Foundation CEO, Citadel21); does not name IVPN

Researcher notes

Context claim for T2-02: this is the flaw IVPN says it was hit by. CoinDesk adds two named victims (hardware-wallet maker Foundation, publication Citadel21) who reported their own nodes swept. Neither source names IVPN. BTCPay says only LND deployments were exposed and that on-chain wallets were not affected; a full postmortem was promised and was not read.

Transparency

What the provider publishes about requests and bug reports.

Sources agree

IVPN's apps and website are open source (GitHub organisation ivpn); Privacy Guides notes the apps have been open source since February 2020.

2 separate sources: IVPN and Privacy Guides

Sources and caveats (2)
  1. IVPN (ivpn.net) · Provider own statement · No publication date stated

    This website and the IVPN app for all platforms are open-source for additional transparency and security.

    Counts toward the two-source rule

  2. Privacy Guides · Analysis · No publication date stated

    As of February 2020 IVPN applications are now open source.

    Counts toward the two-source rule

    Conflict of interest: None seen: states no sponsors or ads. Editorial recommendation list, not a test report; IVPN entry text last checked 2025-10-28 per the page

Researcher notes

Repositories were not cloned or checked for build reproducibility; server-side VPN gateway code and the dnsfilter are described by Cure53 as Go apps deployed with Puppet but their openness was not confirmed. Cure53 audited from source (white-box, 2021 to 2024).

Sources agree

IVPN accepts cash and Monero (and Bitcoin) as well as cards and PayPal.

2 separate sources: IVPN and Privacy Guides

Sources and caveats (2)
  1. IVPN (ivpn.net) · Provider own statement · No publication date stated

    We also accept cash, monero and bitcoin.

    Counts toward the two-source rule

  2. Privacy Guides · Analysis · No publication date stated

    Accepts Cash and Monero

    Counts toward the two-source rule

    Conflict of interest: None seen: states no sponsors or ads. Editorial recommendation list, not a test report; IVPN entry text last checked 2025-10-28 per the page

Researcher notes

The Privacy Guides quote is the entry's feature heading; the body adds card and PayPal and Bitcoin. IVPN's own incident post notes Lightning, on-chain Bitcoin, Monero, card and PayPal.

What we cannot yet show

Where the record is thin

A claim stays off this page until two separate sources back it and an editor has cleared its wording. Each dot is one claim we researched. A filled dot is on this page. A hollow dot is not, yet.

  • Logging and no-logs audits0 of 3 shown
  • Security reviews5 of 7 shown
  • Servers and protocols0 of 2 shown
  • Ownership and jurisdiction0 of 4 shown
  • Incidents and vulnerabilities1 of 6 shown
  • Legal actions0 of 3 shown
  • Transparency2 of 5 shown

Not shown means one of two things: fewer than two separate sources, or still waiting for an editor to settle the wording or check a document. It does not mean the claim is false.

How this feeds the Trust Score

The evidence trail behind the number

The Trust Score has a criterion for security track record: audits, breaches and incidents. This page is the written trail for that kind of question, showing what was published, by whom, and how many separate sources agree.

Points are still assigned by the published formula. Read how in the methodology.

How the Trust Score works

See every published research record

How we research

Four rules we hold ourselves to

  1. Two separate sources, minimum

    Two outlets repeating one press release count as one source. Independence is decided by where the information came from, not by how many sites carry it.

  2. Primary documents first

    Auditor reports, court filings and regulator records come before commentary. A provider own page is evidence of what the provider says, never proof that it is true.

  3. Nothing found is a result

    When a search turns up nothing we record what we searched. We never present an empty search as a clean bill of health.

  4. No softening for partners

    A finding that the evidence qualifies is recorded as qualified, whoever the provider is.

VPN.com does not run its own testing lab. Every audit listed here was commissioned and paid for by the provider it examined, and we say so where it applies. We earn commission from some providers; see our disclosures.Read our disclosures