cryptostorm
Tap a star to rate
A token-based VPN aimed at the privacy-minded
cryptostorm describes itself as "The VPN service provider for the truly paranoid", and its single long homepage reads that way: it is a VPN and nothing else, built around anonymous access tokens instead of user accounts. A buyer pays, receives a token, and uses a hash of that token as the OpenVPN username, with the password left as anything. The site even includes a SHA512 calculator for making the hash in the browser, and links a non-JavaScript version for people who keep scripts switched off.
Who can buy it: prices are shown only in US dollars, and the site offers five ways to pay. PayPal and credit card through CCBill (which the site says "supports most prepaid cards") both allow recurring subscriptions and one-off orders. Monero is accepted with "no 3rd parties, no email or JS required". NOWPayments covers "~200 cryptocurrencies supported", again with no email or JavaScript, and BitPay takes "BTC, ETH, or any other cryptocurrency supported by BitPay". The site itself is also reachable as a Tor hidden service and as an I2P eepsite at cs.i2p, and a translations link sits in the footer. The connect section names Windows, Mac, iOS, Linux, Android and routers. The site does not name any app store, and it does not list countries where it will or will not sell.
What the provider says about logging, and who runs it
The site does not name an independent audit of its logging policy. Its logging claim is short and in its own words: "Our VPN servers never save data that can be used to identify a customer." The provider backs that claim with design choices rather than an outside report. It states that "Access tokens are hashed before connecting" so that "Compromised or confiscated servers can't be used to identify clients", that "All server-side configs are public" and available for review, and that the service is "Open source" with "no proprietary code". It also invites doubt: under the heading "Don't trust that we're not logging?" it suggests connecting to another VPN or to Tor first, as client-side multihop. The footer links a privacy policy and a warrant canary, and the site says "(too many) details on how the network operates" are on its blog and privacy policy page.
The server hardening list is specific. The provider says it runs linux-hardened kernels with exploit mitigation, practices least privilege, mandatory access control and privilege separation, uses AIDE for integrity checking "to prevent backdoors", treats servers as disposable and manages its keys through a secure PKI, so that "Confiscating one server won't compromise the rest." These are the provider's descriptions of its own setup; the site links no outside review of them.
Ownership is described in two ways on the same page. The body says "Decentralized organization, roots in Iceland, entities worldwide" and "Financials in several regions. No central office, anywhere." The footer, meanwhile, reads "Cryptostorm LLC, Dover, DE, US". The site does not explain how that US company relates to the Icelandic roots or the other entities it mentions, and it does not name them.
Protocols, network and features
The VPN protocols the provider supports are OpenVPN and WireGuard, and the homepage lists the cryptography for each. The OpenVPN ECC instances use Ed25519, Ed448, secp521r1 and ML-DSA-87, the last labeled post-quantum, with 521-bit EC keys that the site equates to roughly 15360-bit RSA, TLSv1.3, AEAD authentication, and either 256-bit AES or ChaCha20 with Poly1305. The OpenVPN RSA option uses an 8192-bit RSA server certificate, a 521-bit EC certificate authority and 8192-bit DH parameters. WireGuard uses ChaCha20 with Poly1305, Curve25519, BLAKE2s, SipHash24 and HKDF, as the site lists them.
The feature list is long:
- Server-side multihop to "doublehop between endpoints", plus the client-side chaining idea above.
- DeepDNS, the provider's own encrypted DNS system, public DNSCrypt v2 servers and anonymized DNS.
- Direct access to Tor .onion and I2P .i2p addresses through the VPN.
- DNS and WebRTC leak protection and DNS-based ad and tracker blocking.
- "Many different killswitches available".
- Obfuscation over SSH or HTTPS (via Xray or stunnel) or obfs4, pitched as a way to "bypass restrictive firewalls".
- Connections on any port, UDP or TCP, from 1 to 65535.
- "BitTorrent allowed" and "Port forwarding supported".
- Unlimited bandwidth with "No data caps, no throttling".
On the network itself, the site says it uses bare metal, "dedicated servers only", with redundant load balancing, and that there are "Currently over 450 available IPs" with IPv6 support. It points to an uptime page for the detailed server list but does not give a server or country count on the homepage. It names no streaming service and makes no streaming claims, and it does not say the service works in any particular country.
Prices, devices and the fine print
Every plan is priced in US dollars, and the device figure is, in the site's words, "the maximum number of devices allowed to connect at the same time." The recurring subscriptions are yearly at $52 for 4 devices, semiannually at $28 for 3 devices, quarterly at $16 for 2 devices, monthly at $6 for 1 device, and weekly at $1.86 for 1 device, though the weekly option is listed only under PayPal. One-off orders use the same prices and add two years at $94 for 5 devices, plus bundles of 1-month tokens: 5 for $24, 11 for $48 and 25 for $97. Not every term is available with every payment method: CCBill stops at one year, NOWPayments starts at three months, and BitPay starts at one month. The recurring subscriptions are listed at those same prices, and the site does not state a separate renewal price or say whether prices can change.
Anyone who needs more devices is told to "buy more tokens, or buy ones that allow more devices, or setup your router to use cryptostorm." The footer links a refund policy, but the homepage does not state a refund window or a free trial. Support is through a live chat link in the footer and a contact page; the homepage does not describe support hours.
What the site leaves open, and who it suits
The open questions are about people and paperwork more than technology. There is no named audit, and the logging claim rests on the provider's word and its published configs. The site names Cryptostorm LLC in Dover, Delaware, while describing a decentralized organization with Icelandic roots and no central office, and it does not reconcile the two. The server count and country list sit on a separate uptime page, and the refund terms sit behind a link.
For readers who want anonymous signup, cash-like payment in Monero, token-based logins, published server configs, obfuscation options and port forwarding, cryptostorm offers a detailed technical account of itself. It suits less well someone who wants polished apps from an app store, streaming claims, a named independent audit or a plain answer about which company is legally responsible for the service.