Proton VPN Free is the best overall free VPN in this evidence-based comparison because it combines unlimited data, no advertising, open-source applications, and recurring independent no-logs audits. Windscribe Free is better for multiple personal devices, while hide.me is a strong alternative when unlimited data and no-email signup matter.
The important word is not just “free.” Every no-cost VPN imposes a trade-off somewhere, whether that means restricted server choice, a monthly data allowance, fewer features, one simultaneous connection, or an account requirement. This guide compares those limits using current provider documentation verified on September 8, 2026. No first-hand speed, latency, or streaming tests were supplied, so none are presented as our own results.
Quick Take: Best Free VPNs at a Glance
The table below focuses on what actually changes when you pay $0. Compare the data allowance first, then look at simultaneous connections, server choice, registration requirements, and the strength of the provider’s privacy evidence.
Best free VPN services compared by data limits, devices, registration, and free-tier restrictions
Rank
VPN
Free data
Connections
Registration
Best for
What you give up
1
Proton VPN Free
Unlimited
1 device
Account required
Always-on free use
Automatic connection to a limited free-server pool and fewer advanced features
2
Windscribe Free
2 GB/month without email; 10 GB/month with confirmed email
Unlimited personal devices
Email optional
Multiple devices and advanced controls
Monthly data cap and smaller server pool
3
hide.me Free
Unlimited
1 connection
No email or card required
Unlimited use without signup
Restricted speeds, limited locations, and no streaming-optimized servers
4
PrivadoVPN Free
10 GB full-speed allowance every 30 days, then restricted emergency/Lite access
1 connection at a time
Verified email required
Defined higher-speed workloads
Limited locations, one active device, and reduced post-cap performance
5
TunnelBear Free
2 GB/month
Current free-plan documentation does not clearly state a separate simultaneous-device allowance
Account required
Light occasional use
No country selection or split tunneling on the standard free tier
Proton VPN is the easiest recommendation when one device needs continuous protection because there is no monthly data ceiling. Windscribe becomes more attractive when several personal devices need VPN access. hide.me also removes the data cap, but its free tier restricts speed and location choice.
Advertisement
How We Evaluated Free VPN Services
Privacy Comes Before Price
A virtual private network, or VPN, creates an encrypted connection between your device and a VPN server. That can prevent the local network or internet service provider from directly inspecting traffic inside the VPN tunnel, but it also means the VPN operator occupies an important position in your network path.
That trust should not be granted simply because an application appears in an app store. The Federal Trade Commission’s VPN privacy guidance warns that VPN apps can receive extensive access to internet traffic and that some free services may fund themselves through advertising or information sharing. The FTC also notes that a VPN does not make a person completely anonymous.
For this reason, a free VPN gets more credit here when its privacy claims have evidence beyond marketing language. Useful signals include published source code, independent security assessments, no-logs audits, transparent descriptions of retained account data, and clear explanations of how the free service is funded.
An audit still has limits. It examines a defined system at a particular time. It does not guarantee that a provider can never make a configuration error, suffer a vulnerability, or change its practices later.
Advertisement
Data Caps and Speed Limits Are Not the Same Thing
A data cap is the total quantity of data you are allowed to transfer over a period. A speed limit restricts how quickly that data can move. The distinction matters because providers use both approaches.
For example, a 10 GB free VPN could run at normal available speed until that 10 GB is consumed. An unlimited-data service can remain connected indefinitely but may restrict free-user speeds or give paid customers more capacity.
Server congestion is another variable. Even when a provider says it does not impose a formal speed cap, a heavily used free server can still be slower because many customers share finite network resources. That is why this article does not translate “no speed limit” into a guarantee of a particular throughput.
Free VPN Business Models Matter
The most understandable free-VPN model is freemium. A freemium provider offers a restricted service at no cost and funds it partly from customers who upgrade to paid subscriptions.
Advertisement
That model explains why a free account might receive 10 GB instead of unlimited data, fewer server locations, or one connection rather than ten. It does not prove that the provider is secure, but it provides a clear economic reason for maintaining the free tier without needing to monetize browsing activity.
The evaluation therefore considers both technical restrictions and the transparency of the privacy model. A large free allowance does not compensate for unclear data handling.
The Best Free VPN Services in 2026
1. Proton VPN Free: Best Overall
Proton VPN Free takes the top position because its most important limitation is not data volume. The provider currently offers unlimited free data with no stated time limit, no advertising, and one simultaneous device.
The free application automatically connects to a server from Proton’s limited free-server pool rather than giving users the full location control of a paid account. Current official documentation identifies automatic free connections across the United States, Netherlands, Japan, Poland, Romania, Canada, Norway, Mexico, Singapore, and Switzerland. Proton also notes that free servers can become busy.
Advertisement
That makes the free plan especially practical for one laptop or phone that stays connected for long periods. You do not have to calculate whether normal browsing, software updates, cloud synchronization, or occasional video use will exhaust a monthly quota.
The privacy evidence is also stronger than a simple no-logs statement. Proton’s apps are open source, and its free-plan documentation states that the free service has no data limit and uses the same core privacy protections. Proton also publishes a recurring no-logs audit record, updated in June 2026 to include its fifth consecutive annual assessment.
The main compromise is control. Free users receive automatic server selection and do not receive the complete paid server network or features such as Secure Core, BitTorrent support, and Proton’s full premium server choices.
Best fit: one user who wants to leave a VPN connected without watching a data meter.
Look elsewhere if: you need several simultaneous devices or precise control over your exit country.
2. Windscribe Free: Best for Multiple Devices and Controls
Windscribe Free is a better fit when device count matters more than unlimited data. The free account can be used across unlimited personal devices, while the baseline monthly allowance depends on whether you provide an email address.
You receive 2 GB per month without an email. Confirming an email increases that allowance to 10 GB per month. Windscribe also runs optional promotions that can increase the cap, but those conditional bonuses are not treated as the standard allowance in this comparison.
Advertisement
The free tier includes more technical controls than many no-cost competitors. Current free-plan documentation lists its firewall leak protection, multiple VPN protocols, split tunneling, and limited R.O.B.E.R.T. domain filtering alongside a smaller server pool.
Windscribe is also unusually explicit about operational records. For free accounts, it says it retains the total bandwidth used during the current period so it can enforce the cap, plus a last-activity timestamp used to remove abandoned accounts. It states that it does not retain browsing destinations, DNS queries, or traffic-linked session histories.
