Cao and Green analyze Nym’s live network, source code, node selection, staking, and performance scoring. They find differences between the early white paper and the deployed Nym VPN design, including more centralized layer assignment than the design implied.
Their simulations and limited mainnet experiments identify a framing attack against node performance scoring. The attack could make malicious nodes cheaper to place in the active set and thereby increase the chance of fully compromised routes. The authors disclosed the findings to Nym, which acknowledged them and changed development priorities.
This paper does not show that ordinary NymVPN sessions are routinely traced. It shows that token incentives, reputation, and permissionless node entry create additional attack surfaces that a marketing claim such as “decentralized” does not resolve.
Built on 1 source (1 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (35 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "GPT-5", "label": "GPT-5 (94%)", "lines": 33, "share": 0.9428571428571428}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (3%)", "lines": 1, "share": 0.02857142857142857}, {"model": "Claude Sonnet 5", "label": "Claude Sonnet 5 (3%)", "lines": 1, "share": 0.02857142857142857}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}