Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.
The AI company says that between December 2025 and August 2026, it recorded various forms of artificial intelligence misuse, including for cyber and influence operations, surveillance, scams, development of biological and conventional weapons, and model distillation.
Over the eight-month period, Anthropic disrupted several activities linked to the ShinyHunters collective, infamous for massive data theft attacks that typically begin with social engineering and account compromise.
An alleged French-speaking member of the group that used the handle ‘frkoo’ distributed a credential-harvesting pipeline across ten AWS EC2 workers that downloaded from multiple stores and then scanned for secrets in 1.8 million Android APKs.
“This pipeline mass-downloaded 1.8 million distinct Android APKs from multiple app-store sources, decompiled them, and scanned for hardcoded secrets with TruffleHog,” Anthropic explains.
“Verified findings were routed in real time to a Telegram group organized into over 100 source types.”
The same actor used a separate automated process to collect GitHub organization email addresses and used them to obtain GitHub Personal Access Tokens (PATs).
The two pipelines provided initial-access credentials that ‘frkoo’ used “for the bulk of the confirmed breaches” associated with the hacker.
Anthropic says that ‘frkoo’ also set up a carding shop at policenationale[.]cc that impersonated the French national police to sell stolen payment-card records, full cardholder information, and an interactive map of victim addresses.
Suspected ShinyHunters members also stole AI API keys and used them for breaching other organizations or for reconnaissance activity.
In one case, they breached a software-as-a-service provider and stole data belonging to around 200 downstream customers.
Fast-paced attacks
With the help of Claude AI, it took a suspected ShinyHunters threat actor about 34 hours to extract authentication data and get more than 2,100 sets of Azure AD authentication tokens linked to over 40 separate corporate Microsoft tenants. According to Anthropic, “AI agents performed nearly all of the work.”
Additional harmful activity involving Claude and attributed to ShinyHunters affiliates includes breaching a technology provider and stealing 1TB of data, compromising an airline, and accessing systems of an energy company.
ShinyHunters moved quickly after obtaining initial access. In the case of an enterprise software firm, the hackers went to bulk data theft in just a few hours.
In another instance, the AI company says that the attacker moved from a single stolen developer token to full administrative control in less than three hours.
Russian and Chinese hackers
Anthropic’s report also highlights activity attributed to the Russian espionage group “Midnight Blizzard,” which used Claude to automate malware development, research, infrastructure acquisition, phishing, persistence, command-and-control (C2) operations, and data exfiltration.
The threat actor also set up a feedback loop that rebuilt malware whenever security products detected it.
Anthropic observed Midnight Blizzard targeting over 20 government, defense, diplomatic, intelligence, and foreign-policy entities.
The campaigns included device-code phishing, ClickFix attacks, DNS hijacking through compromised hotel Wi-Fi providers, WhatsApp account takeovers, cloud-email theft, and Windows, Android, and iOS malware, with Claude being used throughout all attack stages.
Midnight Blizzard automated its operations through AI-driven workflows built around Claude Code skills, with the human operator primarily modifying those skills when they needed refinement.
Anthropic also describes an espionage operation attributed to a Chinese-speaking group tracked as GTG-10007, where Claude was used “as the engineering and orchestration layer of a coordinated offensive program involving a variety of tasks,” such as:
- intrusion attempts against production systems
- reconnaissance of foreign-government networks across the Middle East, Europe, and Southeast Asia
- a standing vulnerability-research and exploit development effort against major endpoint-security products
- malware development
- building an intelligence-collection platform
The GTG-10007 espionage group operated autonomous vulnerability-research workflows while the human operators were away, which uncovered multiple previously unknown vulnerabilities in a major security product.
Additionally, the automated effort also delivered “working exploits for several families of network and security appliances.” The actor then leveraged the exploit code against several government organizations around the globe.
The group’s operations targeted around 50 organizations across government, education, retail, energy, technology, healthcare, finance, and manufacturing, with confirmed compromises at an education-technology company, a retailer, and a Southeast Asian government agency.
The AI company notes that it disrupted the actors’ use of Claude for harmful activities and banned the threat actors’ account.
Furthermore, Anthropic adjusted its guardrails based on the observed malicious use, added measures to detect future misuse faster, and contacted the authorities, industry partners, and victims.
Tech
Mecka AI nears $500M valuation in Sequoia-led deal amid rush for robot training data
Mecka AI, a startup that collects and analyzes human motion data to train humanoid robots and other robotics, is nearing a new round led by Sequoia Capital at a valuation of about $500 million, according to two people with knowledge of the deal.
The new financing comes just three months after Mecka announced that it raised $60 million in a round led by Framework Ventures that included participation from Menlo Ventures, SV Angel, and Kindred Ventures.
TechCrunch has not learned the precise size of the new round. The terms of the deal are not final and could still change.
Mecka AI didn’t respond to a request for comment. Sequoia declined to comment.
Mecka AI was co-founded in 2024 by four entrepreneurs, including Canadians Josh Gao and Mogen Cheng, who previously built a restaurant fintech startup, and Jason Chong, who joined Coinbase after it acquired his crypto exchange. Duy Nguyen, the only non-Canadian on the team, focuses on operations at Mecka.
The four co-founders don’t have backgrounds in robotics. But they did recognize that there was a dearth of physical-world data and realized that capturing real-world interactions was the primary bottleneck holding back general-purpose robots, including humanoids.
Mecka, which derives its name from “mecha,” a fictional giant robot controlled by humans, set out to do for robotics what Scale AI, Mercor, Surge, and other human data companies have done for LLMs. The startup pays people to record themselves performing everyday tasks — like making coffee or fixing cars — using body sensors and smartphones.
As of early June, Mecka was projecting that it would end 2026 at an annual run rate of $100 million, Gao told Fortune when the startup announced its previous fundraise.
While Mecka AI hasn’t publicly disclosed its customer list, many robotics companies and AI labs rely on real-world data captured through this “egocentric” approach, alongside other physical data collection methods like teleoperation, to build their models.
