A security researcher discovered that Mullvad VPN's deterministic IP assignment based on WireGuard public keys creates a potential fingerprinting vector, as the same key consistently receives the same exit IP across connections. Testing revealed that despite having trillions of possible IP combinations, only 284 distinct combinations were observed across 3,650 key rotations, significantly reducing anonymity. This finding raises concerns about user tracking and the effectiveness of Mullvad's privacy protections.
Background
Mullvad is a privacy-focused VPN provider known for its strong security practices and no-logs policy. The service uses WireGuard protocol and assigns unique exit IPs to users based on their cryptographic keys.
- Source
- Lobsters
- Published
- May 15, 2026 at 11:40 AM
- Score
- 7.0 / 10