noKYCme

Case file · VPN

Cryptostorm

A token-only VPN: buy an access token anonymously, no account or email — an elite no-KYC model run by operators you cannot identify.

Never KYC
Based
Opaque — Cryptostorm LLC (Delaware, US) / historically Baneki (Canada); no central HQ
Price
Token access; pay by Monero, Bitcoin or ~200 coins
Reviewed
2026-08-02
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

7.9/10 · Guaranteed no-KYC

On the no-KYC axis this is close to ideal: the terms unconditionally refuse KYC and age/ID verification, you buy an access token anonymously with no account or email, only a hashed token ever reaches the auth server, and it accepts Monero with .onion/.i2p ordering. What holds it back is trust, not privacy: the operators are pseudonymous, there is no independent audit (only open client configs), the jurisdiction is opaque and 5-Eyes-adjacent (a Delaware entity and historically a Canadian one, behind Icelandic .is branding), and it carries an old, unresolved reputational cloud around its founder history that we report as attributed allegation, not fact. No deanonymization or log-handover has ever been corroborated. It lands at 7.9/10 — an elite token model with the lowest trust in our VPN cohort.

What the internet says

3 recurring praises · 3 recurring gripes

Most praised: broad praise for the anonymous token model and monero payment. Most cited downside: pseudonymous operators; no independent audit.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Specs & jurisdiction.

Jurisdiction
Opaque — Cryptostorm LLC (Delaware, US) / historically Baneki (Canada); no central HQ; .is is branding, not domicile
Intel-sharing
5-Eyes-adjacent (US/Canada entities)
Logging
Node logging disabled; auth server holds only a SHA-512 token hash + session count; website logs (visitor IP) kept 2 weeks
Anon. payment
Monero, Bitcoin + ~200 coins (PayPal/CCBill = non-anonymous)
Protocols
WireGuard, OpenVPN (ECC + post-quantum)
Network
Token-authenticated node network
Devices
Multiple
Kill switch
Yes (config)
RAM-only
Private keys held in RAM (not a full diskless claim)
Open source
Client configs + tooling open (no public server/auth stack)
Audited
No independent audit (open configs only)
Free tier
No (free token discontinued after 10 years)

The full read

Our analysis, in plain words.

Cryptostorm is one of the purest expressions of the no-KYC idea in the whole VPN field. Its terms do not hedge: it "will not be implementing any kind of KYC" or age/ID verification, and you buy an access token anonymously with no account, no email and no username. Only a SHA-512 hash of that token ever reaches the authentication server, node-level logging is disabled, and you can even order over .onion/.i2p and pay with Monero. By design there is structurally no way to single out or "shut off" one customer, and no identity to hand over. On the KYC and privacy axes it is close to the Mullvad/IVPN class, and it has done this for over a decade.

The whole story is on the trust axis. The operators are pseudonymous; there is no independent audit, so the no-logs claim rests on community-inspectable client configs rather than a third-party attestation (which is also why it cannot earn our Verified badge). The jurisdiction is deliberately opaque and, where it can be pinned, 5-Eyes-adjacent — a Delaware LLC and historically a Canadian entity — behind Icelandic .is branding that does not reflect the actual domicile. And it carries a long-running reputational cloud tied to its founder history and an unresolved "honeypot" narrative. We handle that carefully: it is attributed allegation, not fact — no deanonymization, log-handover, court order or seizure has ever been corroborated, its warrant canary is current, and the concern lowers our trust score without firing any cap or being asserted in our voice. The result is an elite token model with the lowest trust in our VPN cohort: genuinely no-KYC, community-inspectable, but run by people you cannot identify. That nets to 7.9.


The score, broken down

How the 7.9 is built.

Privacy 4.7Trust 1.8Reliability 1.5 Headroom 2.1

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

93/100

93 × 50% = 4.7 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

60/100

60 × 30% = 1.8 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

74/100

74 × 20% = 1.5 of 10

Weighted total 7.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +10Token-only access — no account, no email, buy anonymously
  • +5Terms unconditionally refuse KYC and Age/ID verification
  • +5Only a SHA-512 token hash reaches the auth server; node logging disabled; .onion/.i2p ordering
  • +4Accepts Monero (PayPal/CCBill attach identity — anonymity is user-dependent on how you pay)
  • +-3Payment record retains an email; website logs (visitor IP) kept 2 weeks

Trust

  • +5Open client configs + tooling; 10+ year operating history; PGP-signed warrant canary
  • +-4No independent audit — the no-logs claim rests on community-inspectable configs, not third-party attestation
  • +-4Pseudonymous ownership + an unresolved, attributed founder-history/reputation cloud
  • +-3Opaque, 5-Eyes-adjacent jurisdiction (Delaware US / historically Canada) behind Icelandic .is branding

The fine print, read for you

The clause they bury.

Verbatim — the honest version
“Regarding KYC, we do not and will not implement any type of KYC policy. ... people can order an access token anonymously without providing any personal information. ... there's structurally no way we can "shut off" an individual customer.”

What it meansThis is the opposite of a trapdoor: an unconditional, written refusal of KYC and age/ID checks, plus a token-authentication design that structurally cannot single out a user. There is no identity to demand because none is collected. That earns the top no-KYC posture; the caveats live entirely on the trust axis, not here.

Read the source →
Verbatim — the catch
“No matter what payment method you choose, the data we retain is always the same: email, token delivered, and a transaction ID provided by the payment processor.”