Other startups collecting real-world data for robot training include XDOF, which TechCrunch reported last week was nearing a new round at a $1.2 billion valuation, as well as human-data platforms expanding beyond LLMs, such as Scale AI and Micro1.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Best SIM-only Deals September 2026: Plans for all budgets
Are you in the market for a better data, minutes and texts plan for your mobile? Perhaps you’ve found you’re hitting your data limit a little too often for comfort and now’s the time to do something about it. Or, if you’re out of contract and have realised you’re paying too much for what you have – don’t worry, the deals below can help you out.
We’ve compiled the best SIM plans right here, no matter what your budget is or your requirements, all of which take into consideration costs and, of course, how much data you can get for your buck.
SIM-only deals are just as they sound: the SIM without the expensive phone added to the whole contract. It’s the minutes, texts, data allowance and nothing more.
These are great if you’re out of contract and want to save some money, or if you’ve bought a phone SIM-free, such as any in our best smartphone buying guide. It’s also ideal, as mentioned, if you now need more data, as there are great deals to be had.
We’ve broken down the best of the best. They’re sorted by data and price, making it easy to find what you’re looking for and allowing you to compare to what you already have.
Some of the best offers are from companies running off the back of EE, O2, Vodafone and Three. That’s because they can undercut the prices of the main networks and by some margin, too.
Also, if you are reading this while researching what’s available as an initial step to buying a new phone, then we can also help you out. Feel free to dive into our best foldable phones buying guide, best mid-range mobile, best budget phones, and best small phone round-ups.
Unlimited Data Deals
100GB+ Data Deals
50-100GB Data Deals
10-50GB Data Deals
Below 10GB Data Deals
How to choose the best SIM
There are various factors to think about when considering a SIM-only plan:
Data: Using the phone for streaming, gaming, apps and surfing the web away from Wi-Fi can put a strain on your data allowance. It might be worth reviewing your current usage and what you use or might need in the future when considering an upgrade. It’s always worth giving yourself a data cap that provides some wiggle room in relation to your average usage, just to ensure that you don’t have to incur additional costs if you happen to have a particularly data-heavy month.
Contracts: SIM deals usually have shorter service terms than all-in-one phone plans, typically 12-month or 30-day rolling plans, with the latter offering greater flexibility. While 18-month and even 24-month options are available, we recommend choosing a shorter term so you’re not tied in for long if you’re ever dissatisfied with your service.
Networks: Most mobile phone networks nowadays offer a good coverage area, and it’s worth checking what works best in the usual places you’d be with your mobile. With that said, there are networks that run off the back of the usual EE, O2, Vodafone and Three that offer good service at a lower price, such as Smarty and Voxi. Some networks also come with additional freebies and reward services, including O2 Priority and Three Plus, so it’s worth doing a bit of comparison to see what you can get for your money.
Tech
Trying To Fix A Suspiciously Cheap Enterprise-Grade Network Switch

Naturally this Juniper EX4100-F-12P switch came without power supply brick for its 48VDC input. Figuring out its pin-out and probing said input showed that the voltage rails had been shorted, giving a first clue as to why this switch had been on sale for so very cheap. Bravely hoping that it would be a straightforward fix, the unit was disassembled.
With a 280 Watt power brick, it’s little wonder that the top of the unit is a one massive aluminium heatsink, including a large heatpipe. Also visible on the lid near the power input was a very-bad-news black skid mark.
From that first discovery the news just got worse and worse, with clear signs of water ingression, rust and corrosion, along with the aftermath of a powered circuit meeting such bad corrosion. After some clean-up it’s clear that some components had violently exploded, ripping apart layers of the PCB and likely parts of traces in those inner sections too.
With no schematics available and no other good repair options via Juniper or anywhere else, it seems that unfortunately this gamble turned out to be merely a pile of e-waste and a few bucks worth of scrap metal. Caveat emptor, once more.
Tech
5 Underrated Motor Oil Brands That Can Compete With Castrol
Castrol is known among car enthusiasts and everyday drivers alike as one of the industry’s best motor oil brands. The company’s lineup includes EDGE, GTX, and GTX Full Synthetic — oils for a wide range of vehicles. Castrol also has products that meet industry standards and specific automaker requirements. All of this means that Castrol’s reputation is based on much more than just name recognition.
Castrol’s motor oils give drivers many options within their lineup. For example, EDGE includes low-viscosity oils for newer engines, as well as versions made for vehicles with higher mileage. GTX is available as a conventional oil, synthetic blend, and full synthetic, including high-mileage formulas. That being said, this is just a snapshot of what the company offers in terms of selection, as there’s no single Castrol product that fits every vehicle. Factors like viscosity, certifications, and engine requirements should all be considered.
Therein lies the issue for some drivers wanting different options, as it can be tough to know what other brands may be on par with Castrol. There are several other brands producing conventional and full-synthetic oils that meet industry standards and, in some cases, carry approval from major automakers. Some of these other brands have been around for years, though you may not be that familiar with them. There are several legitimate alternatives to Castrol that could be right for you.
Ravenol
Ravenol may not be as familiar to some American drivers as Castrol, but the German-owned company does have a big selection of motor oils for cars, trucks, motorcycles, and a lot more. Ravenol’s line of passenger-car oils includes formulas with different viscosities and specifications, including DXG SAE 5W-30. This full-synthetic oil is designed for gasoline engines with and without turbocharging and direct injection, and it uses a polyalpholefin (PAO) base along with a Group V base oil, tri-nuclear molybdenum, and organic friction modifiers.
Ravenol DXG 5W-30 also carries API SQ Resource Conserving and ILSAC GF-7A, along with a General Motors dexos1 Gen 3 approval. Ravenol also lists recommendations for Chrysler, Fiat, Ford, Honda/Acura, and Opel/GM. Its technical data includes a viscosity index of 163, an HTHS viscosity rating, and a pour point of -71 degrees Fahrenheit. This formula is also designed to address low-speed pre-ignition, oxidation, and engine cleanliness.
Ravenol’s quality-management system is certified to IATF 16949 and ISO 9001, while its testing lab holds ISO/IEC 17025 accreditation. Ravenol also has approvals from major manufacturers including BMW, Chrysler, Cummins, Porsche, and Volkswagen, among others. Additionally, the American Petroleum Institute’s certification system requires that companies obtain a license before displaying API quality marks. This makes Ravenol more than a manufacturer just claiming that its oils meet a certain standard.
