Kairos · working analysis · 9 September 2026 · updated 11 September

If you built it today, from zero,
would it still be a VPN?

The companion page stripped a residential VPN to the parts that obey physics and found that most of what it charges for is habit. This one goes a layer up and asks the question that page assumed away: whether the product on top of those atoms should be a VPN at all. Three questions, in the order they were asked. What box should a node runner buy. What survives a deletion pass. And whether the thing worth building is a tunnel.

Short answers. The box does not matter, and here is the number that ends the argument: the average node sells well under one percent of what its own line could carry. At Mysterium's own payout rates that is 0.38% — more than 260× as much capacity already installed as is being sold. Nothing about hardware moves that.

The product: no. Of the five jobs a VPN app claims, two have been absorbed by the browser, one has moved to a better tool, one is a different business. One stands.

The 1000x is not a faster tunnel. It is deleting the company from the trust path, the account from the purchase, and the connect button from the product.

Part one

One app, five unrelated jobs, bundled in 2010.

A consumer VPN is not a product. It is five products that shipped together because in 2010 they happened to share an implementation. Question each requirement separately and the bundle falls apart. This is the deletion pass: for each job, is it still a job, and is a tunnel still the right shape for it?

The job
Verdict
Why
Keep the coffee-shop network from reading my traffic
absorbed
The founding sales pitch, and the web did it itself. Near-universal TLS, plus encrypted DNS and encrypted client hello closing the hostname leak, leave a residue that is real but is not worth a monthly subscription to most people. Note the precise boundary: the browser absorbed the encryption, not the address. Google retired its Privacy Sandbox IP Protection work in October 2025, so Chrome will not be masking anyone's address. The platform took the easy half and handed back the hard half.
Hide my address from the site I am visiting
reshaped
Still a real job, but a one-hop tunnel does not do it. It moves the watcher from the ISP to a stranger who now sees both who you are and where you are going. Only splitting those two facts across independently operated hops changes the shape of the trust, and the companion page prices that at about ten percent of latency when the hops sit on the path.
Be somewhere else on purpose
stands
This is what people actually buy and the only job on the list that is growing. It is a location product wearing a privacy product's clothes, which is why the marketing and the usage never match. It is also the job the industry measurably fails at: of 2,269 proxy servers advertised across 222 countries, a third were found not to be in the advertised country at all, and another third could not be confirmed either way.
Reach my own machines from away
left the category
Mesh tooling took this and did it better. It is also, awkwardly, a documented substitute for the location job: routing through your own home device gives home-country access while travelling, free, with no third party in the path at all.
Get through a state that is blocking me
different business
An adversarial engineering problem against a funded opponent, with different protocols, a different release cadence and different legal exposure. Selling it inside a consumer subscription is the reason consumer clients carry obfuscation features that mostly do not work when they are needed.

One job stands unambiguously, and it is the one the industry is least honest about. The measured cancellation survey is consistent with that reading: across 10,275 responses in 2026 the top named reasons are price at 24%, then usability at 12% and disconnects at 12%, with a further 11% on a specific error code. Nobody cancels because their coffee shop turned out to be safe.

And the case for deletion is stronger than "these jobs are separate." A product that bundles them cannot be good at the one that stands, because the bundle forces a global tunnel, and a global tunnel is exactly the wrong shape for being somewhere else on purpose.

Part two

Three inversions. Each one deletes something the industry sells.

These are ordered by how much has to be given up to get them, which turns out to be the same as the order of their size. The first needs no new protocol. The second needs the warm pool the companion page already argued for. The third needs the company to give up something it currently thinks is an asset.

10×

Stop hiding the customer. Start protecting their coherence.

deletes: the arms race

An address is one signal out of roughly seven. The others are the shape of the TCP stack, the TLS handshake fingerprint, the HTTP/2 settings fingerprint, timing coherence, resolver behaviour, and consistency across all of them. A residential address wearing a datacentre TLS fingerprint is more anomalous than a clean datacentre address, because that combination does not occur in nature.

