



















Authorities from 27 countries reportedly seized infrastructure linked to “First VPN Service” during Operation Saffron.
According to reports, 33 servers were taken offline and the service was allegedly used by cybercriminal groups.
This case will likely spark more discussion around VPN trust, infrastructure transparency, and the difference between privacy-focused services and so-called “bulletproof” providers.
A researcher discovered that Mullvad’s WireGuard exit IP assignment could create identifiable patterns across different servers.
Mullvad’s co-founder responded publicly, confirming that some behavior was intended, some wasn’t, and that patches are already being tested on part of their infrastructure.
The issue does NOT mean Mullvad logs user activity, but it raises concerns about cross-server correlation and fingerprinting tradeoffs.
Read more: https://www.digitalescapetools.com/2026/05/mullvad-wireguard-exit-ip-correlation.html