Liqui Moly
Liqui Moly is a German manufacturer that offers a selection of motor oils developed for both American and Asian vehicles. The company has updated several of the oils in its Special Tec AA line, as well as the Molygen New Generation line, for the latest API SQ specification. One example is Special Tec AA SAE 0W-20, a fully synthetic motor oil made for gasoline engines, including those with direct injection and turbochargers.
The API SQ specification focuses on several areas of engine oil performance, including fuel efficiency, improved engine cleanliness, and protection against sulfate ash, and more. Liqui Moly’s oils have also passed the new LSPI Aged Oil test, which checks protection against low-speed pre-ignition after the oil has aged over a period of time. This is important as LSPI is a concern when it comes to downsized gasoline engines, and that’s especially true for those using direct injection.
Special Tec AA SAE 0W-20 has ILSAC GF-7A approval, as well as GM dexos1 Gen 3. Liqui Moly recommends this motor oil for vehicles requiring specifications from Chrysler, Ford, Honda, Kia, Nissan, and Toyota, among others. With multiple oils updated for the current API SQ and ILSAC GF-7 standards, Liqui Moly gives drivers another solid option beyond the more familiar brands like Castrol on store shelves.
Amsoil
Amsoil’s Signature Series is a 100% synthetic motor oil line available in eight viscosities, from 0W-16 through 10W-30. The Signature Series provides protection against wear, horsepower loss, deposits, sludge, and turbocharger coking. This lineup has also been tested to industry standards including ASTM D6891, D5293, D8111, and D6593. The Signature Series 5W-30 has also been tested against the GM dexos1 Gen 2 turbocharger requirement.
In an ASTM D5293 cold-cranking test, Signature Series 5W-30 had a lower cranking viscosity than the other motor oils Amsoil evaluated. That testing included products from Driven, Lucas, Red Line, and Royal Purple. Amsoil also cites an independent 100,000-mile test comparing Signature Series 5W-30 with a leading synthetic-blend 5W-30 in Ford F-150 trucks with 3.5-liter twin-turbo engines. According to Amsoil, the Signature Series oil provided better wear protection, with the engine bearings still looking like new after the test was complete.
The latest Signature Series formula has also undergone additional testing, with the results showing a 12.5% improvement in cold-cranking results when compared with the previous formula. The new formula produced better results during TEOST testing, an industry-standard lab test for motor oil. Amsoil also tested the oil after aging it to represent 25,000 miles in a high-output Ford Raptor engine. The test showed that the oil exceeded the minimum LSPI protection requirements.
Motul
Motul’s 8100 line of motor oils includes several synthetic options in different viscosity grades. One example is the 8100 ECO-LITE 5W-30, a 100% synthetic oil for both naturally aspirated and turbocharged gasoline engines with either direct or indirect injection. The 5W-30 meets API SQ-RC and ILSAC GF-7A standards and has GM dexos1 Gen 3 approval. This oil also meets specific performance requirements for various automakers, including Ford, GM, and Volkswagen.
Motul updated several of its 8100 ECO-lite oils in 2025 to meet the API SQ and ILSAC GF-7 specifications. API SQ actually replaces two other API standards, with requirements for fuel economy, low-speed pre-ignition protection, component durability, and engine cleanliness. The new standard also uses revised engine tests that measure deposits, viscosity, and fuel economy. While the 8100 ECO-lite 5W-30 meets these newer requirements, it is also still compatible with the previous standards.
The company’s 8100 lineup goes beyond just the 5W-30, as ECO-nergy is specially designed with fuel economy in mind. It comes in 0W-30 and 5W-30, while the ECO-clean and ECO-clean+ use lower-SAPS formulas for vehicles with catalytic converters and diesel particulate filters. Then there’s X-cess, which uses a high-HTHS formula for engines that run at higher temperatures, and X-power 10W-60 which is made specifically for high-performance gasoline engines.
Red Line
Red Line’s Professional-Series 5W-30 is a full-synthetic motor oil made with both Group III and Group IV PAO base stocks. It carries API SP and ILSAC GF-6 certifications and is approved for GM dexos1 Gen 2 and Gen 3. This is a relatively newer option from the company, which lists the 5W-30 as a replacement for vehicles that call for older Chrysler, Ford, and Honda/Acura motor oil specifications.
Red Line is known for its high-performance applications, which may set it apart from traditional motor oil brands for some drivers. In fact, Red Line’s selection includes dedicated racing oils, along with high-performance motor oils for street vehicles. The company’s history and experience with racing has informed the development of its street motor oils, which use PAO and ester base stocks along with an additive package containing higher levels of zinc dialkyldithiophosphate (ZDDP).
Red Line’s High-Performance motor oil lineup includes viscosity grades ranging from 0W-20 through 20W-50, along with 15W-40 diesel and 10W-60 motorcycle oils. Some of these products are designed for fuel efficiency and driving in cold weather, while others are made for high-performance engines or vehicles that require thicker oil. Red Line also sells separate Euro-Series and break-in oils, giving the company options for specific engine requirements beyond its standard street oils.
Methodology
The search for the five motor oils in this list began with a look through the manufacturers’ own product catalogs. This includes technical information, certifications, and OEM approvals. Ravenol, Liqui Moly, Amsoil, Motul, and Red Line were chosen because each brand offers specific motor oils with well-documented specifications, testing or automaker approvals that can be directly compared with Castrol.
We also looked for brands that offered something more than just the usual standard and synthetic lineups. This is why API SQ specifications, high-performance formulas, and company testing all became important parts of the selection process. This list was not based on customer ratings, or random social media reviews. The goal was to find five brands with enough technical information and strong supporting details to make a meaningful comparison.
Tech
Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too
When it comes to Chinese AI labs using distillation techniques to extract knowledge from frontier model makers, Y Combinator CEO Garry Tan is hoping regulators stay out of it. In fact, he thinks U.S. AI labs should perhaps play the same game.
“I would do nothing,” he told CNBC in an interview earlier this week. “We could argue that there should be an American distillation regime.”
He elaborated to TechCrunch that this means he wants smaller, American open-weight AI labs to use the same kind of training techniques on American frontier AI labs, giving the U.S. a more robust set of open-weight options that aren’t Chinese.