So look at what the current product does to a customer. It takes a real person, on a real operating system, running a real browser, from a real place. That person is already perfectly coherent. The product then damages the coherence, charges a subscription for the damage, and lets the customer pay a second time in challenges and blocks. This is the only industry that sells you a disguise and then bills you for being recognised.

The inversion: the network's job is to be transparent to identity, not to obscure it. You do not manufacture authenticity, which is what a scraping proxy has to do and why it is so hard. You only avoid destroying authenticity in transit. That is a far easier engineering problem and nobody ships it.

It also happens to be the version of the residential story that the first screening data leaves standing. The direct claim — that a household address unlocks destinations a datacentre address cannot reach — was screened on 10 September across twelve destinations and three exit classes: Mysterium residential, Mysterium datacentre and a competitor's datacentre. Nine destinations ignored exit class entirely. The two that refused every datacentre exit refused the residential exit identically, and Stack Overflow, behind Cloudflare, challenged residential exactly as it challenged datacentre. One destination refused Mysterium's datacentre ranges while admitting both the residential exit and the competitor's datacentre. The run was curl with a browser user-agent, two repeats a cell, unguarded, and a red team rejected the causal readings drawn from it, keeping only the recorded contrasts. Coherence is a different claim, and a curl run cannot test it, because curl only borrows a browser's user-agent.

Cheapest falsifier

Run the current client past a fingerprint-inspection endpoint. If the exit address and the stack above it already tell the same story, this is closed. If they contradict, the size of the contradiction is the size of the opportunity. Half a day.

100×

Delete the tunnel. Route per destination, not per device.

deletes: connect, servers, countries, the kill switch

Why does one tunnel carry everything on a device? Because operating systems put VPNs at the network layer in the nineteen-nineties and nobody revisited it. That is the whole reason. It is not a security property, it is not a performance property, and it is the direct cause of most of what customers cancel over.

Be precise about who has already broken this, because it is not nobody. Enterprise and prosumer tooling has per-destination exits today: Tailscale shipped app connectors in December 2023, Zscaler anchors source addresses per application, GL.iNet routers do per-domain policy routing, and one consumer router product holds five locations at once. Apple's relay was never a single tunnel either — it carries Safari, DNS and insecure HTTP only. What does not exist, on the evidence available, is a consumer VPN that does it: the consumer versions are all include-and-exclude toggles hung off one global tunnel. So this is a mile that has been run in the next lane and never on this track.

Route per destination instead. The bank sees the home line. The streaming service sees a node beside its own edge. Work sees the office. Ordinary browsing takes a shared pool. There is no mode, so there is nothing to switch, and nothing to forget to switch back.

Look at what disappears. The connect button, because with three to five permanently handshaken tunnels a connection becomes a routing-table write, about a tenth of a millisecond against a shipped two to eight seconds. The server list and the country picker, because a country is a legal category and routing is a geometric one; the client already knows its own destination and can rank candidates locally. The kill switch, because a kill switch exists to contain the failure of a global capture, and there is no global capture. The measured failure it exists to prevent is real: when a provider died mid-session the ISP address was exposed at three seconds and still exposed at forty-five, and a session showed Connected while carrying no traffic for seventy-eight seconds. Per-destination routing does not fix that bug. It removes the state in which the bug can exist.

It is also the only structure in which the genuine trade can be resolved rather than hidden. Acceleration wants to terminate and re-originate a connection; fingerprint fidelity wants to forward it untouched. Those are mutually exclusive on one connection, so any product claiming both globally is not being examined. Per destination they coexist: accelerate the video segments, the downloads and the updates, and forward the login and the checkout untouched.

Cheapest falsifier

Packet-capture the current client connecting and count the round trips, marking each avoidable or not. If fewer than four are avoidable, the warm pool buys nothing and the rest of this does not follow.

1000×

Delete the company from the trust path, and the account from the purchase.

deletes: the audit, the subscription, the email address

Here is the convention nobody in the category will touch: you must trust the operator. Every annual no-logs audit is a ritual that concedes the point. An audit is only necessary because the architecture makes logging possible; it certifies a promise rather than removing the capability. When researchers interviewed nine providers, seven said they deliberately avoid learning about their users. Read that carefully. It is not a technical guarantee, it is a confession that knowing is available and they are managing the temptation with policy.

