The 'privacy browser' was caught secretly adding its own referral codes to crypto exchange URLs. When you typed binance.com, Brave redirected you through their affiliate link to earn commission. The CEO called it a 'mistake' — but someone wrote that code on purpose. Brave blocks everyone else's ads — then offers to show you Brave's own ads instead, paying you in crypto tokens while Brave takes 30%. They replaced Google's ad surveillance with their own advertising system.
What they claim: Brave blocks ads and trackers by default with Brave Shields
What we found: Brave also runs its own advertising network (Brave Ads) with a built-in crypto token (BAT). The privacy browser has a built-in ad system. Users can opt in to see Brave's ads and earn BAT tokens. Brave takes a 30% cut. The browser that blocks everyone else's ads serves its own — replacing the surveillance with Brave's surveillance.
What they claim: Brave includes Tor integration for anonymous browsing
What we found: In 2021, Brave's Tor mode was caught leaking DNS requests — the one thing Tor mode is supposed to prevent. DNS queries went to the user's regular DNS resolver instead of through Tor, exposing which .onion sites the user was visiting. The feature that promised anonymity was actively revealing your activity.
What they claim: Brave is headquartered in San Francisco, California
What we found: Brave Software Inc. is a US company subject to the CLOUD Act, FISA Section 702, and National Security Letters. The BAT token raised $35M in an ICO in 2017, creating potential SEC securities classification risk. Brave's VC-funded business model (Founders Fund, Peter Thiel) creates growth pressure that could push toward more aggressive monetisation.
What they claim: Brave claims to be 'de-Googled' — removing Google's tracking from Chromium
What we found: Brave still contacts 12 endpoints including p3a.brave.com (telemetry), variations.brave.com (feature flags), ads-serve.brave.com, and go-updater.brave.com. While less than Chrome, the browser still phones home. Brave also inherits Chromium vulnerabilities — CVE-2025-2783 (sandbox escape used in Operation ForumTroll espionage campaign) affected Brave users.
What they claim: Brave markets itself as 'the privacy browser' that 'blocks ads and trackers'
What we found: In June 2020, Brave was caught injecting affiliate referral codes into cryptocurrency URLs — adding Brave's referral link to Binance, Coinbase, Ledger, and Trezor URLs. Users typing a crypto exchange URL got silently redirected through Brave's affiliate link, earning Brave commission. CEO Brendan Eich apologised and called it 'a mistake' but the code was intentional.
What they claim: Brave promotes itself as the privacy-first browser that blocks trackers
What we found: In 2020, researchers discovered Brave was adding affiliate referral codes to cryptocurrency URLs — inserting Brave's affiliate link when users typed Binance, Coinbase, or Ledger URLs. Brave was redirecting users' crypto exchange URLs to earn referral revenue without disclosure. The privacy browser was silently rewriting URLs for profit. Brave CEO Brendan Eich apologised and called it a mistake.