Distillation is when a model maker extensively prompts another model in order to learn how it works and reasons. It is commonly, and legitimately, used by AI labs to help train new models.
Anthropic this week released its second report alleging that Chinese labs are engaged in “illicit distillation attacks,” hiding their identities to distill without permission and relying on fraud and stolen credentials to do so. Anthropic CEO Dario Amodei had previously publicly called on U.S. regulators to crack down on distillation.
It’s notable that the commander of Silicon Valley’s prestigious and prolific startup accelerator doesn’t agree.
To be clear, Tan isn’t advocating for American AI labs to use stolen credentials to distill. He wants them to be free to come in the front door. In fact, his argument is twofold. He feels it’s an overreach for AI labs to dictate what their customers can do with the information their models share with them.
He also notes that the proprietary AI labs didn’t ask permission when they vacuumed up as much human knowledge as they could to train their models. They famously ingested plenty of copyrighted material without the permission of those intellectual property holders.
“Controlling what users and customers do with API calls to closed weight models feels constraining, and there’s a role government can play here to normalize the fact that access to intelligence that was trained on broad public access data should itself also be more a form of a public good than something locked away behind restrictive terms of service,” he told TechCrunch when asked why American labs should be free to distill, too.
Tan, who is himself such an avid AI user that he once described himself as having cyber psychosis, wants to see a balance between open-weight AI labs and frontier labs.
“They are at the frontier and driving it forward. We want that to be fundable, and be a great business model ongoing,” he told CNBC. “You want open weight models to give people freedom and access.”
To him, the true AI doomer scenario is for all the immense power of frontier AI to wind up in the hands of a single powerful, proprietary provider. “The nightmare scenario, the doomer scenario for AI is that there’s just one company,” he said. “It has the best access to capital. It has the best AI researchers. It runs away with it and suddenly there’s one company that’s monolithic. And that would be bad.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
How Much Has The Second-Gen Supercar Depreciated?
The second generation Acura NSX is nothing short of an icon, even though it had a relatively short run from 2017 to the 2022 model year. Culminating with the NSX Type S for the final model year, the hybrid mid-engine supercar made 600 horsepower, had a top speed of 191 miles per hour, and could accelerate to 60 miles per hour in under three seconds.
New, a 2022 Acura NSX Type S retailed for $169,500. The “standard” 2021 Acura NSX had an MSRP of $157,500. With a few model years in the rear view mirror, how much has the mighty NSX depreciated? Well, the answer really depends on what NSX we are talking about. As with all collector cars and performance machines, condition and whether or not it’s a special edition weigh heavy on the price you can expect to pay.
The second generation NSX hasn’t depreciated all that much. You’ll still likely pay over six figures for one. Remember, it isn’t comparatively all that old compared to other supercars you could be buying, and it’s a mid-engine supercar. Those don’t tend to be cheap.
You aren’t going to save any money
Getting specific, if you were to look for a 2017 Acura NSX, the first model year available, you can expect to pay around $120,000 to $130,000, or about $25,000 down from a new one. If you want a 2022 Type S, of which only 350 left the factory, the price has actually greatly appreciated. CarGurus shows prices of well over $250,000, even approaching $300,000 if you include taxes and fees that you might pay at an exotic car dealer.
The Acura NSX, really of all model years, is not a car that you are going to find inexpensively. It’s not even really a “hidden gem” of the automotive world. It’s a mainstream supercar from a mainstream automaker with a long history in the racing world. If you’re looking to save money buying an older model, the second generation NSX probably isn’t the car for you. But if you’re looking for probably the best Honda made in the last decade, then it might be your car.
Tech
Moss Developer Polyarc Has Closed
The studio produced some early hits for the PSVR and Oculus Quest.
Polyarc, the developer behind virtual reality games Moss and Moss: Book II, has closed, according to a new post on the studio’s LinkedIn page. Based on a reverse recruiting sheet shared alongside the announcement, at least 29 members of the studio’s staff are now looking for work.
“After nearly 12 years riding the joyous rollercoaster of emotions that is making video games, our time together has come to an end,” Polyarc says. “As we wind down active development, we are saying our farewells to each other. Working together over all of these years has been an honor. Bringing surprise and delight to those who played our games has been a privilege. Thank you to everyone at Polyarc, our work is now finished.”
The Seattle-based studio’s Moss series was an early VR favorite, thanks in part to the way it fused traditional action-adventure gameplay with a camera system that let you peer around diorama-like levels while controlling Quill, the series’ mouse protagonist. Polyarc’s output also became a reliable catalog filler for various VR platforms — Moss launched on the PlayStation VR, and was also ported to the Oculus Quest as a launch title. Moss: Book II was similarly released on PSVR, Quest, SteamVR and Pico, and the studio even released one of the few VR games for the Apple Vision Pro, a multiplayer strategy title called Glassbreakers.
In May 2026, Polyarc tried to reach a non-VR audience with Moss: The Forgotten Relic, which collected the Moss series into a single game and reimagined the gameplay so you didn’t need a VR headset to play. It’s unclear how well the game has sold, but it evidently wasn’t enough to keep the studio afloat. The bigger issue might be changes to the VR ecosystem that made it harder to get new projects off the ground. Meta began its big pivot away from the metaverse towards AI products at the start of this year. Not only did the company close several of its own VR studios, but its retreat from the space likely made getting new VR games funded even harder.
Even though the studio is closed, all of Polyarc’s games remain available to purchase. If you have a VR headset collecting dust somewhere and haven’t tried them, they’re absolutely worth playing.
Tech
Why Is My VPN Slow? 10 Causes and Fixes for 2026
A VPN normally adds some network overhead, but a severe slowdown is usually caused by server distance or congestion, protocol choice, weak Wi-Fi, packet loss, MTU problems, device limits, or a poor route between your internet provider and the VPN server. The fastest way to diagnose the problem is to compare the same connection with the VPN off and on, then change one variable at a time.
Do not begin by changing advanced settings. Establish a baseline first. If the underlying connection is already slow, changing VPN servers, protocols, or packet sizes will not fix the real bottleneck.