This is a useful example of why “no logs” should not be interpreted as “no operational information of any kind.” A provider with a 10 GB cap needs some mechanism to determine when the account reaches 10 GB.
The biggest weakness is obvious: 10 GB can be generous for web browsing but restrictive for heavy video, large downloads, operating-system updates, or continuous cloud synchronization.
Advertisement
Best fit: users who want to protect several personal devices and value configuration controls.
Look elsewhere if: you expect to keep the VPN active during large data transfers every day.
3. hide.me Free: Best Unlimited-Data Alternative
hide.me is the strongest direct alternative to Proton for users who dislike monthly data caps. Its current free plan provides unlimited data, allows one simultaneous connection, and does not require an email address or payment card.
That last point creates a meaningful difference. A user can install the client and begin using the free service without tying the VPN account to an email address. The trade-off is that the free tier has restricted speed and a much smaller location pool than the paid service.
Current hide.me pages are not completely consistent about whether the free tier exposes seven or eight locations. Its pricing and free-VPN pages say eight, while one support comparison updated in 2026 lists seven named server locations. Because the provider’s own documentation conflicts, this article treats the exact count as changeable rather than presenting one number as definitive.
The provider has stronger privacy evidence than most free products. Its no-logs documentation describes independent assessments of its logging implementation and provides access to audit material. A 2024 Securitum assessment examined areas including server configuration, deployment processes, and the standardized VPN environment used by the service.
That audit is valuable evidence, but it remains a point-in-time assessment. It should not be interpreted as a permanent security certificate.
Advertisement
Best fit: one-device users who want unlimited data and prefer not to provide an email address.
Look elsewhere if: you need predictable high throughput, several simultaneous devices, or specialized streaming servers.
4. PrivadoVPN Free: Best for Defined Higher-Speed Workloads
PrivadoVPN Free uses a different model. Instead of offering unrestricted full-speed usage, it provides 10 GB of data every 30 days on its normal free service and then offers restricted emergency or Lite-mode connectivity after that allowance is consumed.
Current pricing documentation states that free users receive 10 GB every 30 days, access to a limited group of server locations, and one connection at a time. Its support documentation says older post-cap behavior limits the connection to 1 Mbps, while a January 2026 product guide describes the transition more generally as Lite Mode with adjusted performance parameters.
Advertisement
Because those descriptions are not perfectly aligned, the defensible conclusion is that full-speed usage is restricted after the 10 GB allowance. The exact post-cap behavior should be verified in the current application rather than treated as a permanent fixed number.
PrivadoVPN requires a verified email but not a credit card for its free account. Its applications can be installed on multiple supported devices, although only one free connection can be active at a time. That distinction prevents a common misunderstanding between “works on unlimited devices” and “unlimited simultaneous connections.”
The company states that the same no-log policy applies to free and paid users. However, a sufficiently strong current public independent no-logs assessment did not surface during this research pass, so this article treats that as a vendor claim rather than independently verified assurance.
Best fit: someone who needs a modest amount of normal-speed VPN traffic and can monitor the 10 GB allowance.
Look elsewhere if: public audit evidence or unlimited normal-speed data is a higher priority.
5. TunnelBear Free: Best for Light Occasional Use
TunnelBear’s free plan is increasingly best understood as a limited entry point rather than a full-time free VPN. It currently includes 2 GB of encrypted data per month.
The allowance is enough to learn the interface, protect occasional browsing, or cover a short period on an unfamiliar network. It can disappear quickly when large downloads, cloud backups, application updates, or video are involved.
Advertisement
TunnelBear also changed the free tier materially heading into 2026. Its December 2025 free-account announcement moved country selection and SplitBear split tunneling into the paid experience for ordinary free users. Free accounts retain VPN connectivity along with features such as VigilantBear and GhostBear.
The service has a substantial security-audit history. Cure53 has repeatedly examined TunnelBear applications, infrastructure, backend systems, server configurations, public-facing interfaces, and data-handling components. That transparency is meaningful, although the company’s own publications contain an inconsistency in how they number the most recent audit years. For that reason, it is more accurate to describe a long-running annual audit program than claim a precise total.
Best fit: occasional users who want a small free allowance from a provider with an established public security-assessment history.
Look elsewhere if: you want continuous protection, control over the exit country, or more than 2 GB every month.
What Does a Free VPN Actually Cost?
A $0 subscription still has an economic cost. The difference is that the provider collects it through restrictions rather than a payment at checkout.
The five services above show the main ways that happens.
Common free-VPN trade-offs and examples from current free plans
Trade-off
What it means
Current example
Data allowance
You can transfer only a fixed amount each month before the service stops or changes behavior
Windscribe and PrivadoVPN use monthly allowances; TunnelBear provides 2 GB
Server choice
You receive fewer countries or less control over the exact exit location
Proton automatically assigns free servers; all five restrict locations compared with paid service
Device limit
Only one active device may use the account at a time
Proton, hide.me, and PrivadoVPN limit the free tier to one active connection
Account information
More allowance may require registration details
Windscribe increases 2 GB to 10 GB when a user confirms an email
Feature restrictions
Advanced routing or location controls stay behind the paid tier
TunnelBear moved country selection and split tunneling to paid plans
Performance priority
Free infrastructure may be restricted or more congested
hide.me documents restricted free-tier speeds; Proton warns that free servers can become busy
These are not necessarily deceptive restrictions. Running VPN infrastructure costs money. The relevant question is whether the provider explains its boundary clearly enough for you to decide whether the free tier fits your workload.
Advertisement
Are Free VPNs Safe?
Some are defensible choices. The category as a whole is not automatically safe.
A VPN occupies a privileged position because traffic is intentionally routed through infrastructure operated by the provider. The encryption protects the connection between your device and the VPN server, but it does not remove the need to trust whoever operates that server.
This is why a credible free service should be evaluated using more than a lock icon and a statement such as “military-grade encryption.” Encryption can protect the tunnel while a poor privacy policy still permits problematic collection elsewhere.
Before installing a free VPN, check the following:
Advertisement
Identify the actual company. Know who operates the app and where its privacy policy applies.
Read what it collects. Separate browsing or connection logs from account information, crash diagnostics, bandwidth counters, and support records.
Understand how the free tier is funded. A paid upgrade model is easier to evaluate than an unexplained product with no obvious source of revenue.
Look for independent evidence. Public audits do not guarantee perfection, but they are stronger than an unsupported assertion that the service keeps no logs.
