Hola VPN
A peer-to-peer "VPN" that routes free users' traffic through one another's devices rather than dedicated encrypted servers.
hola.org/ ↗⚠ Documented concerns
We don't give Hola VPN an overall score. A proven logging breach, or an ownership history in adware or surveillance, is not something a good feature list should be able to average away. The data below is still shown in full so you can judge it yourself.
- Free users are still sold as network resources
Hola's own FAQ states that it works by sharing the contributed resources of its users for business use by Bright Data, that free users provide a certain amount of network and processing power, and that only Premium subscribers do not contribute device resources. The same FAQ says its browser extensions are not part of the peer-to-peer network, so this applies to the free apps rather than every product. The 2015 model continues; it is now disclosed rather than hidden.
Source ↗ - 2015: Free users' bandwidth resold via Luminati
Hola sold access to its free users' idle connections as residential exit nodes through its sister company Luminati. This is admitted rather than alleged: the founder confirmed the model publicly in May 2015.
Source ↗ - 2015: User nodes used in an attack on 8chan
8chan's founder reported an attack sending thousands of requests in 30 seconds from clean residential IPs. Hola's founder confirmed that an attacker had used Luminati against 8chan, and said the customer had slipped through the company's screening.
Source ↗ - 2015: Researchers demonstrated remote code execution
The adios-hola.org researchers published a working in-browser exploit against Hola users and reported that it could run attacker-supplied code with high privileges on some systems, an issue they said had been present since at least 2013. They also found persistent identifiers readable by any website.
Source ↗ - 2018: Chrome extension hijacked to phish a crypto wallet
Hola's Chrome extension was compromised and served code that redirected MyEtherWallet users towards a phishing site for around five hours. MyEtherWallet itself was not breached and advised affected users to move their funds. This was an attack on Hola rather than conduct by Hola.
Source ↗
What counts in their favour
- Disclosure has improved substantially: the FAQ, website and install flow now state the peer-to-peer arrangement and name Bright Data explicitly.
- Paying Premium subscribers are exempt and do not contribute device resources.
- After the 2015 disclosures the company announced an internal review, an external security audit, a bug bounty and a security lead hire, and said the reported console issues were fixed.
- Luminati was sold in 2017 and renamed Bright Data, so the reseller is no longer a Hola subsidiary.
- Hola states that average peer traffic is very small per day and that peers cannot access the contributing device.
Listing a concern is a statement about the documented record, not a claim about how the service behaves today. Where a provider has since changed owner, jurisdiction or policy, that is noted above and in the report below.
- Jurisdiction
- Israel
- Founded
- 2007
- Owner
- Hola VPN Ltd. (Hola Networks Limited)
- Best price
- $2.99/mo
- Devices
- 10
- Free tier
- Yes
Best for
- · Casually unblocking a geo-restricted website or stream on a throwaway basis
- · Users who specifically want a free, browser-based proxy and accept the trade-offs
Not ideal for
- · Anyone needing genuine privacy, anonymity, or protection from surveillance
- · Journalists, activists, or anyone whose threat model includes their IP being used by strangers
- · Torrenting/P2P safety, sensitive transactions, or corporate/work devices on a network
Strengths
- ✓Free tier exists with a large number of geo-unblocking exit locations
- ✓Inexpensive long-term Premium plans (as low as ~$2.99/mo on 3 years)
- ✓Effective at unblocking region-locked streaming/websites for casual use
- ✓Backed by an established company (founded ~2007) that is still actively maintained
Weaknesses
- ✗Free users' devices are turned into peers/exit nodes and their IPs are resold via the Bright Data network, exposing them to others' traffic
- ✗Company's own privacy policy admits logging IP, browsing history, timestamps and installed apps (retained up to 12 months), with no free-vs-premium distinction
- ✗No OpenVPN or WireGuard, no independent audit, no open-source clients, kill switch on Windows only
- ✗Repeated serious security incidents (2015 botnet/Luminati scandal, 2018 Chrome extension compromise targeting MyEtherWallet, 2021 Google malware removal, June 2026 Windows Hola Browser cryptominer supply-chain attack)
Protocols & encryption
The tunnelling protocols this service offers and the cryptography behind them.
IKEv2 / IPsec
TrustedA fast, stable protocol that reconnects quickly when you change networks, so it is popular on mobile. Built natively into most operating systems.