What it meansThe anonymity is real but user-conditional. Buy the token with Monero (and an anonymous email) and there is nothing to link you; pay with PayPal or a card and your real identity is attached at the payment layer, and an email is retained regardless. The token model protects you only as far as your payment choice does.

Read the source →
KYC trigger threshold

None. The terms explicitly and unconditionally refuse KYC and age/ID verification, and access is a purchased, hashed token with no account or email — a genuine level-0 posture. The only residual identifiers are a pseudonymous token hash and session count (a credential, not an identity, exactly like Mullvad's account number) and, at the payment layer, a retained email unless you pay with Monero.

Policy review — point by point

  • Unconditional KYC refusal + token model

    The terms state it will never implement KYC or age/ID verification and that tokens are ordered anonymously, with a design that structurally cannot shut off an individual customer.

  • Hashed-token auth + node no-logging

    Only a SHA-512 token hash reaches the auth server, and node logging is disabled; website logs (visitor IP) are kept 2 weeks.

  • No independent audit; client configs only

    Open client configs and tooling are public, but there is no public server/auth stack and no third-party audit — the no-logs claim is inspectable, not attested.

  • Opaque, 5-Eyes-adjacent jurisdiction

    A Delaware LLC and historically a Canadian entity, with "no central HQ"; the Icelandic .is domain is branding, not the operating domicile.

Jurisdiction analysis

Cryptostorm deliberately obscures its jurisdiction: it lists a Delaware (US) LLC on its site, has historical ties to a Canadian entity (Baneki), and claims "no central HQ," all behind an Icelandic .is domain that is branding rather than a real domicile. Both identifiable entities sit in Five-Eyes countries. As with the rest of this service, the defence is architectural rather than jurisdictional — a token model that holds no identity means a lawful order has little to compel — but the opacity, and the fact that there is no accountable, named legal entity a user could pursue, is a genuine trust cost.


We keep watching

Incident & policy timeline.

  1. ~2013

    Emerged from the earlier Cryptocloud service

    Cryptostorm traces to roughly 2013, described by reviewers as a continuation of the earlier Cryptocloud/Baneki Privacy Computing lineage, built around anonymous token access. It has operated for over a decade.

    source ↗
  2. Historical

    Founder-history controversy (attributed, unproven)

    Reviewers and a 2019 privacytools.io removal proposal cite the service's association with Douglas Spink (a convicted figure), which seeded a persistent "honeypot" narrative. Cryptostorm has denied any current affiliation, stating the team disassociated him. We report this strictly as attributed allegation — there is no evidence, court record, or incident corroborating deanonymization, and it fires no cap.

    source ↗
  3. Jul 2026

    Warrant canary current and clean

    The PGP-signed warrant canary (updated 2026-07-01) states no National Security Letters, FISA orders or gag orders received. A canary that goes stale or is pulled would be a same-day downgrade signal; as of review it is current.

    source ↗

The verdict

Where it stands.

Strengths

  • Token-only access — no account, no email; buy anonymously
  • Unconditional written refusal of KYC and age/ID verification
  • Monero accepted; .onion/.i2p ordering; node logging disabled
  • 10+ year operating history with a maintained PGP-signed warrant canary

Trade-offs

  • No independent audit — no-logs rests on open configs + trust, not attestation
  • Pseudonymous operators + an unresolved, attributed reputation cloud
  • Opaque, 5-Eyes-adjacent jurisdiction behind Icelandic branding
  • Payment-layer email retention; anonymity depends on paying with Monero
Visit Cryptostorm No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Broad praise for the anonymous token model and Monero payment
  • Over a decade of operation with a maintained warrant canary
  • Community-inspectable client configs; strong strict-no-log posture

Recurring complaints

  • Pseudonymous operators; no independent audit
  • Unresolved, attributed founder-history/"honeypot" reputation cloud
  • Opaque, 5-Eyes-adjacent jurisdiction; user-unfriendly

Community sentiment praises the no-KYC token model consistently and clusters its criticism on trust/transparency and usability — not on any funds or logging betrayal. The "honeypot" allegation recurs but has never been substantiated; it is a persistent reputational cloud, not a corroborated event, and we present every reputational claim attributed (ProPrivacy, privacytools.io #1098, Wikipedia) and none asserted. KYCnot.me rates it level 0 / 9-of-10 / "Verified" (their repeated-check label, not an independent audit — which is why we hold at Reviewed).


Keep exploring

Related lists & categories.


Ask the bureau

Cryptostorm, common questions.

Is Cryptostorm no-KYC?

Yes — level 0. Its terms unconditionally state it will never implement KYC or age/ID verification, and you buy an access token anonymously with no account or email; only a hashed token ever reaches its servers. Pay with Monero to keep the payment layer anonymous too.

Is Cryptostorm an "FBI honeypot"?

There is no evidence that it is. That narrative traces to its founder history (an association with a convicted individual, which the company says it severed) and has circulated for years, but no deanonymization, log-handover, court order or seizure has ever been corroborated. We report the reputation concern as an attributed, unproven allegation — it lowers our trust score but is not stated as fact and fires no reliability cap.

Why is the score only 7.9 if the no-KYC model is so strong?

Because privacy is only half the picture. The token model earns a top-tier privacy score, but trust is the lowest in our VPN cohort: the operators are pseudonymous, there is no independent audit to back the no-logs claim, the jurisdiction is opaque and 5-Eyes-adjacent, and the founder-history cloud is unresolved. Elite privacy, thin trust.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.