Is VPN Satoshi — Chrome VPN extension safe?

Medium risk

VPN Satoshi collects a browser fingerprint on startup and transmits it to its backend, while storing credentials encrypted with a hardcoded key.

On startup, the extension builds a fingerprint from canvas, WebGL, audio context, and hardware properties and sends it to api.aamenista.pro, attaching the returned signature to every subsequent API request. Access tokens and proxy credentials stored in local extension storage are encrypted with a static AES-GCM passphrase that is fully readable from the distributed bundle. The extension also fetches its live backend API endpoint list from Yandex Cloud S3, decrypted with a hardcoded AES-CBC key and IV ('1234567890123456'), allowing the active server pool to be redirected remotely.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

vpn-satoshiv4.0.22Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Data recipients

api.aamenista.prostorage.yandexcloud.net
Updated 17 September 2026oafoojegpciffpajphojgkkdgnngigfb