- Data cipher
- AES-256-GCM
- Key exchange
- Diffie-Hellman (ECP)
- Integrity
- SHA-256 / SHA-384
- Stated data cipher
- AES-256
- Stated handshake
- IKEv2
- Perfect forward secrecy
- Yes
- Post-quantum resistant
- No
- RAM-only servers
- Unknown
- Kill switch
- Yes
- First-party DNS (leak protection)
- Unknown
- IPv6
- Unknown
Full data sheet
Every attribute we track, coloured by whether it helps or hurts your privacy.
| Based in | Israel |
| Eyes alliance | Outside 5/9/14 Eyes |
| Enemy of the Internet | No |
| Owner | Hola VPN Ltd. (Hola Networks Limited) |
| Conglomerate | Independent (Hola Networks, founded by Ofer Vilenski and Derry Shribman, who retain their stake). NOT owned by EMK Capital. EMK Capital acquired the proxy arm Luminati (rebranded Bright Data in March 2021), which was spun out of Hola and sold SEPARATELY in 2017 (~$125M for ~75.6%); Bright Data is now a separate company, formerly a sister/sibling of Hola. |
| Founded | 2007 |
| Traffic / activity | Logged |
| DNS requests | Some |
| Timestamps | Logged |
| Bandwidth | Unknown |
| Source IP address | Logged |
Hola's own privacy policy (hola.org/legal/privacy) states it collects Log Data including IP address, OS, browser type, browsing history (obtained via the browser extension), access times and dates, and the names of applications installed on the user's device, with Log Data retained up to 12 months. The policy does NOT distinguish logging between free and Premium/Ultra users. Free users' devices become peers/exit nodes on the Bright Data (formerly Luminati) residential-proxy network and their IPs are commercially resold. Among the most data-collecting and least private services marketed as a VPN. DNS and bandwidth logging are not explicitly itemized in the policy (downgraded to 'some'/'unknown').
| Anonymous signup | No |
| Accepts cash | No |
| Accepts crypto | Unknown |
| PGP key | No |
| OpenVPN | No |
| WireGuard | No |
| Proprietary protocol | IKEv2/IPsec (AES-256); also legacy PPTP/L2TP. No OpenVPN or WireGuard. |
| Multi-hop | No |
| Obfuscation | No |
| Kill switch | Yes |
| First-party DNS | Unknown |
| RAM-only servers | Unknown |
| Port forwarding | Unknown |
| P2P / torrenting | Yes |
| IPv6 | Unknown |
| Data cipher | AES-256 |
| Handshake | IKEv2 |
| Open-source clients | No |
| Independent audits | None |
| Transparency report | No |
| Court / seizure-tested | Unknown |
No independent no-logs audit exists, and the company's own policy documents extensive logging. In 2015 free users were exposed as having been sold as Luminati exit nodes (including traffic used to DDoS 8chan). No documented case of a seizure/subpoena yielding no usable data.
| Simultaneous devices | 10 |
| Countries | 41 |
| Servers | 1500 |
| Linux support | Unknown |
| Month-to-month | $14.99 |
| Best $/mo | $2.99 |
| On plan | 3 years (Premium) |
| Free trial | None |
| Refund window | 14 days |
| Free tier | Yes |
| Logging policy | Contradictory |
| Marketing honesty | Overclaims |
Hola is technically a peer-to-peer routing network rather than a conventional encrypted-tunnel VPN. CORRECTION to common claims: EMK Capital does NOT own Hola VPN. EMK acquired the commercial proxy arm Luminati (which monetizes free users' bandwidth) SEPARATELY from Hola in 2017 (~$125M / ~75.6% stake; valuation ~$165M, potentially up to ~$200M headline); Luminati rebranded to Bright Data in March 2021 and is a separate company. Hola's founders (Vilenski/Shribman) retained their Hola stake. Founding year: company-profile databases (Tracxn/Crunchbase) cite 2007; Wikipedia describes the P2P launch as late 2012 (concept from 2008), kept as 2007. Refund window: Hola's official money-back guarantee is widely reported in 2026 as 14 days and conditional on the Premium plan being entirely unused (cloudwards.net, vpnmentor.com); one source (security.org) cites 30 days, corrected to 14. Pricing varies by promotion; figures may differ from on-site checkout. 'Ultra' tier runs ~$29.99/mo month-to-month down to ~$7.99/mo on 3 years. Server/country counts vary widely by source (security.org ~1,000-1,500 servers; cloudwards confirms 41 countries; vpnmentor cites 700+ servers / 195+ claimed countries).
Sources
- Hola official Privacy Policy (hola.org/legal/privacy) ↗
- Hola official site ↗
- Wikipedia: Hola (VPN), history, botnet, Luminati/Bright Data, EMK Capital ↗
- Wikipedia: Bright Data, Luminati spun out of Hola, sold separately to EMK Capital 2017, rebrand 2021 ↗
- Cloudwards, Hola VPN Review 2026 (pricing, 14-day conditional refund, 41 countries, logging, no audit) ↗
- Security.org, Hola VPN Review & Pricing 2026 (Premium/Ultra pricing, servers, kill switch) ↗
- vpnMentor, Hola VPN Review 2026 (operational status, 14-day refund, no free/premium logging distinction, no audit) ↗
- BleepingComputer, Hola Browser for Windows compromised to deliver cryptominer (June 4, 2026) ↗
- Newsweek, Trend Micro security warning on Hola/Luminati ↗
- BleepingComputer, Hola Chrome extension breach targeting MyEtherWallet (2018) ↗
- Mergr, EMK Capital Acquires Bright Data (deal details) ↗
- CSO Online, Hola users vulnerable to hacking ↗
Last verified 2026-06-17. Point-in-time data, so always confirm on the provider's own site.