Your Free VPN Is Not Free: The Largest Independent Investigation of Free Android VPNs and What It Found

In June 2024 the independent testing lab Top10VPN published the largest public investigation of free Android VPN apps to date: 100 of the most popular free VPN applications on the Google Play Store, with a combined install base of roughly 2.5 billion devices. The findings were bad enough that the report has become a reference document for any subsequent discussion of consumer VPN safety, and the patterns it identified are still driving news in 2026. Eighty-three of the hundred apps leaked DNS requests, which means that the websites a user visited were visible to their ISP or to the network administrator even while the VPN was supposed to be running. Nineteen percent of the apps were flagged as malware by VirusTotal. Eighty-four percent contained third-party tracker SDKs, which means that the apps were not just protecting the user but actively harvesting behavioural data for the ad-tech industry. And ninety-three percent of the apps carried Play Store data safety labels that did not match what the apps actually did. The single most important fact about a free VPN in 2026 is that the product you think you are getting is not the product the vendor is selling.
What was tested
The Top10VPN team installed each of the 100 apps on a clean Android device, ran them through an automated battery of tests including DNS leak detection, IPv4 and IPv6 leak detection, WebRTC leak detection, encryption-strength analysis, third-party SDK identification, and VirusTotal malware scanning, and correlated the results with the apps' Play Store data safety labels. The full per-app dataset was published as a public Google Sheet linked from the report. The headline figures are dramatic on their own, but the individual app findings are where the practical lesson lives.
The most-installed offenders were Turbo VPN at 335 million installs (DNS leak, ad-tracker SDKs), SuperVPN at 250 million installs (DNS leak), Secure VPN at 166 million installs (DNS leak), Psiphon Pro at 141 million installs (DNS leak), and Kaspersky VPN at 117 million installs (background location tracking via Facebook and Huawei SDKs). WiFi Map VPN, at 116 million installs, leaked DNS requests, sent PII in unencrypted HTTP responses to ip-api.com, and exposed its user agent string in plaintext telemetry. VPN Proxy Master, at 84 million installs, leaked both DNS and IPv6, sent PII to an unrelated domain, and bundled Bytedance, Yandex, and Indian and Singaporean ad-tech SDKs.
Encryption failures
Eleven of the apps failed at the most basic level of a VPN's job. One app, VPN Satoshi, transmitted all traffic in plaintext with no encryption at all — every URL, every HTML page, every API request was visible to anyone on the network. Several others used obsolete SSLv2 or TLSv1 ciphers, both of which are considered broken by modern standards. Thunder VPN, despite having more than 91 million installs, used SSLv2 on ancillary connections. Tomato VPN, Urban VPN, VPN Ukraine, VPN Monster, and "VPN — fast secure vpn proxy" all used the same obsolete cipher. Phone Guardian, despite marketing itself as a privacy app, did not encrypt traffic at all and only covered HTTP on untrusted WiFi.
The encryption failures are particularly damaging because they are silent. A user who installs a free VPN and sees the "connected" indicator has no way to tell whether the underlying connection is encrypted, weakly encrypted, or not encrypted at all. The only signal that something is wrong would be a certificate warning in the browser, which is exactly the kind of warning most users have been trained to click through.
DNS and IP leaks
DNS leaks are the most common failure mode for free VPNs, and they defeat the entire purpose of using one. When a VPN leaks DNS, the websites you visit are visible to your ISP's resolver even while the rest of your traffic is encrypted. The Top10VPN team found DNS leaks in 83 of the 100 apps tested, with most of the leaked requests hitting Google or Cloudflare resolvers. The five most-installed DNS leakers were Turbo VPN, SuperVPN, Secure VPN, Psiphon Pro, and Kaspersky VPN. Three apps leaked both IPv4 and IPv6 addresses simultaneously: Tomato VPN, Phone Guardian, and Ultimate VPN. The practical effect is that a user who installs one of these apps to "protect their privacy on hotel Wi-Fi" is in fact no more protected than a user who did not install the app at all.