Quick Fixes to Try First
These checks solve many VPN speed problems without changing low-level network settings. Work through them in order and retest after each change.
Checklist
- Disconnect the VPN and measure your normal internet speed.
- Reconnect to the nearest practical VPN server.
- Try a second server in the same city or country.
- Switch to another supported VPN protocol.
- Test over Ethernet if you are currently using Wi-Fi.
- Pause cloud backups, game downloads, system updates, and other large transfers.
- Update the VPN application.
- Restart the VPN app, device, and router if the problem persists.
The important troubleshooting rule is to change only one variable before each test. If you switch the server, protocol, Wi-Fi band, and DNS settings simultaneously, you will not know which change actually affected performance.
First Confirm the VPN Is Actually the Problem
A VPN cannot provide more usable capacity than the connection underneath it. VPN traffic still has to cross your Wi-Fi or Ethernet connection, your internet service provider, and the wider internet before reaching the VPN server.
VPNs also add processing and an additional network path. Cloudflare’s explanation of VPN speed factors notes that encryption and routing through an intermediary VPN server can increase latency and affect performance.
Run a Baseline Speed Test
Disconnect the VPN and test the connection on the same device and network you normally use. Record at least:
- Download speed: how quickly data reaches your device.
- Upload speed: how quickly your device sends data.
- Latency or ping: how long a request takes to travel to a destination and return.
- Packet loss: the proportion of packets that fail to reach their destination, if the testing tool reports it.
Our internet speed testing guide explains how to read download, upload, ping, and jitter results if you need a baseline before starting the VPN-specific diagnosis.
Reconnect the VPN and repeat the test under otherwise similar conditions. One result can be noisy, so several runs are more useful than one unusually good or bad measurement.
Read the Pattern, Not Just the Number
If both VPN-off and VPN-on results are poor, investigate the underlying internet connection first. If the connection is fast without the VPN but consistently much slower with it, the VPN path deserves closer inspection.
Different patterns point toward different causes. One slow VPN server suggests server congestion or routing. Every server being slow may indicate protocol, device, router, or provider limitations. A fast speed test combined with websites that stall halfway through loading can point toward packet loss, Domain Name System issues, or Maximum Transmission Unit problems rather than raw bandwidth.
10 Reasons Your VPN Is Slow and How to Fix Each One
1. The VPN Server Is Too Far Away
Distance usually affects VPN performance because your packets have to travel to the VPN server before continuing toward their final destination. The longer that round trip becomes, the more latency is added.
Latency is the delay between sending network traffic and receiving a response. It matters especially for gaming, video calls, remote desktops, and interactive web applications because these activities depend on frequent back-and-forth communication.
For example, if you are in Washington, D.C. and connect to a VPN endpoint in Tokyo, traffic must cross a long international path even when the website you are opening is hosted nearby in the United States.
Fix: connect to the nearest suitable city or country unless you specifically need a distant exit location. Proton’s current VPN speed guidance similarly recommends nearby servers and notes that distance and server load affect connection performance.
The geographically closest server is not guaranteed to be the fastest. Internet routing depends on peering arrangements and network topology, so test two or three nearby options rather than assuming the nearest city will always win.
2. The VPN Server Is Overloaded
A VPN server and its network connection have finite capacity. When many customers use the same endpoint at once, they compete for processing resources and available bandwidth.
The resulting symptom can be confusing because the VPN may work normally in the morning and become much slower during evening peak hours.
Fix: switch to another server in the same general region. If your VPN app displays server-load indicators, compare alternatives from that provider. Load percentages should only be treated as relative indicators within the provider because different companies calculate and expose them differently.
Suppose one London server is slow but another London endpoint performs normally on the same device and protocol. That strongly points toward server-specific congestion or routing rather than a problem with your home connection.
ExpressVPN’s current slow-speed troubleshooting similarly recommends moving to another VPN location when one endpoint performs poorly.
3. Your VPN Protocol Is a Poor Fit for the Network
A VPN protocol defines how your device establishes and transports the encrypted tunnel. Common options include WireGuard, OpenVPN, Internet Key Exchange version 2, usually called IKEv2, and provider-specific protocols.
Different protocols behave differently across operating systems, networks, firewalls, and connection types. A protocol that performs well on fiber may not behave the same way on a restrictive hotel network or unstable cellular link.
Fix: start with the VPN application’s automatic or recommended protocol. If performance remains poor, test the alternatives your provider supports and record the result of each one.
WireGuard is often a sensible option to test because it has a relatively compact design, but it should not be described as universally fastest. Implementation, hardware, server capacity, route quality, and the underlying network still matter.
OpenVPN can operate over User Datagram Protocol, or UDP, and Transmission Control Protocol, or TCP. UDP generally avoids some retransmission behavior of TCP and is commonly selected for performance-sensitive VPN use. TCP can be useful where network restrictions or reliability requirements favor it, but tunneling TCP traffic inside another TCP transport can behave poorly on lossy connections because multiple reliability mechanisms react to the same packet loss.
4. Your Wi-Fi Is the Real Bottleneck
A stable VPN cannot repair a weak wireless connection. Distance from the router, walls, radio interference, crowded channels, and a weak access point can all reduce speed or increase packet loss before VPN traffic even reaches the internet.
Fix: if possible, repeat the same VPN test over Ethernet. A large improvement over the wired connection identifies Wi-Fi as an important part of the problem.
You can also:
- move closer to the access point;
- try the 5 GHz or 6 GHz band when signal strength is sufficient;
- use 2.4 GHz when you need greater range and higher frequencies are weak;
- reduce local interference;
- test another trusted network.
A common diagnostic result is a laptop reaching high throughput over Ethernet with the VPN enabled but slowing dramatically from a distant bedroom over Wi-Fi. In that case, changing VPN providers is unlikely to fix the wireless bottleneck.
If the issue appears mainly on airports, hotels, or cafes, the existing public Wi-Fi safety guide covers additional network-selection and security checks.
5. Your Base Internet Connection Is Congested
VPN performance depends on the internet connection underneath it. A household connection that is already saturated by large downloads, cloud backups, video calls, or operating-system updates has less capacity available for the VPN.