Check permissions. A VPN needs networking privileges, but unrelated access requests deserve scrutiny.
Verify the official download source. Install from the provider’s real website or its verified app-store listing rather than an advertisement or unofficial download mirror.
Check the free-tier security boundary. Determine whether free accounts use the same encryption and protocols or a technically different network implementation.
A free VPN also does not make an unsafe device safe. Malware can still run locally. A phishing site can still steal credentials you enter voluntarily. Cookies can still recognize your browser, and logging into an account can identify you regardless of the VPN exit address.
The practical goal is therefore narrower: protect a network path, reduce exposure to the local network and internet provider, and change the public IP address destinations normally see. Do not treat a VPN as an anonymity system or complete cybersecurity package.
Free VPN Limits That Matter in Practice
Some restrictions sound minor on a pricing page but become important during everyday use. The following table translates them into operational consequences.
How common free-VPN restrictions affect real usage
Limit
What happens in practice
Who should care most
2 GB data cap
Large downloads or prolonged video can consume the monthly allowance quickly
Video viewers, cloud-storage users, software developers
10 GB data cap
Comfortable for moderate browsing but still requires monitoring during heavier workloads
Travelers, students, remote workers
One connection
A phone and laptop cannot both stay protected through the same free account simultaneously
Multi-device users
Automatic server assignment
You cannot reliably choose a specific country whenever you connect
Travelers and users with jurisdiction-sensitive requirements
Restricted speed
Large transfers, video calls, and high-resolution media may feel less responsive
Heavy data users
No streaming servers
Provider-specific optimized infrastructure is unavailable on the free tier
Media users
No split tunneling
You may be unable to choose which applications bypass the VPN
Users of local-network devices or apps that reject VPN connections
A restriction also interacts with your device behavior. An operating-system update or cloud-photo upload can consume data without looking like deliberate VPN usage. If you select a capped plan, check whether background applications are transferring large amounts of data.
When You Should Not Use a Free VPN
A free VPN is useful when the workload fits its limits. There are cases where choosing one primarily because it costs $0 creates more friction than value.
Advertisement
Warning!
You regularly transfer large volumes of data. Monthly caps can make a free plan impractical, while speed-restricted unlimited tiers may not meet the workload.
You need several devices connected continuously. A one-device plan creates repeated disconnect-and-reconnect management.
You require a specific exit country. Automatic assignment or a small location pool may not provide the jurisdiction you need.
You depend on business support. A paid or managed service is normally more appropriate when downtime affects work.
Your employer provides a managed VPN. A company’s remote-access VPN is designed to connect authorized devices to company systems. It serves a different purpose from a consumer privacy VPN.
You face a high-risk targeted threat. Journalists, activists, political targets, or people facing sophisticated surveillance should use threat-model-specific professional guidance rather than assume that any general consumer VPN provides complete protection.
Public Wi-Fi is another case where the VPN should be only one layer. You should still confirm the correct network, update your device, disable unnecessary automatic connections, and protect important accounts with multi-factor authentication. Our public Wi-Fi safety guide covers those precautions separately.
If you routinely exceed free-tier limits, compare the restrictions against a full consumer VPN plan rather than creating multiple free accounts or constantly switching providers.
How to Choose a Free VPN
The simplest way to choose is to identify the restriction you are least willing to accept.
Decide whether you need unlimited data. If yes, start with Proton VPN Free or hide.me rather than a capped plan.
Count the devices that must be connected at the same time. Windscribe is the clearest choice here because its free tier supports unlimited personal devices.
Decide whether you want to provide an email. hide.me requires no signup, while Windscribe works without an email at a reduced 2 GB allowance.
Check server control. Do not choose Proton Free if manually selecting a specific country is essential to the workflow.
Inspect the privacy evidence. Prefer published audits, transparent logging explanations, and open-source software where available.
Check your operating system. Confirm that the provider supports the exact Windows, macOS, Linux, Android, iOS, browser, TV, or router environment you plan to use.
Identify what happens at the limit. Some VPNs stop normal usage, while others provide restricted fallback connectivity.
Download from an official source. Avoid lookalike websites, unofficial APK repositories, and sponsored search results whose domain does not match the provider.
For a concrete example, a person protecting one laptop during a month-long trip can prioritize Proton’s unlimited allowance. Someone switching among a phone, tablet, and laptop may prefer Windscribe even though the monthly cap is lower. A user who wants no email attached to the service may prefer hide.me.
If speed becomes the main problem after installation, that is a separate diagnostic issue involving server load, route distance, protocol choice, local congestion, and device performance. Check our VPN slowdown troubleshooting guide to fix the issue.
Advertisement
Key Takeaways
Proton VPN Free is the strongest overall option when unlimited data on one device matters most.
Windscribe Free is the better choice for several personal devices, but its standard allowance is 2 GB without an email or 10 GB with a confirmed email.
hide.me combines unlimited data with no-email signup, although the free tier restricts speed and location choice.
PrivadoVPN provides a useful 10 GB full-speed allowance but restricts users to one active free connection and limited locations.
TunnelBear’s 2 GB plan is best treated as an occasional-use tier rather than an always-on free VPN.
Do not assume that “no logs” means no operational account data at all. Read what a provider actually retains.
A free VPN should explain how it funds the service and what changes between free and paid accounts.
No consumer VPN makes you completely anonymous or replaces device security, account protection, HTTPS, or safe browsing habits.
Frequently Asked Questions
Which free VPN does not require a credit card?
None of the five services in this comparison requires a credit card merely to use the standard free tier. Account requirements differ, however. hide.me does not require an email or payment information, Windscribe can be used without an email at the lower 2 GB allowance, and PrivadoVPN requires a verified email.
Is there a free VPN with unlimited data?
Yes. Proton VPN Free and hide.me currently provide unlimited data. They impose different restrictions instead. Proton limits the free account to one device and automatically assigns servers from its free pool. hide.me permits one connection and limits free users by speed and server choice.
How long will 10 GB of free VPN data last?
There is no single duration because usage depends on what your applications transfer. Reading websites and messaging generally consume much less data than high-resolution video, game downloads, cloud backups, or operating-system updates. A 10 GB allowance may cover substantial lightweight browsing but can be consumed quickly by large media or file transfers.
Can I use one free VPN account on several devices?
It depends on the provider’s simultaneous-connection rule. Windscribe Free supports unlimited personal devices. Proton VPN Free and hide.me allow one active free connection, while PrivadoVPN allows installation on multiple devices but only one connection at a time. Always distinguish how many devices can install an app from how many can remain connected simultaneously.
