You can now verify Mullvad VPN’s credentials

Mullvad VPN has recently made a significant stride in enhancing user trust with the announcement that its Android app builds are now reproducible. This development allows users to verify that the app they have downloaded is indeed constructed from the open-source code that Mullvad publishes. The focus begins with the 2025.2 version of the Android app, enabling users to confirm that their application remains untampered and secure from potential malicious interventions.

What are reproducible builds and why do they matter?

According to Mullvad’s blog, a build is deemed reproducible if, given the same source code, build environment, and build instructions, any party can recreate bit-for-bit identical copies of all specified artifacts. In simpler terms, the code of the Android VPN app you have installed should match the code published by Mullvad’s developers. This verification process serves as a robust assurance that the app is authentic and built from the exact source code it claims to be derived from.

Reproducible builds offer a strong guarantee regarding the integrity of the app being downloaded. If the build process yields identical results, it confirms that:

  • The published source code matches what is actually distributed to users
  • No unintended modifications occurred during the build process

“We believe transparency is crucial for security software,” stated Mullvad. “Investing in reproducible builds is a testament to our commitment to providing you with a trustworthy and secure application.” The company is encouraging technically inclined users to engage in the verification process, with source codes and detailed instructions available on Mullvad’s GitHub page.

(Image credit: Future)

A strong start to 2025 for Mullvad

The early months of 2025 have proven to be fruitful for Mullvad, marked by a series of updates and enhancements. In February, the company announced a partnership with the newly established Obscura VPN, where it serves as the second hop in Obscura VPN’s dual-provider model. Additionally, Mullvad expanded its offerings to include an app for Windows Arm devices, aligning itself with the best VPNs for Windows.

March brought further advancements, including two notable security updates. Mullvad’s Android app successfully passed a standardized security assessment and introduced version two of its Defence Against AI-guided Traffic Analysis software. Moreover, the launch of Multihop for Android allows users to route their internet traffic through two Mullvad servers, reinforcing their online protection and security.

Disclaimer

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2. Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.

AppWizard
You can now verify Mullvad VPN's credentials