Can a compromised VPN server trace your real IP? With a typical single-hop VPN, yes. With ProtonVPN Secure Core enabled, no. That is the fundamental difference, and it is why many business users pay for it.

Several incidents over recent years showed VPN exit servers seized or attacked, exposing user entry IPs. Secure Core, launched in 2017, targets exactly that weakness most providers preferred to ignore.

1. The single point in ordinary VPNs

Normal traffic flows "user → exit server → website". The exit server sees both your real IP and your destination, holding the full association. If it is compromised or forced to log, your path is exposed.

Single-hop VPN connection path diagram

The problem is not encryption strength but a single point in the architecture. Encryption protects content, not the metadata of who is connecting.

2. Secure Core's double hop

Secure Core rewrites the path to "user → Secure Core server → exit server → website". The first hop runs on self-operated servers in privacy-friendly countries like Switzerland and Iceland. The exit server never sees your real IP, only the Secure Core server's address.

ProtonVPN Secure Core double-hop protection diagram

Even if the exit node is fully controlled, attackers can only trace back to the Secure Core server, leaving a barrier they cannot cross. These servers run on ProtonVPN's own hardware with tightly restricted physical access.

The tradeoff is added latency from the extra hop. That is why Secure Core is optional: ordinary users get single-hop speed, while high-sensitivity users opt into the extra layer.

3. Real-world attack tests

In a simulated attack report by a security lab in 2024, testers tried to trace a connector from a controlled exit node. Single-hop VPNs revealed the real IP within ten minutes with complete logs; Secure Core connections stopped at the relay server, unable to proceed.

ItemSingle-hop VPNSecure Core
Exit node sees real IPYesNo
Endpoint attack resistanceWeakStrong
Average latencyLowerSlightly higher
Target usersGeneralHigh-sensitivity

The lab noted Secure Core "effectively severs the link between the exit node and user identity", matching ProtonVPN's published whitepaper.

Back to the opening question: can a compromised server trace your IP? With Secure Core, it cannot. It removes the single point rather than merely strengthening encryption. If your privacy concerns are above average, open ProtonVPN, enable Secure Core, and decide whether the extra milliseconds are worth it.