Turbo VPN, one of the more widely downloaded free VPN apps on Windows, shipped an emergency patch on August 7, 2026, after TechRadar’s testing found its Windows app was leaking users’ real IPv6 addresses, even after an earlier attempt to fix the same problem.
What actually happened
TechRadar’s investigation found that Turbo VPN’s Windows client failed to block IPv6 traffic across all of its available connection methods, including its proprietary Lepus and LinkSentinel protocols as well as standard OpenVPN. In practice, that meant a user connected to Turbo VPN believing their traffic was fully protected could still have their real IPv6 address exposed to any site or service checking for it, defeating a core purpose of using a VPN in the first place.
Turbo VPN issued a first patch, version 3.6.0.0, after TechRadar shared its initial technical findings. That patch did not fully resolve the issue. TechRadar’s continued testing showed the leak persisting, prompting Turbo VPN to ship a second update, version 3.7.0.0, which the outlet confirmed successfully blocks unencrypted IPv6 traffic in follow-up testing. (TechRadar, August 7, 2026)
Why an IPv6 leak matters
Most VPN leak protection historically focused on IPv4 traffic, since it has been the dominant addressing standard for decades. IPv6 adoption has grown steadily, though, and a growing number of networks and devices now use it by default alongside or instead of IPv4. A VPN that only protects IPv4 traffic while leaving IPv6 unencrypted creates exactly the kind of gap this incident exposed: your VPN app shows you as connected and protected, while a separate channel quietly reveals your actual IP address and location to anyone checking for it. This defeats both anonymity and geo-unblocking, the two most common reasons people use a free VPN like Turbo VPN in the first place.
How this compares to other recent VPN security incidents
This is the second notable VPN security story in the space of a week. It follows reporting on SplitVPN, a Russian provider accused of breaching its own no-logs policy after a database containing an alleged 58 million connection logs surfaced on a cybercrime forum, a claim the company disputes. Together, the two incidents point to the same underlying lesson: free and lower-tier VPN apps vary enormously in how rigorously they test for leaks and how transparently they respond when problems are found. Turbo VPN’s willingness to ship two consecutive patches once the issue was documented is a better response than staying silent, but it does not erase the fact that the leak existed and shipped to users in the first place.
How to check if your own VPN is leaking IPv6
Regardless of which VPN you use, it takes under a minute to check for this specific issue. Connect to your VPN, then visit an IP leak test site that specifically checks IPv6 alongside IPv4, such as ipleak.net or browserleaks.com. If an IPv6 address appears alongside your VPN’s IP, or if your real IPv6 address shows up at all, your connection has the same category of leak that affected Turbo VPN. The fix, if you find one, is usually either disabling IPv6 entirely at the operating system level or switching to a VPN provider that explicitly documents full IPv6 leak protection.
Providers with a stronger IPv6 leak protection record
NordVPN and ProtonVPN both explicitly test for and document IPv6 leak protection as part of their client software, and neither has had a comparable leak reported in our research. NordVPN scores 5/5 on leak protection in our full comparison, with Proton VPN close behind. If you’re currently using a free VPN and this story gives you pause, both offer straightforward switching with an audited no-logs record on top of documented leak protection.
A pattern worth watching in 2026
This is not an isolated story this year. TechRadar’s own recent reporting has also flagged Android VPN apps with unclear ownership, fake VPN websites hosted on official app stores, and other free Windows VPN apps with their own leak issues. Taken together, these stories describe a broader pattern: the free VPN market is large, unevenly regulated, and includes some genuinely well-run services alongside others that cut corners on exactly the technical protections users assume they’re getting. None of this means every free VPN is unsafe, but it does mean checking a provider’s actual documented protections is worth the few minutes it takes, rather than assuming any app calling itself a VPN delivers on that promise equally.
What Turbo VPN users should do right now
If you use Turbo VPN on Windows, update to version 3.7.0.0 or later immediately through the app or Turbo VPN’s official site, since this is the version TechRadar confirmed resolves the leak. Then run your own IPv6 leak test as described above to confirm the fix applies to your specific setup before trusting the connection for anything sensitive.
Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.
Why this kept happening after the first patch
The persistence of the leak across a first patch is worth sitting with for a moment. Turbo VPN’s initial fix, version 3.6.0.0, addressed part of the problem but not all of it, since the leak reportedly continued across the app’s proprietary Lepus and LinkSentinel protocols as well as OpenVPN even after that update shipped. This points to a leak that was baked into how the app handled network interfaces at a lower level than a single protocol fix could address, which is a harder class of bug to catch through normal internal testing and a good example of why external, independent testing like TechRadar’s investigation genuinely catches things a provider’s own QA process can miss.
What this means if you switch VPNs after reading this
If this story is enough to make you reconsider your current VPN, take the opportunity to actually check its documented leak protection rather than assuming any paid alternative is automatically safer. Look specifically for IPv6 leak protection mentioned in the provider’s own technical documentation or in independent audit reports, not just marketing copy claiming “leak-proof” without specifics. NordVPN and ProtonVPN both publish this information clearly, which is part of why they consistently score highest on leak protection in our comparisons.
The bigger picture on free VPN apps
Free VPN apps are not automatically unsafe, but incidents like this one are a reminder that leak protection, audit history and response transparency vary enormously across the hundreds of VPN apps available on Windows and mobile app stores. A provider’s willingness to patch quickly once a real researcher flags a problem is a meaningfully positive sign, but it doesn’t substitute for choosing a provider that tests for these issues proactively in the first place, rather than after a journalist finds them and forces the issue into public view.
Turbo VPN's second patch appears to have fixed the specific IPv6 leak TechRadar identified, but the fact that it took two attempts and outside reporting to get there is a real mark against it. If IPv6 leak protection matters to you, NordVPN and Proton VPN both have a stronger, independently documented track record on this specific protection.
Keep reading: How to Check for a VPN IP Leak and VPN Browser Fingerprinting in 2026.