Will a free VPN work if my internet provider blocks VPN connections?
Possibly, but there is no universal result. Some providers offer obfuscated or stealth protocols designed to make VPN traffic less obvious to restrictive networks. Blocking methods vary, and a protocol that works on one network may fail on another. Free tiers may also expose fewer anti-censorship options than paid plans.
Advertisement
Can a free VPN see my passwords?
A reputable VPN normally cannot read passwords sent through a properly configured HTTPS connection because HTTPS encrypts the content between your browser or app and the destination service. The VPN provider can still occupy an important position in the network path and may observe some connection metadata depending on its architecture and logging practices. This is another reason to choose a provider carefully rather than trusting any free VPN application.
Is a free VPN browser extension the same as a full VPN app?
Not always. A full VPN application can route traffic from the operating system and multiple applications through the encrypted tunnel. A browser extension may protect or proxy only browser traffic. Some extensions described as VPNs operate as proxies rather than full device-level VPN tunnels, so check the provider’s documentation before assuming the protection covers every application on the device.
Is a free VPN better than a paid VPN for occasional travel?
It can be. If you need VPN protection only for light browsing during a short trip, a reputable free plan may provide enough data and locations without a subscription. Paid service becomes more useful when you need predictable location choice, several devices, large transfers, advanced routing features, or consistent long-term support.
The Metric Is Not the Mission is a ten-part examination of how Big Tech moved from building and expanding the open internet to increasingly shaping it around its own metrics, incentives and assumptions. Across the series, the argument follows the evolution of the platform economy—from the optimism of the early internet to the growing tensions around power, prediction, geopolitics, accountability and the future of digital life.
The series will be published in two parts each week over five weeks, with each installment building on the one before it. At the end of the series, the complete essay will be brought together in a single PDF edition, providing the full argument in one place.
Part III: When the Maps Became the Territory
In Part II, the story turned on a crucial distinction: measuring behavior is not the same as understanding people. Part III takes that idea further, examining what happens when the platforms’ representations of the world begin to substitute for the world itself.
There is a curious tendency among successful technologies to disappear. Not physically, of course, but cognitively. Once they become sufficiently embedded in everyday life, they cease to be experienced as technologies at all. Electricity is no longer a marvel of engineering but an expectation. We do not admire the plumbing each time we turn on a tap, nor do we reflect on the extraordinary complexity of global logistics every time fresh fruit appears on supermarket shelves in the middle of winter. The greatest infrastructures become invisible because they succeed so completely that we mistake them for part of the natural order.
Advertisement
The internet reached that point sometime during the second decade of the twenty-first century. Yet something else happened along the way that proved far more consequential. As the network itself faded into the background, the platforms through which most people experienced it moved decisively into the foreground. Increasingly, users no longer spoke about “going online.” They spoke about opening an app.
That linguistic shift deserves more attention than it usually receives. Language often reveals structural change before statistics do. To “browse the web” implied movement across an open landscape whose boundaries were undefined. One followed links, discovered obscure websites, stumbled upon ideas that had not been recommended by anyone, and occasionally became gloriously lost. The experience resembled wandering through an unfamiliar city with no particular destination in mind. Serendipity was not a flaw in the architecture; it was one of its defining virtues.
Applications altered that relationship almost without anyone noticing. They replaced geography with destination. Instead of entering a network whose possibilities remained unknown, we entered environments that had already been organized on our behalf. The internet did not disappear, but it became increasingly hidden beneath layers of interface, recommendation and curation. Like passengers traveling through an airport without ever seeing the city beyond the terminal, we continued moving through digital space while encountering only the carefully managed environments that had been prepared for us.
This transformation is often described as an inevitable consequence of convenience. While accurate in its own right, this explanation offers an incomplete narrative. Convenience was certainly the language through which the platforms justified many of their design choices. Friction was treated as the great enemy of the digital age. Every additional click became an obstacle to be eliminated. Every decision that users might otherwise make for themselves could instead be anticipated by software. Recommendation replaced search. Autoplay replaced choice. Infinite scrolling replaced endings. The future, we were told, belonged to experiences so seamless that they would feel almost effortless. And they did.
Advertisement
It is difficult to criticize convenience because convenience is genuinely valuable. Few people wish to return to an internet in which finding information required memorizing obscure web addresses or navigating labyrinthine directories. The platforms did not succeed by forcing people into inferior experiences. They succeeded because, for many years, they built better ones.
Yet convenience has always carried an intellectual cost. Every technology that removes friction also removes moments of deliberation. The elevator spares us the staircase but also the awareness of distance. Satellite navigation ensures that we rarely become lost, while quietly diminishing our ability to construct mental maps of the places through which we travel. Streaming services relieve us of searching for entertainment, but in doing so they also shape the boundaries of what we are likely to discover. Every act of technological simplification transfers a small measure of agency from the individual to the system.
The internet had originally been built on a different assumption. Its underlying protocols did remarkably little. They did not decide which website deserved prominence, which ideas should travel furthest, or which communities ought to flourish. Their genius lay precisely in their restraint. They created conditions under which others could innovate without first requesting permission. The web itself functioned less like a product than like a constitutional order: a simple framework within which extraordinary diversity could emerge.
Platforms gradually adopted the opposite philosophy. They did not merely provide the rules of the game; increasingly, they became active participants in every interaction taking place within it. They selected what deserved attention, inferred what users might prefer before users themselves knew it, prioritized certain relationships over others and determined, through millions of microscopic computational decisions, the contours of everyday experience. The architecture became less constitutional than managerial.
Advertisement
There is an illuminating parallel here with the history of cities. The most enduring cities are rarely the ones that have been planned in every detail. They are those that accumulated layer upon layer of human activity over centuries, adapting continuously to changing needs without ever fully surrendering their unpredictability. One finds unexpected bookshops beside cafés, workshops hidden behind apartment blocks, public squares appropriated for demonstrations one week and festivals the next. Their vitality emerges not from perfect organization but from the freedom they grant people to appropriate space in ways that planners never anticipated.
Shopping malls operate according to an altogether different logic. They are meticulously designed environments in which every entrance, corridor, sightline, and seating area has been carefully considered. Music, lighting, and architecture work together to produce an experience that feels spontaneous while being anything but. There is comfort in their orderliness. They are clean, efficient, and reassuringly predictable. Yet no one mistakes a shopping mall for a city. Its purpose is not to cultivate civic life but to optimize a particular set of behaviors within a privately governed space.
