The number was the easy part
#privacy #VPN #Android #Zambia #OnyxAudit
The claim
On 11 August 2026, two days ahead of Zambia's general election, David Peterson posted a thread cautioning Zambian voters about the VPN apps topping their app stores. Peterson is General Manager of Proton VPN. His bio states that his posts do not count as official company statements until reposted by @ProtonVPN. @ProtonVPN then quote-tweeted the thread, so by his own stated test it became a company position.

That matters only because it sets the standard. A commercial VPN provider warning people away from competing VPN providers is not automatically disqualified from being right, but it is also not a source you take on trust.
He advanced five checkable claims. I tested each one against primary evidence rather than against his citations, and I reproduced the central measurement myself.
Thirty trackers
The headline number was that Turbo VPN carries thirty trackers reporting back to China, Russia, Israel and Five Eyes countries.
A figure like that needs an APK behind it, not a screenshot of someone else's article. Tracker counts belong to a specific build, so an older analysis showing seven says nothing about a current one showing thirty, and the reverse is equally true. The version is the entire question.
Exodus Privacy, Turbo VPN version 4.3.0.2, source Google Play, report created 11 August 2026:
30 trackers. 21 permissions.
The number matches exactly.

I went in expecting this to be the weak point, because I could not locate the figure anywhere before I ran the scan myself. It held. Two rules were operating here and both need to be stated: I was not going to accept thirty simply because someone had written it down, and I was not going to dismiss thirty because a different version of the app had produced a different count.
The four countries
Peterson's jurisdictions hold at the level of corporate origin. Working through the actual SDK list in that report:
China. Huawei Mobile Services Core, Pangle, Mintegral.
Russia. Yandex Ad, myTarget, AppMetrica.
Israel. ironSource.
Five Eyes. Google AdMob, Firebase Analytics, Crashlytics, Facebook Ads, Amazon Advertisement, AppLovin, Chartboost, InMobi, Unity3d Ads, Adjust, Fyber, Tapjoy, Vungle.
Every jurisdiction he named has at least one SDK behind it. Israel, which I could not source at all before running the scan, rests on ironSource, an Israeli mobile advertising platform.
So the claim has a factual basis. What it lacks is the meaning most readers will draw from it, and I will return to that later.
The ownership chain
Turbo VPN's listed developer is Innovative Connecting Pte. Ltd., registered in Singapore. Its shareholder is Lemon Seed Technology Ltd. of the Cayman Islands. Qihoo 360 disclosed in its 2019 annual report to the Shanghai Stock Exchange that it had acquired Lemon Seed along with Lemon Clove Pte. Ltd. and Autumn Breeze Pte. Ltd. for 69.4 million dollars and an intangible asset.
Qihoo 360 sits on the US Commerce Department's Entity List and is designated by the US Department of Defense as a Chinese military company. A 2015 article in the state-run China Daily reported that its customers included the People's Liberation Army and at least eight government ministries.
Two corrections to how Peterson presented it. The app identified by the Tech Transparency Project is Signal Secure VPN, not "SecureVPN". And Thunder VPN, which he advised iPhone users to avoid, was removed from the Apple App Store after the Financial Times put the findings to Apple. Advising people to avoid an app that is no longer available is stale advice rather than wrong advice, but it is still worth recording.
There is also a detail he skipped. Qihoo appears to have sold Autumn Breeze and two other companies to unnamed parties in 2020, shortly after the sanctions took effect, while Autumn Breeze's corporate records continued to list a director whose name matches the individual who previously ran Qihoo's mobile security unit. Present-tense ownership is messier than a clean line.
The research is worse than he said
This is the point where I expected rhetoric to outrun the evidence, and found the opposite.
Benjamin Mixon-Baca, Jeffrey Knockel and Jedidiah R. Crandall published Hidden Links: Analyzing Secret Families of VPN Apps at Free and Open Communications on the Internet, FOCI 2025. They located hard-coded Shadowsocks passwords shared across supposedly independent providers, extracted them, and confirmed they could decrypt the traffic of affected clients.