Several apps also sent PII in unencrypted HTTP responses. Turbo VPN Lite, Speedy Quark VPN, VPN Proxy Master, and WiFi Map VPN each sent the user's real IP address and device information to ip-api.com over plain HTTP. VPN Proxy Speed sent a similar payload to a domain unrelated to the app's stated functionality. The implication is that the apps are not just failing to protect the user but actively feeding the user's real identity to third-party data brokers every time they connect.
Tracker SDKs and data sharing
Eighty-four percent of the apps tested contained third-party tracker SDKs. Twenty-three apps sent the user's real IP address to third-party trackers: Mouse VPN sent IP data to Google, ClearVPN sent IP data to OneSignal, Super VPN shared IP with IronSource and Unity Ads, and NotVPN shared IP with IronSource. Sixty-one apps shared the user's Google Advertising ID with third parties — Turbo VPN, for example, sent its Ad ID to InMobi. Five apps sent the Google Ad ID to their own servers, including Speedify at 12.5 million installs and Zoog VPN at 600,000 installs. Thirty-seven apps shared device fingerprint data including make, model, OS version, screen size, battery state, USB connection, headset state, ISP, SIM country, language, and build number. The combination of fingerprinting, Ad ID sharing, and real IP leakage is the surveillance-tech equivalent of leaving your front door open with a sign on the lawn.
Seven apps bundled the Russian ad-tech SDK myTarget, including Planet VPN, Free VPN Super, Lantern VPN, TLS Tunnel, and Wolf VPN. myTarget is operated by Mail.ru and has been the subject of US sanctions discussions. The presence of a sanctioned SDK inside a consumer VPN is not a hypothetical risk — it is a concrete signal about who is paying for the app and what data they have access to.
Malware flags
Nineteen apps were flagged as malware by VirusTotal. The most common designation was Win32.Troj.Admob.a, which is a Trojan that abuses Google's ad infrastructure to generate fraudulent revenue. The most serious flag was Dropper.Shedun.Android.239430, which drops additional malicious payloads onto the device after installation. Thunder VPN, with 91 million installs, was flagged. VPN – Super Unlimited Proxy, with 93 million installs, was flagged. ClearVPN, the consumer VPN from MacPaw, was flagged. Bitdefender VPN was flagged. HTTP Injector was flagged. The single safest interpretation is that any app on the malware list should not be on your phone.
Play Store data safety labels
Ninety-three of the hundred apps carried Play Store data safety labels that did not match what the apps actually did. Seventy-five misrepresented data collection. Sixty-four misrepresented data sharing. Sixty-five apps claimed "no data sharing" when their privacy policies described data sharing. Thirty-two apps claimed "no data collection" when their privacy policies described data collection. Only five apps had labels that fully matched their privacy policies. Betternet, at 80 million installs, was a notable offender — its label said only "Device or other IDs" while its policy listed account information, billing, usage data, diagnostics, and VPN connection data. The Google Play data safety regime is, in practice, not enforced against VPN apps.
What to use instead
The simplest answer is to pay for a reputable consumer VPN. The five providers we recommend in our Best VPN 2026 article — NordVPN, Surfshark, Proton VPN, ExpressVPN, and PIA — all publish independent no-logs audits from named firms, all run dedicated servers in commercial datacenters rather than borrowing bandwidth from residential proxy networks, and all charge enough that the user's subscription is the product rather than the user's behavioural data. The price difference between a free VPN and a paid VPN is on the order of two to four dollars per month. That is the entire cost of not having your DNS queries logged, your advertising ID sold, or your device enrolled in a botnet.
If you genuinely cannot afford a paid VPN, Proton VPN's free tier is the only free option we can recommend with a straight face. It is funded by the paid tier of the same product, it has published independent audits, and it does not contain the third-party tracker SDKs or the data-sharing behaviour that defined every other free option. The trade-off is that Proton's free tier restricts speeds, location choice, and simultaneous connections, which is the honest way to build a free tier. Every other free VPN we have seen in 2026 either hides the cost in the privacy policy or hides the cost in the advertising SDKs. Both are too high.