The analogy is imperfect, as all analogies are, but it captures something essential about the transformation of the internet. The early web invited participation because it remained fundamentally unfinished. It assumed that users would contribute to shaping it. Today’s dominant platforms present themselves as complete worlds. Participation still exists, but it takes place within boundaries established elsewhere. Users generate the content while the architecture remains firmly in corporate hands.
Perhaps this is why the language of “community” has begun to feel strangely hollow. Communities, in the classical sense, are rarely designed. They emerge through shared experience, mutual obligation, and a degree of unpredictability that no algorithm can fully reproduce. Platforms, by contrast, increasingly treat community as an engineering problem to be optimized. They recommend friendships, suggest conversations, rank relevance, suppress friction, and amplify interaction according to models whose objectives are necessarily commercial because the organizations that develop them are commercial enterprises.
Advertisement
None of this should be understood as an accusation of bad faith. Many of the engineers responsible for these systems genuinely believed they were improving people’s lives. The difficulty lies elsewhere. Every large institution eventually begins to confuse the optimization of its own internal metrics with the fulfillment of its original purpose. Universities sometimes mistake publication counts for scholarship. Hospitals occasionally confuse efficiency with care. Governments become preoccupied with administrative process rather than public service. Technology companies are no different. The indicators that make sense within an organization slowly become proxies for the world outside it. The metric is not the mission. This is the point at which the maps begin to replace the territory.
The extraordinary quantities of behavioral data collected by digital platforms produce an understandable confidence. When one can observe billions of interactions each day, it becomes tempting to believe that society itself has become legible. Human behavior appears measurable, predictable and, increasingly, governable. The platform begins to resemble reality because so much of reality passes through the platform.
Yet the map is never the territory. It captures what can be measured, not everything that matters. A map records roads but not the reasons people travel. It identifies cities without conveying the lives unfolding within them. Likewise, recommendation systems observe behavior with astonishing precision while remaining largely indifferent to experience itself. They recognize patterns without necessarily understanding meaning.
That distinction mattered little while the platforms continued solving the problems that had made them indispensable. It becomes far more consequential once they begin confronting a world that no longer resembles the one for which they were originally designed. Because societies have changed; politics has changed; and, the internet has changed. The question is whether the companies that grew powerful by interpreting one era have noticed that another has already begun.
Advertisement
Konstantinos Komaitis, PhD, is a veteran of developing and analysing Internet policy to ensure an open and global Internet.
While smartphones won’tstop getting bigger, e-readers seem to be getting smaller. Boox has been at the forefront with one of the most popular small e-readers, the Boox Palma, and now it is adding an even smaller model.
Boox announced the Picco, with preorders opening today. Its screen is just under 4 inches (3.97 to be exact), making it about the size of a playing card. It’s even smaller than the Xteink X4 Pro I tested earlier this year, which has a 4.3-inch screen (but just slightly larger than the 3.7-inch Xteink X3), and considerably smaller than the upcoming Boox Palma 3’s 6.19-inch screen. I liked the size of the Xteink in my hand, but navigating the interface and getting books were challenging, so I’m excited to see another option in that smaller size from a maker with more accessible ebooks (though still not as convenient as a Kindle or Kobo with their built-in stores).
The Picco will cost $100 and is expected to ship in November. I’ll be testing it soon, but in the meantime, here are the details if you’ve been eyeing a tiny e-reader.
An E-Reader for Productivity
Courtesy of Boox
The Boox Picco has a monochrome screen with a resolution of 235 pixels per inch and an adjustable front light that switches between warm- and cool-toned lighting. The microSD card slot supports up to 2 TB of flash memory storage (a 16 GB card is included). There are both a touchscreen and physical page-turning controls, thanks to the buttons on the side of the device. The case has a magnetic ring so you can attach it to the back of a smartphone, though I’ll have to see how well it fits when I test it, as I had mixed results attaching an Xteink to my phone due to both fit and magnet strength.
Advertisement
Courtesy of Boox
Boox says the Picco will have a streamlined operating system focused on reading and digital utility tools. It’s also the first in what Boox calls its Tiles lineup, which is how you’ll access ebooks on this device. You can also use web and USB-C file transfers (the Picco has Wi-Fi and Bluetooth connectivity) to get ebooks onto the Picco. The Picco also has the Pomodoro, Todo, and Countdown apps, so you can use it as both an e-reader and a productivity gadget—handy, and a bigger motivation to keep it attached to the back of your phone even when you aren’t reading.
I’m intrigued to see it in action. Boox’s most popular e-reader could become the Picco over the Palma 3, but we’ll have to wait for both devices to become available to see which is the better buy. Stay tuned for my reviews of both when they come out.
But a Chromium-based design means it can only be so efficient.
Discord
Discord is working on a new mode for its social platform that it says might be less resource-intensive. Screenshots of an option called Game Mode began circulating on social media over the weekend. The description shown for the Game Mode toggle states that it will “Reduce Discord’s CPU and GPU usage while a game is running.” By making the chat platform less resource-intensive, concurrently running software should be able to run more smoothly.
Today, the company confirmed on X that this experimental mode will begin rolling out to its users next week. The brief official announcement about Game Mode added that Discord is “aiming to add more resource-saving features over time.”
Discord is based on the Electron web app framework, which uses Javascript and Chromium for creating software. The open-source Chromium, which is the basis for Google’s Chrome and several other browsers, is not known as the most efficient tool for web development. A feature like Game Mode could offer some performance improvements, especially while also running a beefy AAA game on the same machine, but there may only be so far that Discord will be able to streamline on its current architecture.
Six of the nine independent experts on the advisory board of the Global Internet Forum to Counter Terrorism—a consortium run by several of the biggest US tech companies—resigned on Monday, according to a letter seen by WIRED and interviews with three of the people.
The tensions between the independent advisory committee and the GIFCT date back to an email the counterterrorism and free speech experts received in July from Meta’s Nell McCarthy, a vice president overseeing content policy. For years, the group had advised the GIFCT on how to prevent platforms from becoming havens for the radical organizations and individuals blamed for some of the world’s worst mass violence.
But McCarthy wrote that while the consortium welcomed the experts’ insights on violent trends, it no longer desired their scrutiny on the effectiveness of Big Tech’s efforts to curtail violence. Meta and other leaders wanted to “refresh” the 6-year-old independent advisory committee the experts sat on, she wrote. Meta currently serves as chair of GIFCT’s operating board, giving it outsized influence over policy changes, though other companies on the panel must ultimately approve.