Read that again. Not a theoretical weakness and not a potential exposure. Extracted credentials, shared across apps and servers, with demonstrated decryption.
No Chinese ownership is required for that to harm you. No state actor, no compulsion, no jurisdiction argument. An ordinary network eavesdropper holding the extracted password is enough, and the same credentials work across different apps because the providers share backend infrastructure.
It is the single most serious finding in this entire subject. It is independent of Proton, and it barely appears in the thread that was supposed to be warning people.
The two things he missed
Both were present in the report I ran.
Huawei Mobile Services Core carries a location tag. Exodus classifies it as location, advertisement and analytics. It is the only tracker in Turbo VPN's list flagged for location, it is Chinese, and it sits inside a VPN. Peterson claimed the iOS apps track location. The stronger version of that claim was already present in the Android build.
Two separate mechanisms for enumerating installed apps. The permission list contains both QUERY_ALL_PACKAGES and GET_INSTALLED_APPS. Google restricts the former to apps that can demonstrate a core-functionality need, and it is not obvious what that need would be for a VPN. The list also includes CAMERA, which Google marks as a dangerous permission.
And one artefact that takes thirty seconds of anyone's time. The APK signing certificate reads:
Common Name: Noodies Chen, Locality: GZ, State/Province: GD, Country: CN
Guangzhou, Guangdong. A Singapore-registered developer shipping an application signed in mainland China, visible to anyone who scrolls to the bottom of a free public report. That fact does more work than the entire Cayman Islands shell structure, and it requires no corporate registry access.
The app that is not what he said
Peterson named Fast VPN Super as Chinese-owned. I could not verify that, and following the trail produced something else.
The iOS app VPN - Fast VPN Super, App Store ID 1528940523, lists its provider as TOPAPPS TECH PTE LTD, at 10 Jalan Besar, #10-05 Sim Lim Tower, Singapore 208787. The same corporate name and address appear on Google Play as the developer of the Android app VPN Proxy Speed - Super VPN, package com.supervpn.vpn.free.proxy, with over 100 million downloads.

That is a genuine cross-platform link, established from platform records rather than from resemblance. What it is not is a link to Qihoo 360. TOPAPPS is a separate Singapore entity, and nothing I located connects it to the Innovative Connecting cluster. Singapore incorporation tells you where a company is registered, not who owns it, so Chinese-owned remains unverified for this app.

I scanned the Android sibling for completeness. Super VPN 4.6.9, report created 12 August 2026: 21 trackers, 24 permissions. An earlier report for version 4.5.5 from 28 June returns the same counts, so the footprint is stable across builds rather than a one-off spike. The permission list includes USE_BIOMETRIC and USE_FINGERPRINT, which is a question worth asking of a free VPN, and the report notes that no valid signing certificate was found.
None of that measures the iOS app he actually named. Same developer is not the same binary.
Zambia
The context holds. Zambia's general election took place on 13 August 2026. Access Now and the #KeepItOn coalition published an open letter to President Hakainde Hichilema on 5 August. During the 2021 election, Zambian authorities disrupted access to Facebook, Twitter and Instagram nationwide, with similar disruptions recorded in 2020 and 2016.
One omission on his side. In June 2026 the Ministry of Technology and Science publicly assured Zambians that the government would not deliberately shut down the internet during these polls. That assurance does not make a warning unreasonable given the historical record, but leaving it out leaves the picture one-sided.
The sharper current story sits elsewhere: journalists arrested and summoned under Zambia's Cyber Crimes Act No. 4 of 2025, and legal challenges to the surveillance and interception provisions of the Cyber Security Act No. 3 of 2025.
Where the claim stops reaching
Everything above establishes what is present in the software. It does not establish where your traffic goes.
