← Browsers
D

Brave Browser

Serious concerns
Brave Software · 🇺🇸 United States
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: com.brave.browser
Manufacturer: Brave Software Inc.

The bottom line

The 'privacy browser' was caught secretly adding its own referral codes to crypto exchange URLs. When you typed binance.com, Brave redirected you through their affiliate link to earn commission. The CEO called it a 'mistake' — but someone wrote that code on purpose. Brave blocks everyone else's ads — then offers to show you Brave's own ads instead, paying you in crypto tokens while Brave takes 30%. They replaced Google's ad surveillance with their own advertising system.

Legal jurisdiction
🇺🇸 United States (headquarters)
CLOUD Act read more →
US govt can demand your data from this company even if stored overseas
FISA §702 / PRISM read more →
NSA collects stored emails, photos, messages without individual warrants
Geofence warrants read more →
Police can demand location data for everyone near a crime scene
Spying
2/4 MODERATE
Is someone spying on me?
Data Sharing
2/4 MODERATE
Who gets my data?
Security
2/4 MODERATE
Is it actually secure?
Honesty
3/4 HIGH
Can I trust what they say?
CONFIGURE High-risk areas that can be partially mitigated with settings changes.
6Contradictions
0Critical
3High
3Medium
2Sources
Findings by concern
Spying 2/4 MODERATE 2 findings
⚡ highfirmware analysis vs app permissions
Brave blocks everyone else's ads — then offers to show you Brave's own ads instead, paying you in crypto tokens while Brave takes 30%. They replaced Google's ad surveillance with their own advertising system.

What they claim: Brave blocks ads and trackers by default with Brave Shields

What we found: Brave also runs its own advertising network (Brave Ads) with a built-in crypto token (BAT). The privacy browser has a built-in ad system. Users can opt in to see Brave's ads and earn BAT tokens. Brave takes a 30% cut. The browser that blocks everyone else's ads serves its own — replacing the surveillance with Brave's surveillance.

⚫ mediumfirmware analysis vs firmware analysis
Brave's Tor mode leaked your DNS queries in 2021 — meaning your ISP could see which hidden sites you were trying to visit anonymously. The anonymity feature was doing the opposite of its job.

What they claim: Brave includes Tor integration for anonymous browsing

What we found: In 2021, Brave's Tor mode was caught leaking DNS requests — the one thing Tor mode is supposed to prevent. DNS queries went to the user's regular DNS resolver instead of through Tor, exposing which .onion sites the user was visiting. The feature that promised anonymity was actively revealing your activity.

Data Sharing 2/4 MODERATE 1 finding
⚫ mediumpolicy claims vs regulatory findings
Brave is a US company backed by VC money — same jurisdiction as Google, same laws apply. Their $35M crypto token ICO adds SEC regulatory risk. The 'alternative to Big Tech' is funded by Big Tech's investors.

What they claim: Brave is headquartered in San Francisco, California

What we found: Brave Software Inc. is a US company subject to the CLOUD Act, FISA Section 702, and National Security Letters. The BAT token raised $35M in an ICO in 2017, creating potential SEC securities classification risk. Brave's VC-funded business model (Founders Fund, Peter Thiel) creates growth pressure that could push toward more aggressive monetisation.

Security 2/4 MODERATE 1 finding
⚫ mediumpolicy claims vs firmware analysis
Brave claims to be de-Googled but still phones home to 12 endpoints including its own telemetry and ad servers. It also inherits Chrome's security vulnerabilities — including zero-days used by government spies.

What they claim: Brave claims to be 'de-Googled' — removing Google's tracking from Chromium

What we found: Brave still contacts 12 endpoints including p3a.brave.com (telemetry), variations.brave.com (feature flags), ads-serve.brave.com, and go-updater.brave.com. While less than Chrome, the browser still phones home. Brave also inherits Chromium vulnerabilities — CVE-2025-2783 (sandbox escape used in Operation ForumTroll espionage campaign) affected Brave users.

Honesty 3/4 HIGH 2 findings
⚡ highpolicy claims vs firmware analysis
The 'privacy browser' was caught secretly adding its own referral codes to crypto exchange URLs. When you typed binance.com, Brave redirected you through their affiliate link to earn commission. The CEO called it a 'mistake' — but someone wrote that code on purpose.

What they claim: Brave markets itself as 'the privacy browser' that 'blocks ads and trackers'

What we found: In June 2020, Brave was caught injecting affiliate referral codes into cryptocurrency URLs — adding Brave's referral link to Binance, Coinbase, Ledger, and Trezor URLs. Users typing a crypto exchange URL got silently redirected through Brave's affiliate link, earning Brave commission. CEO Brendan Eich apologised and called it 'a mistake' but the code was intentional.

⚡ highmarketing vs third party research
The privacy browser that blocks trackers was secretly adding its own affiliate codes to crypto exchange URLs. Type "binance.com" and Brave redirected you through Brave's affiliate link — earning revenue from your visit. A browser built on "we don't track you" was tracking your crypto exchange visits for referral money. The CEO called it a mistake. The code was intentional.

What they claim: Brave promotes itself as the privacy-first browser that blocks trackers

What we found: In 2020, researchers discovered Brave was adding affiliate referral codes to cryptocurrency URLs — inserting Brave's affiliate link when users typed Binance, Coinbase, or Ledger URLs. Brave was redirecting users' crypto exchange URLs to earn referral revenue without disclosure. The privacy browser was silently rewriting URLs for profit. Brave CEO Brendan Eich apologised and called it a mistake.

Sources