Upload congestion deserves particular attention. When upstream traffic is fully saturated, acknowledgments and other small packets can be delayed, making downloads and interactive applications feel slower even when substantial downstream bandwidth remains available.
Fix: pause large background transfers and retest. Check other computers, consoles, televisions, phones, network-attached storage devices, and cloud-sync applications on the same connection.
Also compare performance at another time of day. If both VPN and non-VPN speeds collapse during the same evening period, the root cause is more likely to be local or ISP congestion than the VPN tunnel itself.
6. Packet Loss or Poor Routing Is Reducing Throughput
Packet loss means some network packets fail to reach their destination. Reliable protocols have to recover from those losses, which can reduce effective throughput and increase delay.
Common symptoms include:
- video calls breaking up;
- gaming latency jumping unpredictably;
- downloads repeatedly speeding up and slowing down;
- one VPN region performing much worse than another;
- remote desktop sessions freezing briefly.
The route between your internet provider and a particular VPN data center may also be inefficient even when normal non-VPN traffic follows a better route to the same general part of the internet.
Fix: test another VPN server, preferably in the same region first. Then compare another network, such as Ethernet versus Wi-Fi or a trusted mobile connection. If one server is consistently problematic while nearby alternatives are normal, report that server and the approximate test time to the VPN provider.
Do not conclude that an ISP is deliberately throttling VPN traffic simply because one route performs poorly. Congestion, peering problems, packet loss, and temporary routing changes can produce similar symptoms.
7. MTU or Fragmentation Problems Are Affecting Larger Packets
This cause is less visible but important when a VPN connects successfully and then certain websites, uploads, or larger transfers stall.
Maximum Transmission Unit, or MTU, is the largest packet size an interface or network path can carry under a particular configuration. A VPN adds its own headers and encapsulation overhead, which increases the size of the packet sent across the underlying network.
If a path cannot carry that resulting packet and the network’s Path MTU Discovery process fails, larger packets may be dropped or repeatedly fragmented.
OpenVPN’s current OpenVPN 2.7 manual explicitly describes the classic symptom: the VPN starts correctly but stalls during active use when Path MTU Discovery is broken. It documents controls such as mssfix and fragmentation for specific OpenVPN UDP configurations.
Beginner fix: do not start by entering arbitrary MTU values. First update the VPN software, reconnect, try another protocol, and use the provider’s automatic configuration. A protocol change can alter encapsulation behavior enough to avoid the problematic path.
Practitioner fix: if you administer the tunnel or router, investigate the actual path MTU and Maximum Segment Size rather than copying a value from an unrelated connection. Cisco’s documentation on IPsec pre-fragmentation likewise describes how tunneling overhead can cause downstream fragmentation around near-MTU packets.
OpenVPN-specific options should not be copied into WireGuard, IKEv2, or proprietary VPN configurations. Each tunnel technology handles packet sizing differently.
8. Your Device or Router Cannot Process the VPN Fast Enough
Encryption and tunnel processing must happen somewhere. If the VPN application runs on a laptop or phone, that device performs much of the work. If the VPN is configured directly on a router, the router may have to encrypt and route traffic for every device in the home.
This becomes noticeable on fast internet connections because a low-power router can hit its processing ceiling long before the internet plan reaches its advertised maximum.
Fix: compare the router-based VPN with the VPN application’s performance on a reasonably modern computer using the same general network and nearby server. If the laptop reaches much higher throughput, router processing may be the bottleneck.
Other clues include unusually high processor use, a router interface becoming sluggish during large transfers, or a very consistent VPN speed ceiling regardless of which fast server you select.
There is no universal throughput limit for VPN routers. Processor architecture, hardware acceleration, cipher implementation, tunnel protocol, firmware, packet size, and thermal limits all affect the result.
Some VPN features intentionally prioritize privacy, censorship resistance, or filtering rather than maximum throughput.
Examples include:
- multi-hop VPN routing;
- privacy-focused hardened entry servers;
- Tor routing;
- traffic obfuscation;
- advanced filtering or inspection features.
Multi-hop is the easiest example. Instead of passing through one VPN server, traffic passes through additional infrastructure before reaching the wider internet. That creates more distance and additional processing opportunities.
Fix: compare a normal single-hop connection with the advanced feature disabled only if your security requirements allow it. Do not automatically disable privacy or anti-censorship features simply to gain speed if they are important to your threat model.
If performance returns to normal with the extra feature off, the slowdown may be an expected operational trade-off rather than a fault.
10. The VPN App, Provider, or Free Tier Is the Bottleneck
After eliminating local network problems, the limiting factor may genuinely be the VPN service.
Possible causes include:
- an outdated application;
- a buggy VPN network adapter or driver;
- a temporary provider outage;
- congested data-center connectivity;
- a small free-server pool;
- free-tier speed restrictions;
- an account or plan that provides access to fewer high-capacity servers.
Fix: update the VPN app, restart it, test multiple nearby servers, compare supported protocols, and check the provider’s official service-status information if available.
Free services require particular care. Some impose a formal speed restriction. Others do not throttle bandwidth directly but expose fewer servers, which can leave free endpoints more heavily loaded.
If the same device and connection perform well without the VPN but remain dramatically slower across several VPN servers and protocols, the provider becomes a more plausible bottleneck.
Troubleshooting Table: Match the Symptom to the Likely Cause
The symptom often tells you where to test next. Use this table to avoid changing unrelated settings.
| Symptom | Likely causes | First test |
|---|---|---|
| Every VPN server is slow | Base internet, protocol, device processing, router, or provider | Run VPN-off baseline on the same device |
| Only distant countries are slow | Latency and route distance | Connect to a nearby server |
| One server is much slower | Server congestion or poor route | Try another server in the same city or country |
| Speed test is fast but pages hang | MTU, DNS, packet loss, or site-specific filtering | Change protocol, then retest the affected site |
| Gaming or calls lag while downloads remain acceptable | Latency, jitter, packet loss, or distant routing | Use the nearest server and compare ping |
| VPN is much slower on the router | Router CPU or firmware processing ceiling | Run the same VPN on a laptop |
| VPN is slow only over Wi-Fi | Signal quality, interference, wireless congestion | Repeat the test over Ethernet |
| VPN becomes slow at night | ISP congestion or VPN server load | Compare VPN-off and VPN-on tests at the same time |
| Free VPN is consistently slower | Small server pool, congestion, or plan restriction | Try another free server if available |
| Connection starts but large transfers stall | MTU or fragmentation issue | Switch protocol before changing MTU manually |
The useful pattern is comparative. A result that changes when you alter one server suggests a different cause from a result that stays identical across every VPN location.
