MyIPScan

Provider-neutral self-test pilot

TunnelBear Leak Test

TunnelBear is worth reading differently on two axes. Its kill switch is called VigilantBear, so if you are hunting for a setting after a failed check that is the name to look for. And it has published an independent security audit every year since 2016, carried out by Cure53 with full access to source code and configuration, which is a longer public record than most providers hold. The output describes this browser right now, not TunnelBear's service as a whole.

Read methodology

Live test

Run the test on TunnelBear now

TunnelBear's kill switch is called VigilantBear, and SplitBear can remove traffic from the tunnel on purpose. Read a surprising address against both.

Open the full VPN Leak Test

Current-session checks

What this TunnelBear self-test checks

Take a reading before connecting and another after. On TunnelBear the first thing to settle is whether VigilantBear was on when the reading was taken, because that decides what a surprising result means.

Before you read the result

What TunnelBear documents about these signals

TunnelBear's blog and product documentation are the source for the points below, including its unusually long public audit record.

VigilantBear is the kill switch

TunnelBear describes VigilantBear as the feature that stops your device sending unencrypted traffic if TunnelBear disconnects. It is the setting behind most unexpected readings here, and it is worth confirming its state before and after the test rather than assuming it was on.

The extension and the app cover different traffic

TunnelBear states that its Chrome and Firefox extension secures browser data only, while the Windows and macOS apps secure everything leaving the computer. If you are running the extension, a check on this page describes the browser and nothing else on the machine - which is the correct behaviour of that product, not a shortfall in the test.

SplitBear removes things from the tunnel on purpose

SplitBear lets you exclude specific applications and websites from the tunnel without disconnecting, and TunnelBear is explicit that excluded apps and sites are not encrypted or protected. An exclusion added for a service that blocks VPNs is a common and documented reason a later check reports your own address.

A public audit record going back to 2016

TunnelBear has commissioned an independent security audit every year since 2016, published on its own blog, with Cure53 performing white-box assessments that include source code, configuration and internal documentation. The 2024 report counted ten vulnerabilities of medium severity or higher and three low ones; a ninth annual audit followed in 2025.

What an audit does not tell you about this session

An audit is a statement about the provider's code and infrastructure at a point in time. It cannot tell you what your particular browser exposed a moment ago. That is the gap these checks fill, and it is why a clean audit history and a surprising local reading are not a contradiction.

Between the readings

Record a kill-switch drop on TunnelBear

VigilantBear is TunnelBear's name for its kill switch, so that is the setting to have open while you do this. The recorder reports whether your own address was reachable while the tunnel was down, and for how long.

What this cannot prove

  • This checks visible browser/session signals only.
  • This does not certify the provider.
  • This does not test every server, app, device, or connection.
  • This does not prove anonymity.
  • This does not prove every security condition.
  • A clean result does not prove every leak is absent.

How to compare before and after on TunnelBear

  1. Take a first reading on your normal connection: address, resolver, IPv6 and WebRTC.
  2. Turn VigilantBear on in TunnelBear's settings, then connect.
  3. Rerun the same checks in the same browser and the same profile.
  4. Read the two side by side. A difference you cannot explain is a question about the local setup rather than a verdict on the provider.
Safe Copy limits

Safe Copy exports use safe summary categories and remove raw IP, exact city, full user-agent, raw fingerprint data, raw resolver IPs and WebRTC candidates. It is not a certificate, provider audit, or proof of anonymity.

FAQ

TunnelBear leak test FAQ

What is VigilantBear?

VigilantBear is TunnelBear's name for its kill switch. TunnelBear describes it as preventing the device from sending unencrypted traffic if the VPN disconnects, so it is the setting to confirm after an unexpected reading.

Does the browser extension protect everything on my computer?

No. TunnelBear says the Chrome and Firefox extension secures browser data only, while the Windows and macOS apps secure everything leaving the computer. Which one you are running changes what these checks can see.

Could SplitBear be the reason a check failed?

It can. SplitBear excludes chosen apps and websites from the tunnel without disconnecting, and TunnelBear notes that excluded traffic is not encrypted or protected. Review the exclusion list before treating the reading as a fault.

How often is TunnelBear audited?

TunnelBear has published an independent security audit every year since 2016, carried out by Cure53 as a white-box assessment with access to source code, configuration and internal documentation. The reports are on TunnelBear's own blog.

Does a clean audit mean my checks will come back clean?

No. An audit describes the provider's code and infrastructure at a point in time. These checks describe what your browser exposed in this session, which depends on your device, your extensions and your settings.

Why does WebRTC still show something after connecting?

WebRTC candidates are produced by the browser. They should carry the tunnel address when the whole system is routed through the app, but an extension, a virtual adapter or a split-tunnel rule can change that.