New additions to the rotating advisory committee had previously been elected by current members; under the plan laid out in July, they would instead be picked by tech companies. The committee would be barred from weighing in on key topics such as the consortium’s performance and making recommendations together as a group. Its role as a watchdog would be neutered, advisers believed.
Advertisement
In their resignation letter, the departing members of the committee wrote that their appeals against the plan had been “ignored” and that, in turn, they had “lost confidence in the GIFCT’s ability to deliver effectively on its founding mission” to prevent terrorists from exploiting online services. “We all know that a body that cannot scrutinise, take a position, or evaluate is not an advisory body at all,” the letter stated. “It is decoration and accountability theatre.”
Meta deferred comment on the resignations to the GIFCT. An unsigned statement sent to WIRED by a GIFCT spokesperson on behalf of the consortium’s leadership and the Meta-chaired operating board says the proposed changes have been “informed by several rounds of feedback” and are not yet final. They came out of discussions on “how to more effectively engage civil society and governments for substantive input” as “multi-stakeholderism is a core principle” for the GIFCT.
The consortium has about 35 members; other long-time board members include Microsoft and YouTube. A small staff alerts members to violent content, helps them exchange threat intelligence, and commissions research on countering extremism. While the coordination has helped some platforms combat problematic content, critics believe the group isn’t living up to its potential.
A WIRED investigation in 2024 uncovered several issues with GIFCT, including Meta delaying TikTok’s membership bid and poor relations between the companies at the helm and the unpaid independent advisory body. It also revealed failures in the tip-sharing database the consortium oversees to coordinate takedowns of problematic content.
Advertisement
The dismantling of the advisory group threatens to deteriorate the organization’s work further at a time when balancing free expression and online safety has become more challenging. Generative AI tools have simplified content creation but imposed limited guardrails.
The experts who resigned include university researchers and representatives of civil society organizations. They had agreed with McCarthy on the need for changes to improve the results of the decade-old anti-terrorism consortium. But they believe the proposal, which could be finalized soon, amounts to a step backward.
“There won’t be critical voices raising concerns about what GIFCT is doing or is not doing,” one of the departing experts says. “It may seem politically convenient for them to abolish the independent advisory committee, but they are going to regret it in the longer term.”
The successful mission also deployed 26 of SpaceX’s latest Starlink satellites.
SpaceX
For its 14th flight, SpaceX’s Starship powered by its Super Heavy megarocket has entered low-Earth orbit for the first time. SpaceX kicked off this major undertaking early Monday morning but had to deal with some hiccups on the way, including losing one of its six Raptor engines. Ultimately, SpaceX decided to push on with the mission and successfully reached orbit albeit with some compromise.
SpaceX originally planned to have Starship orbit Earth six times over a span of nearly 10 hours for the Flight 14 mission. With one of the engines offline, the plan changed to only spend approximately three hours in orbit before reentering the Earth’s atmosphere and landing in the Pacific Ocean. As part of the same mission, SpaceX managed to deploy 26 of its Starlink V3 satellites into orbit. SpaceX said that its Starlink team has made contact with all newly-deployed 26 satellites in orbit, which will eventually be used to improve Internet speeds for customers. While previous Starship missions also carried several V3 satellites, they only remained in suborbital space and served as test flights to see if the new satellites would connect to the existing Starlink constellation.
While Starship’s flight 14 marked a major milestone of reaching orbit, the mission also served as a test of the reusability of its Super Heavy rocket. After providing the necessary boost to Starship, Super Heavy landed in the Gulf of Mexico, where it will eventually be retrieved, but not by a launch tower‘s “chopsticks” as previously demonstrated.
Mipmapping is a good way to add a lot more detail to a 3D scene without overburdening the rendering hardware with detail that won’t be seen by the user. This level-of-detail rendering technique was demonstrated on the N64 console hardware a few years ago by [James Lambert] with [Michael Biggins], also known as [PhonicUK], now demonstrating it on the ESP32-S3 using his own Jet rendering engine.
Although level-of-detail rendering really speeds things up, it does also require far larger texture sizes, with [James]’s N64 demo taking up 40 MB of a 64 MB cartridge. To fit it on an ESP32-S3 with 16 MB of PSRAM and no SD card expansion or such the textures were further compressed to use 8-bit indexing, resulting in a mere 5.01 MB of textures.
There’s a demonstration video over on the associated Reddit thread, which shows the camera moving through the scene. Even if not as exciting as the Wipeout port by [Michael] that we previously covered, it does make clear that even without a proper 3D GPU the ESP32-S3 is already a pretty capable gaming machine that can go toe-to-toe with some 1990s consoles.
There are five weeks left until the midterm elections, and extremism is on the ballot in much of the US. A WIRED review of candidates running for statewide and federal positions in November, along with exclusive data on candidates running for state-level positions, reveals hundreds of Republican candidates who openly express virulently hateful ideologies, share racist content online, have close ties to white supremacist and antisemitic figures, and are members of far-right groups online. President Donald Trump and his administration have openly embraced, endorsed and defended many of these candidates.
At a local level, over 500 candidates running for state legislator positions in November are members of far-right groups on Facebook that promote militias, gun rights, and Christian nationalism, according to data collected by the Institute for Research and Education on Human Rights and shared with WIRED.
“The candidates are taking a page out of the Trump administration’s playbook,” Luke Baumgartner, a former research fellow at George Washington University’s Program on Extremism, tells WIRED. Baumgartner claims that many of the candidates running in November have been inspired by those in the White House. “In essence, the executive branch has handed them a permission slip to say and do what would have been unthinkable during the George W. Bush, McCain, or [Mitt] Romney eras of the GOP,” he says.
Advertisement
Extremist rhetoric has led to real world political threats. In 2025, terrorism and targeted violence incidents rose 19 percent compared to 2024, according to researchers at the University of Maryland; the US Capitol Police reported an increase in “threat assessment cases” against members of Congress for the third year in a row, with a 58 percent increase from 2024; and the US Marshals Service documented threats against almost 400 judges, a roughly 5 percent increase from the previous year.
Here are five races involving candidates who have shared extremist ideologies or have close ties to extremist figures, that WIRED is watching ahead of the November midterms.
The Texas Railroad Commissioner Race
Photo-Illustration: WIRED Staff; Getty Images
Bo French, the GOP candidate for Texas Railroad Commissioner, is so extreme that Republican strategist Karl Rove has said he would vote for a Democrat rather than supporting a “bigot.”