How to Test Whether a Fix Worked
A good troubleshooting test changes one factor and holds the others as steady as reasonably possible.
- Use the same device.
- Stay on the same Wi-Fi or Ethernet network.
- Use the same VPN location unless the server itself is the variable being tested.
- Use the same speed-test service and nearby test destination.
- Run several measurements instead of relying on one result.
- Record download speed, upload speed, and latency.
- Record packet loss or jitter if the tool provides them.
Suppose you are testing protocols. Leave the VPN server unchanged, switch from protocol A to protocol B, reconnect, and repeat the same measurements. If you are testing servers, leave the protocol unchanged and move only to another nearby server.
Do not rely on a universal rule such as “a VPN should lose no more than 10%.” The relative difference depends on your internet speed, server distance, device, protocol, network path, and workload. A 30 Mbps loss has very different implications on a 50 Mbps connection than on a 1 Gbps connection.
Latency may also matter more than headline download speed. A remote worker could prefer 200 Mbps with stable low latency over 400 Mbps with severe jitter if the main workload is video conferencing and interactive remote sessions.
When Slower VPN Speed Is Expected
Some performance loss is a normal consequence of the route or security features you deliberately selected.
- Distant VPN server: longer round trips increase latency.
- Multi-hop routing: traffic crosses additional VPN infrastructure.
- Tor-related routing: additional relay hops prioritize anonymity properties rather than raw speed.
- Obfuscation: extra processing may be necessary on networks trying to detect or block VPN traffic.
- Busy shared server: available capacity may vary with demand.
- Router-level tunneling: low-power hardware can limit encryption throughput.
Expected overhead should not become an excuse for accepting a severe unexplained slowdown. If a nearby single-hop server performs dramatically worse than the same internet connection without the VPN, controlled troubleshooting is still worthwhile.
Contact support after you have established a repeatable pattern rather than sending only “the VPN is slow.”
Useful diagnostic information includes:
- operating system and version;
- VPN application version;
- VPN protocol;
- server name, city, or country;
- approximate time of the problem;
- VPN-off and VPN-on speed results;
- whether the connection uses Wi-Fi or Ethernet;
- internet provider or network type;
- whether another nearby VPN server behaves normally.
If the slowdown began immediately after a software update, say so. If only one server is affected, identify that server. These details help separate application problems from server, routing, or local-network issues.
Do not send passwords, recovery codes, private keys, authentication tokens, or other credentials in diagnostic messages.
Key Takeaways
- Always measure the internet connection without the VPN before blaming the tunnel.
- A nearby alternate server is the quickest test for distance, congestion, and routing problems.
- Protocol choice can materially affect performance, but no single protocol is universally fastest on every network.
- If VPN performance is poor only over Wi-Fi, fix the wireless connection before replacing the VPN.
- Packet loss can make calls, games, and downloads feel slow even when the connection still reports substantial bandwidth.
- A VPN that connects successfully but stalls during larger transfers can have an MTU or fragmentation problem.
- Router hardware can become the throughput ceiling when it performs VPN encryption for an entire network.
- Multi-hop and obfuscation can intentionally trade some performance for additional privacy or censorship resistance.
- Change one variable at a time and repeat measurements before deciding that a fix worked.
Frequently Asked Questions
Why is my VPN fast for downloads but slow for gaming?
Large downloads depend heavily on throughput, while games are much more sensitive to latency, jitter, and packet loss. A VPN may provide plenty of download bandwidth while adding enough round-trip delay to affect real-time gameplay. Connect to a nearby VPN server and compare latency rather than focusing only on Mbps.
Why does my VPN slow down only at night?
Evening slowdowns often point toward congestion. Your internet provider, local network, or VPN server may be carrying more traffic during peak hours. Test the same connection with the VPN off and on during the slow period. If both degrade similarly, the underlying connection is the stronger suspect. If only one VPN server becomes slow, try another nearby endpoint.
Why is my VPN much slower on my router than on my laptop?
The router may not have enough processing capacity to encrypt and route traffic at the same rate as the laptop. Consumer routers vary widely in processor performance and hardware acceleration. If the VPN app on a modern computer is significantly faster than the same service running on the router, the router is likely contributing to the throughput ceiling.
Can changing DNS make a VPN faster?
Changing Domain Name System servers can improve how quickly a domain name begins resolving when DNS itself is slow, but it normally does not increase the bulk throughput of an established VPN download. If pages hesitate before loading but large downloads are fast once they start, DNS deserves investigation. If every large transfer is slow, look elsewhere first.
Why do websites load halfway and then stop when my VPN is connected?
Several problems can cause this, including packet loss, site-specific VPN filtering, DNS issues, or an MTU problem. MTU trouble is especially worth considering when small requests succeed but larger responses or uploads stall. Try another protocol and VPN server before changing manual packet-size settings.
Does split tunneling make a VPN faster?
Split tunneling can reduce the amount of traffic passing through the VPN because selected applications or destinations use the normal internet connection instead. Those excluded applications may therefore perform differently, but split tunneling does not inherently accelerate the traffic that remains inside the VPN tunnel.
Can a VPN ever make my internet faster?
Occasionally. A VPN may send traffic through a route that happens to be better than the ISP’s normal route, or it may alter the handling of traffic that was being selectively constrained. That is an exception rather than something to expect. A VPN cannot create additional physical bandwidth in the underlying internet connection.
Why does my VPN keep slowing down and then speeding up again?
Variable performance commonly points toward changing server load, Wi-Fi interference, packet loss, cellular signal changes, or congestion somewhere along the network path. Test another nearby server and compare a wired connection where possible.
