You install a VPN to hide your traffic from your ISP, your carrier, the coffee shop router. That part works. But the app you just handed all your traffic to is running more surveillance code than almost anything else on your phone.
That is not speculation. In 2024, Zimperium’s zLabs team analyzed over 800 free VPN apps available on Google Play and third-party stores. The results were consistent across samples: 88% of the apps leaked user data through insecure implementations or deliberate collection. 80% embedded third-party tracking SDKs. 39% contained behavior classified as malware. The very tool people download to protect their privacy was, in most cases, the single largest privacy exposure on their device. (If you want context on how widespread tracker embedding is across all app categories, we covered what four academic studies actually found.)
Why Free VPNs Cannot Be Free
VPN infrastructure costs money. Servers, bandwidth, peering agreements, DDoS mitigation. A single VPN endpoint handling a thousand concurrent connections runs roughly $400 per month in hosting alone. Scale that to millions of users and you need millions in revenue.
Paid VPNs charge $5 to $12 per month. The math is straightforward. Free VPNs charge nothing, which means the revenue comes from somewhere you cannot see. Data brokerage. Ad injection. Surveillance contracts. Selling aggregate browsing profiles to marketing firms. The product is not the VPN. The product is you.
What the Research Actually Found
The Zimperium zLabs analysis went beyond permission lists. The team reverse-engineered APKs, inspected embedded libraries, and monitored actual network behavior. Here is what they reported across the 800+ apps:
- 88% leaked user data. Either through poor implementation (no encryption, DNS leaks) or through intentional collection and exfiltration to third-party servers.
- 80% contained tracking SDKs. Not just analytics. Full attribution and advertising frameworks reporting device fingerprints, location, and usage patterns.
- 60% shared data with third parties. The apps actively transmitted user information to advertising networks and data brokers, not as a side effect but as the core business model.
- 39% exhibited malware-level behavior. Credential harvesting, keystroke logging, screenshot capture, background recording.
- Outdated cryptographic libraries. Multiple apps shipped OpenSSL versions vulnerable to Heartbleed, a flaw disclosed in 2014. A VPN using a broken TLS stack is worse than no VPN at all, because you think you are protected.
- Microphone and screenshot permissions. Dozens of apps requested access to the microphone, camera, or screen capture. None of those permissions have anything to do with routing traffic through an encrypted tunnel.
These numbers align with what our own research data from 3,745 analyzed Android apps shows about tracker density in the broader ecosystem. VPN apps are not uniquely bad. They are just uniquely ironic.
What Is Actually Inside the APK
When you install an app, Android reads its manifest file and unpacks its compiled code. Every third-party SDK the developer included is right there in the bytecode. This is not hidden. It is declared, compiled, and shipped.
Here is what shows up in a typical free VPN APK:
Attribution SDKs. AppsFlyer, Adjust, Branch. These track where you came from, what you do after install, and report that back to the developer and their advertising partners. They assign you a persistent device fingerprint that survives app reinstalls.
Advertising frameworks. Google AdMob, Facebook Audience Network, Unity Ads. These are not just serving banners. They build behavioral profiles based on your app usage, device characteristics, and sometimes your location.
Data broker integrations. Some free VPNs ship SDKs from companies like Kochava or Lotame whose entire business is aggregating user data and selling it. These SDKs collect device identifiers, installed app lists, and browsing patterns.
Analytics beyond analytics. Firebase Analytics is one thing. But when you see Mixpanel, Amplitude, and CleverTap all in the same APK alongside two attribution platforms and an ad network, you are looking at an app whose primary function is data collection, not VPN service.
All of this is declared at build time in the AndroidManifest and compiled into the DEX bytecode. It is not loaded dynamically. It is not injected at runtime. It ships with the app, and it is fully verifiable by anyone who knows how to look. Our scoring model explains exactly how we detect and classify these embedded libraries.
How to Verify Your VPN App Yourself
You do not have to take anyone’s word for it. The tools exist to check for yourself.
1. Scan with AppXpose. Install AppXpose and scan the VPN app on your device. The report will show you every tracker SDK embedded in the APK, every permission requested, and a risk score based on actual bytecode analysis. Compare what the VPN promises in its store listing against what the scan finds. If the app claims “zero logging” but ships with four attribution SDKs, you have your answer.
2. Cross-reference with Exodus Privacy. Exodus Privacy maintains a public database of tracker signatures found in Android apps. Search for your VPN app there for an independent second opinion. If both AppXpose and Exodus flag the same libraries, the evidence is solid.
3. Add network-level blocking with NetGuard. NetGuard is a local firewall that lets you block individual apps from accessing the internet. If you need to keep a VPN app installed but want to cut off its tracking, NetGuard can block the SDK domains while still allowing the VPN tunnel to function. It is not a perfect solution, but it adds a layer.
The important thing is that this is verifiable. You are not relying on a company’s promise. You are looking at the compiled code.
What to Use Instead
If you need a VPN, pay for one. Mullvad charges a flat 5 euros per month with no account, no email, no tracking. ProtonVPN offers a free tier that is genuinely free, subsidized by paying subscribers, with zero third-party trackers in the APK. Both publish independent security audits.
The rule of thumb is old but still accurate: if you are not paying for the product, you are the product. With VPNs, that tradeoff is especially dangerous because you are handing the provider the single most complete record of your internet activity that exists.
Open-source options like WireGuard let you run your own endpoint if you have a server. The setup takes thirty minutes and costs $5 per month in hosting. You control the logs because there are none unless you create them. To see what heavy tracker embedding looks like in popular apps, check the scan results for Instagram or Facebook.
The Bottom Line
The VPN you trust to hide you is probably the most exposed app on your phone. That is not a design flaw. It is the business model. The good news is that it is entirely fixable once you know what to look for. Scan the app. Read the permissions. Count the trackers. If the numbers do not add up, the app is not protecting you. It is profiling you.