We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.
Roborock Qvero 2 Pro: 30-second review
The Qrevo 2 Pro is the latest robot vacuum and mop combo cleaner from Roborock and includes detachable mop plates to help ensure it doesn’t get carpets wet while cleaning.
Cleaning performance is a match for some of the most expensive options on the market with its mopping being as good as I have ever tested making it a fantastic pick for the price.
Advertisement
It is relatively tall so it can’t clean under low furniture and its hard floor cleaning isn’t flawless but it is an excellent option, especially when on sale.
Latest Videos FromTechRadar
Advertisement
Roborock Qrevo 2 Pro: price & availability
List price: $799.99 / £649.99 / AU$1,199
Launch date: August 2026
Availability: worldwide
The Roborock Qrevo 2 Pro sits right on the line between premium and mid-range robot vacuums, with a list price $799.99 / £649.99 / AU$1,199. However, almost immediately after launch I have already seen it get a significant discount to $549 / £549.99, tipping it firmly into the more affordable category — especially considering the features and performance.
Even at full price it sits below the Roborock’s Curv models and produces similar results (although it doesn’t have the AdaptLift chassis for getting over higher thresholds between rooms) making it an excellent value pick. If you’re looking to spend less, the Roborock Q7 is a good alternative although it has much lower suction power and doesn’t have an auto-empty dock.
A branded floor cleaner compatible with the Qrevo 2 Pro is available on Roborock’s website but they don’t push this hard and after testing it without it, it’s definitely not required.
You don’t have to use Roborock’s own floor cleaner, but you will need to buy disposable dust bags (Image credit: Future)
What you will need to buy are disposable dust bags as these are thrown away once full. A three-pack costs $39.90 in the US, and a six-pack is £31.99 in the UK, so this needs to be considered in the running costs. I have tested Roborocks with cheaper unbranded dust bags in the past and not encountered problems, but check model compatibility before ordering.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
Advertisement
You can also buy replacement brushes, mop pads, filters and other parts in case anything breaks.
Roborock Qrevo 2 Pro review: design
Smart-looking robot and dock
Can’t get under low furniture
Smart home integration
Available in all white or black (currently only available in white in the UK and Australia) it is pretty unfussy in terms of design with the dock a bit squarer than the slightly bulbous base stations of Roborock’s Curv series.
The robot is circular, measuring 14 inches wide with a 6-inch cleaning opening underneath for picking up dirt.
The lidar scanner the robot uses to navigate sits in a cage on top of the robot, increasing its height and reducing its clearance so it won’t be able to vacuum under low furniture like a sofa, unlike Roborock’s Qvrevo CurvX with its retractable lidar scanner.
Advertisement
Image 1 of 2
The robot’s lidar scanner doesn’t retract, so it can’t fit under low furniture
(Image credit: Future)
The dock is easy to set up, provided you have sufficient space
(Image credit: Future)
Setting the dock up is easy, involving just attaching the ramp to the front of the dock, filling the clean water tank and plugging it in. The more difficult part may be finding a place for it as it needs to sit on a hard floor with at least 1.5 inches either side and 27.5 inches of clear space in front of the dock. It also needs to be within reach of a power socket and somewhere you won’t trip up over it or mind looking at it everyday.
Set up is simple, you will need to find an appropriate spot for the dock on a hard floor with plenty of space either side. You then download the app, pair the robot and then you can send it on a discovery run around your house to build a map.
Once it has scanned the space you can then edit the map to combine or divide spaces into rooms, mark areas as no-go zones, manually designate floor types and mark things like curtains and furniture. I found that aside from ensuring the rooms are divided correctly I didn’t have to make any changes to get it to work well, with the carpeted areas successfully detected.
Advertisement
The robot has detachable mop pads, which it leaves in its dock after mopping your floors (Image credit: Future)
After setup you can use the app to kickstart cleans of the whole map, one or more selected rooms or a designated zone clean you can mark on the map. As well as ad hoc cleans you can set routines for different types of cleans from deep intensive cleans, to specific after dinner cleans of smaller zones or light maintenance vacuuming without mopping.
As the Qrevo 2 Pro has detachable mops, rather than vacuuming and mopping room by room it first goes around the carpeted areas of the whole space you are cleaning first. Once that is complete it returns to the dock to reattach the mop heads before cleaning the rest of the hard floors.
Obstacle detection was generally good, though the Qrevo 2 Pro did get caught on a USB charging cable (Image credit: Future)
Cleaning performance is OK on hard floors, although it can lead to some spreading of larger debris as the edge cleaning arm sent rice grains skittering across the floor. It did better with fine particles, although there was still some tea visible on a pass on the standard cleaning settings.
It handled larger particles much better on carpet, picking up almost every single grain of rice, although there was some tea left after the first pass.
Advertisement
As with most robot vacuums, its edge cleaning wasn’t great on carpet, but the sweeping brush does well to move material into the vacuum’s path on hard floors..
During the obstacle avoidance tests it did well to identify the shoe and sock, staying clear as it cleaned around them but it did go over the charging cable, getting it stuck in the cleaning brushes and needing me to rescue it before it could continue cleaning.
During my mopping tests on first pass it did a reasonable job taking up a fair bit of the ketchup although there was a hint of the soy sauce remaining. Trying a second clean on maximum water flow and cleaning settings it did a fantastic job cleaning off even the dried on patches of ketchup.
While the most intensive cleaning took some time and left the floor relatively wet, it was some of the best mopping I have ever seen from a robot. You do need to delve into the settings to get the best performance and it probably is only practical for small zone cleaning but it’s still a lot less effort than getting out a mop and bucket.
Advertisement
On regular cleaning settings it can manage around five regular rooms before needing recharging so depending on your home it may need to recharge before completing a full clean. Recharging takes around four hours.
It’s not loud in operation, registering around 60db while cleaning on carpet. The dock emptying is a little louder, topping out at 69db (around the level of normal conversation), although this is pretty brief so shouldn’t be too disruptive.
The Qrevo 2 Pro uses dust bags so emptying it of dirt is quick and neat, although that does add ongoing costs to using it. You will also need to empty the waste water and refill the clean water tanks regularly which is easy to do (as long as you leave enough clearance room above the robot) as these lift out of the dock and then can be unclipped open for emptying or filling.