Tech
The 9 Best TV Shows to Stream This Month (September 2026)
September is typically the time when television gets serious again. The summer’s biggest TV shows have aired their finales, the fall schedule is kicking into high gear, and streamers are rolling out everything from high-concept sci-fi to prestige dramas. There’s plenty of familiar IP in the mix, but also some genuinely original shows worth putting on your to-watch list.
While plenty of outlets will tell you what everyone is watching (see: Reacher), that’s not our goal. As always, the TV shows we’re watching this month reflect the kinds of stories WIRED covers every day—shows that explore technology, science, politics, culture, and the sometimes unsettling ways they intersect.
From returning favorites to ambitious new series—and at least one show that might rekindle your love of traditional anime—these are the TV shows we think you should make time to stream this month.
The Paper
What happens when a newspaper attempts not just to survive, but to thrive, in a world where digital media has become the norm? The Paper, a spinoff of The Office from Greg Daniels and Michael Koman, follows the staff of a struggling Midwestern paper as they attempt to revive it.
Ultimately, its idealistic new editor-in-chief Ned Sampson (Star Wars and Harry Potter alum Domhnall Gleeson) and his hungry young reporter Mare Pritti (Chelsea Frei) end up grappling with what journalism looks like in the digital age. Season 2, which arrived on September 9, finds their Toledo Truth Teller newly revitalized and searching for its next big scoop, making the show a surprisingly sharp comedy about the future of journalism—and who gets to shape it.
Lego Star Wars: The Mandalorian
Though this summer’s The Mandalorian and Grogu (which is streaming on Disney+ now) seriously underperformed at the box office, Lucasfilm is partnering with Lego to take another stab at the fan-favorite Star Wars series—which might be exactly what the franchise needs right now. Lucasfilm and Lego are going back to the beginning, reimagining all three seasons of the Pedro Pascal–starring live-action series as a 49-minute animated comedy.
Tech
Amazon Quick is now available on desktop, with a new mobile activity feed
Amazon has made its Quick desktop assistant generally available on macOS and Windows, pitching it to enterprise IT as the governed alternative to shadow AI. Quick runs in ordinary European AWS regions with inference kept inside Europe, but it is not on the published service list for the sovereign cloud AWS opened in Brandenburg in January to put European data beyond the reach of US law.
Amazon has made its Quick desktop app generally available on macOS and Windows, AWS said, and added an activity feed to the iOS and Android versions that pools email, calendar, CRM and messaging into one list.
The pitch is governance. Amazon says customer data stays inside the customer’s own environment, conversations stay private, and audit trails run through CloudWatch and CloudTrail. It describes the underlying AWS as the infrastructure behind the world’s most security-sensitive workloads.
The compliance list is HIPAA, FedRAMP, SOC 2 and ISO 27001. The argument underneath is that shadow AI is what happens when staff route around approved tools, and that the answer is a sanctioned assistant rather than a ban.
In Europe that argument runs into a distinction Amazon drew itself in January.
Quick has run in the AWS Frankfurt region since March, with inference requests routed only within European regions. It also runs in London and Ireland.
Those are ordinary AWS regions.
The AWS European Sovereign Cloud is not. It opened in Brandenburg on 14 January, staffed only by EU residents and overseen by a board of EU citizens, on a commitment of EUR 7.8B.
Quick does not appear on its published service list. SageMaker and Bedrock do.
The distinction matters to the buyers Amazon is describing. Airbus is moving 70 applications off AWS to the French provider Scaleway, out of roughly 900 it runs, on a contract worth more than EUR 50M.
Its stated test was legal safeguards against non-European laws. The law in question is the US CLOUD Act, which reaches American companies’ data wherever in the world it is held.
Then there is the question of whether anyone pays. Of the Microsoft 365 users who can reach Copilot Chat, 3.3% pay for Copilot, about 15 million seats out of 450 million.
Amazon names three customers in the announcement, Southwest Airlines, Labcorp and the PGA Tour. All three quotes are supplied testimonials. The post gives no pricing, no seat numbers and no date for sovereign cloud support.
Quick’s case is that it is the assistant IT already controls. In Europe the follow-up is which AWS they control it from, and European rivals are selling the answer.
-
Tech3 days agoMemory prices are slowing because buyers ran out of money
-
Business2 days agoMicron Stock Climbs Above $1,031 as AI Memory Crunch and a $50 Billion Outlook Fuel the Rally
-
Business2 days agoAMD Stock Climbs After Management Lifts 2027 Data Center Outlook Toward $70 Billion in AI Sales
-
Crypto World3 days agoBitcoin price risks $76K drop as $78K support weakens
-
Crypto World3 days agoRobinhood Stock: How To Take Advantage With Reduced Risk
-
Crypto World3 days agoEthereum price stalls below $2,500 as ADX drops to 11
-
NewsBeat3 days agoEngland up in reading, maths and science rankings as Scotland and Wales dip
-
NewsBeat3 days agoWhat went right this week: an ‘historic’ fall in violent crime, plus more
-
Crypto World3 days agoIntel Stock Jumps 9% on Chip Price Hike Report, US Stake Gains $36 Billion
-
Crypto World2 days agoBitcoin price risks $70K if $78K neckline breaks
-
Crypto World3 days agoBitcoin price holds near $79K as cycle drawdowns narrow
-
Crypto World1 day ago2 Chip Stocks Broke Out This Week. Neither Was Nvidia
-
Business3 days agoMeta debuts long-awaited personal AI agent, Muse
-
Crypto World1 day ago
Ethereum Price Analysis: Consolidation at $2.5K Tests Momentum as On-Chain Activity Surges
-
Sports4 days agoPhones confiscated, players sent home: Pakistan’s England tour turmoil revives memories of Mohammad Amir, Salman Butt and Mohammad Asif’s 2010 Lord’s spot-fixing scandal | Cricket News
-
Crypto World1 day agoOKX launches 10x OpenAI, Anthropic X-Perps in Europe
-
Crypto World2 days agoEthereum price breakout hinges on a close above $2,535
-
Crypto World3 days agoPump Fun and Kraken delete Hunter Biden $LAPTOP promotion
-
Crypto World3 days agoBrent Crude Oil Moves Above $100 for the First Time in 3 Months
-
Entertainment2 days agoCase Sees Major Update As Jury Deliberations Begin


You must be logged in to post a comment Login