An advertising SDK runs inside the app process and collects device identifiers, install attribution and usage events. It has no visibility into the encrypted tunnel. Thirty tracker signatures with corporate origins in four jurisdictions is therefore a data-collection finding, and a real one. It is not evidence that a VPN tunnel is being delivered to Beijing, Moscow, Tel Aviv or Fort Meade.
Corporate origin is not network destination. A signature is not a transmission. Exodus states this itself at the foot of every report: these are signatures located by static analysis, and their presence is not proof that the trackers are active.
That caveat applies to my measurement in exactly the same way it applies to Peterson's.
The chain the reader is invited to follow is: SDK present, therefore tracker active, therefore data transmitted, therefore sent to that company's home country, therefore available to that country's government, therefore your browsing is being watched. Each step sounds plausible. Only the first is measured.
The ledger
- Thirty trackers. Reproduced independently. Turbo VPN 4.3.0.2, Exodus, 11 August 2026.
- Four countries at corporate-origin level. Supported by the SDK inventory, including Israel via ironSource.
- Ownership links to Qihoo 360. Supported by corporate records and Qihoo's own annual report.
- Security flaws. Supported, and understated: the research demonstrates decryption, not merely the possibility of it.
- Fast VPN Super is Chinese-owned. Unverified. The developer is a Singapore entity with no established link to the Qihoo cluster.
- Thunder VPN on iOS. Stale; Apple removed it.
- Traffic being sent to those four countries. Not established, and not tested by anything in the thread.
Which leaves an uncomfortable result for anyone looking for a simple verdict. Peterson was substantially right, more right than his own thread shows, and the strongest evidence against these apps is evidence he did not use.
The problem is not that the warning was false. It is that several true observations were joined into a single proposition stronger than any of them supports, and the reader was left to make the joins.
Method and limitations
Every scan referenced here was run or retrieved by me through Exodus Privacy against the Google Play build, on a Samsung Galaxy A56, with the version number and report date recorded in each case. Static analysis only. No traffic capture, no dynamic instrumentation, no behavioural testing, and therefore no claim about what any tracker actually does at runtime.
I did not test any iOS application, because I do not have an iOS device. Where iOS claims appear above they rest on App Store listings and prior published research, not on my own measurement.
App store rankings within Zambia could not be verified from South Africa. That claim is neither confirmed nor disputed here.
The Financial Times investigation referenced in this area sits behind a subscription and I have not read it directly. Where its findings appear, they are relayed through the Tech Transparency Project's account and labelled as such.
Innovative Connecting told the Financial Times that its article was not accurate, and declined further comment. Qihoo 360 and Chen Ningyi did not respond. Guangzhou Lianchuang declined to comment. None of that disproves the reporting, and leaving it out would make this account incomplete.
I hold no commercial relationship with any VPN provider named here, and none with Proton.
Sources
Exodus Privacy, Turbo VPN 4.3.0.2, report created 11 August 2026: reports.exodus-privacy.eu.org
Exodus Privacy, Super VPN (com.supervpn.vpn.free.proxy) 4.6.9, report created 12 August 2026
Mixon-Baca, B., Knockel, J., and Crandall, J.R., Hidden Links: Analyzing Secret Families of VPN Apps, FOCI 2025, pp. 18 to 27
Tech Transparency Project, Apple Offers Apps With Ties to Chinese Military, 1 April 2025
Tech Transparency Project, Spot Check: Apple and Google Still Have a Chinese VPN Problem, 12 June 2025
Access Now and the #KeepItOn coalition, open letter to the President of Zambia, 5 August 2026
Apple App Store listing, VPN - Fast VPN Super, ID 1528940523
Google Play listing, VPN Proxy Speed - Super VPN, TOPAPPS TECH PTE LTD
Clayton Bax
Published under ONYX Digital Intelligence
Following the #OnyxAudit methodology.
- X: @onyxaudit
- Email: onyxdigitalintelligence85@protonmail.com
- https://github.com/Baximus855
- @Onyx_Digital@mastodon.social
"Adjacent to true is not true."
Truth has no flag nor favour, only a standard. And it's heavy