Smart home integration worked well for starting a whole house clean but I did have a little trouble using the room clean function for custom named rooms. Naming a room one of the default names such as Kitchen or Living Room worked fine, but a custom name such as Utility Room sparked a whole house clean instead.
Advertisement
While custom room names would be helpful, even getting default room cleaning to work is not a guarantee with any of the robot vacuum cleaners I have tested so, relatively, this is a success.
Performance score: 4.5 out of 5
Roborock Qrevo 2 Pro: app
Easy setup
Clear house map
Can set frequent types of clean and schedule cleans
The app is simple to use, although I did find it can sometimes get a little lost if you select your cleaning mode too quickly, meaning you have to move to another mode and back again before getting the options you need.
Once you select the robot you are shown the map of your home and have four tabs to select the type of clean you want, ‘Full’, ‘Room’, ‘Zone’ and ‘Routine’. ‘Full’ starts a clean of the whole map and to the left of the play button there is a button for adjusting the type of clean including whether you want to vacuum and mop, just vacuum or just mop. There are also controls for the level of suction, waterflow, amount of times you want the robot to clean the area and the intensity of the cleaning pattern.
Image 1 of 4
The app is simple to use provided you don’t hop between modes too quickly
(Image credit: Future)
Select your robot to see a map of your home
(Image credit: Future)
You can adjust the settings for the vacuum and mop independently
(Image credit: Future)
The ‘Routine’ option allows you to schedule different types of cleaning
(Image credit: Future)
Room allows you to select one or more rooms to clean, while Zones lets you pick multiple rectangular sections of your chosen size on the map for it to clean, allowing you to spot clean specific sections of floor.
‘Routine’ is the final option and allows you to create shortcuts for regular types of clean that will then be available from the opening screen on the app. This is useful for setting up things like zone cleans that focus around a dining table following a meal or if you want a predefined deep clean compared with a light maintenance clean.
Advertisement
Despite the name, ‘Routine’ doesn’t include any scheduling functionality by default. That is hidden somewhat in the settings menu, but can be used with scheduled cleans (if your home doesn’t regularly have bits of Lego on the floor like mine does).
Should you buy the Roborock Qrevo 2 Pro?
Swipe to scroll horizontally
Attribute
Notes
Advertisement
Score
Value for money
Even at full price the Qrevo 2 Pro represents good value and at a discount price it is a fantastic deal. You will need to consider the price of disposable dust bags in the running costs but you’ll be hard pressed to find these features and performance for less.
5/5
Advertisement
Design
The design is more focused on function than form but it is unfussy and designed to fit into most homes. The tall mounting of the lidar scanner will stop it from cleaning under low furniture.
4/5
Performance
Advertisement
Vacuuming performance is good and mopping is excellent although It did have trouble picking up on a charging cable in our object avoidance tests leading it to get stuck.
4.5/5
App
The app makes it easy to control, with simple options for choosing the type and location of cleans as well as a clear map of your home.
Advertisement
5/5
Buy it if
Don’t buy it if
Advertisement
How I tested the Roborock Qrevo 2 Pro
I tested the Roborock Qrevo 2 Pro over a period of over two weeks, using it as an everyday cleaner of a busy household.
As well as day to day use I put it through a series of tests, assessing its performance picking up fine particles and larger debris on carpet and hard floor by having it clean an area with a set amount of rice and tea sprinkled on the surface. Edge cleaning was also tested using tea on the edge of a carpet and hard floor area.
Mopping performance was tested by having the robot clean up a spill of soy sauce, as well as tackling a patch of dried ketchup. After an initial pass on regular settings, this was then retested with cleaning settings set to maximum.
The forthcoming iPhone Duo has more features than Apple has revealed, including a whole series of faces for its StandBy mode. Here’s what to eventually look for.
While pre-orders for iPhone Duo don’t start until October 16, and the Xcode betas still don’t show developers everything, one has found many new options coming to iOS 27 for this device.
Developer pdfu reports that the Xcode 27.1 simulator is lacking Rushmore, an app that is for displaying the new StandBy faces. But despite that, they have managed to get certain of the new faces running.
Here’s a deep dive into StandBy mode on iPhone Duo.
Rushmore, the app meant to host the redesigned faces, is missing from the iOS 27.1 simulator.
Advertisement
But its localization strings reveal unreported faces, and I got some new faces running in the current renderer. pic.twitter.com/lDQHOy5R0e
These working ones are variants on familiar clock and calendar faces as used on the iPhone‘s current StandBy mode. But code references describe several more options.
Here’s a deep dive into StandBy mode on iPhone Duo.
Rushmore, the app meant to host the redesigned faces, is missing from the iOS 27.1 simulator.
Advertisement
But its localization strings reveal unreported faces, and I got some new faces running in the current renderer. pic.twitter.com/lDQHOy5R0e
Just because something is referenced in code, it doesn’t necessarily mean that it will launch immediately. But those code references show five more faces:
Home Camera: up to nine camera views
Home Module
Flow
Fade
Snoopy
There are no details for Home Modular, Flow, or Fade. But the code for Flow also includes the term ResponsiveArt, which suggests that it will at least be an animated face.
Face editor
The iPhone Duo will also feature a revised editor for customizing these StandBy faces. It’s very similar to the existing one on iPhone and is perhaps more like the Apple Watch face editor.
Advertisement
Users can swipe left and right to adjust, for instance, the style of an analog clock, its numerals, light mode and dark mode, plus the color of the face and the hands.
Some of these clock faces also have room for two widgets. Then some more are digital instead of analog and there pdfu has found code references for five layouts:
StandBy
Stacked
Top
Middle
Bottom
The presumption is that all but the StandBy one may actually be intended for when the iPhone is opened like a book.
Developer pdfu has a strong track record for examining beta code. They confirmed that the iPhone Duo would use Touch ID, for instance, and most recently uncovered that Siri could be replaced by Claude or ChatGPT.
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption.
Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.
Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts.
Advertisement
The destructive stage lasted seven minutes and targeted more than 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services.
Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections.
Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals – security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources.
Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other “performed discovery, destructive operations, and credential collection.”
Advertisement
Timeline of observed attacks Source: Microsoft
The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an effort to make restoration more difficult.
This operational pattern could further support ransomware extortion, although Microsoft did not report anything about financial demands and didn’t confirm data theft in the observed cases.
According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed.
“The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type,” Microsoft said.
Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded.
Advertisement
Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks.
The researchers recommend several mitigation steps and guidance for system administrators, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
You must be logged in to post a comment Login