Three deletions, in increasing order of how much they hurt.

Delete the single hop. Two independently operated hops so that no one machine holds both who you are and where you are going. This is the only change that alters the shape of the trust rather than its address. Priced on the companion page at about ten percent of latency when the hops sit on the path, against the premium the industry charges for it.

The honest limit on that. Every shipped "we cannot log you" design is two-party non-collusion, not impossibility. Apple's relay chooses and pays both hops. Oblivious HTTP fails if the relay and the gateway confer. The one consumer product built on hardware attestation instead has had its hardware root broken three separate ways in a year, including by a roughly fifty-dollar memory interposer, and all three were declared outside the chip vendors' threat model. Nobody has shipped cryptographically enforced non-logging, and no third-party audit of any VPN attestation claim exists. Two hops is a real and large improvement. It is not a proof.

Mysterium already owns hop one, and does not use it as one

This is not a greenfield proposal there. A controlled measurement in August found that the WireGuard endpoint for a Vilnius residential exit was a Hetzner box in Nuremberg, confirmed three ways after it was challenged, with a household router behind consumer NAT at hop four. The relay exists for a good engineering reason — a NATted household cannot accept an inbound connection — and it makes the residential claim stronger, not weaker, because it demonstrates a real home line at the far end.

But it means customer traffic already transits Mysterium-controlled German infrastructure, at a structural cost of about fifty milliseconds. So the architecture already has the first hop of a two-hop design. It is simply operated by the same party as the second, which makes it a single point that can see both who the customer is and where they are going — Atom 3, paid for and not spent. Handing that hop to an independently operated party would cost close to nothing in latency, because the detour is already being paid, and would convert the largest privacy liability in the current design into the strongest claim available in the category.

Delete the identity from the payment. Blinded tokens let the network prove you paid without knowing which customer you are, and this is shipped infrastructure rather than a research idea: Privacy Pass became three RFCs in June 2024 and runs in production at Apple and Cloudflare. A privacy product that begins by taking your email and your card is selling you something it has already spent.

Delete the subscription. This is the DHH move, and it is already claimed ground: one provider did it, for exactly this reason. Mullvad removed recurring subscriptions in June 2022, reasoning in public that a twelve-month subscription forces them to keep the link to you for twelve months. The same company sells access against a random account number and accepts cash sent by post. So the deletion is proven shippable by someone with revenue; what is unclaimed is assembling it with the other two. It fits the product: the measured average subscriber life is about three months against roughly thirty percent monthly gross churn, and current revenue growth is price-led rather than volume-led, up nineteen percent in purchases against seventy-three percent in average ticket. A business raising prices into thirty percent churn is harvesting, not compounding. A one-time purchase for a device that does this at the edge of a household is a different business with a different balance sheet, and it is closer to what the asset actually is.

One correction to make before anyone presents this: pay-per-use already exists in the product line. Proposing usage pricing as new would be wrong. The proposal here is the removal of the account and the recurring relationship, not the introduction of metering.

Part three

The thing people will need, and the buyer who is already paying.

The last question was whether there is something people already need, will need far more, and do not yet know they need. There is. It is not a better tunnel, and the surprise is that the buyer is not a person.

A consumer pays about $2.49 a month for a VPN, renewing at $6.58, and is being repriced toward zero.

An AI lab pays $1.75 to $8 per gigabyte for the same underlying thing: traffic that arrives from an ordinary household. The two buyers are separated by four orders of magnitude per unit, and they are standing next to each other.

The numbers on the second buyer are not speculative. Bright Data runs about $300M of annual recurring revenue growing fifty percent, and reports serving fourteen of the top twenty language-model labs and over a hundred million agent interactions a day. Oxylabs took $130M from Warburg Pincus in July 2026 at a $3.6 billion valuation with more than 350,000 customers. And a network with a structure much closer to Mysterium's went from roughly nothing to $12.8M in a single quarter selling to AI customers, a $33M annual run rate built in four quarters.

That last one matters most, because it is the existence proof. A distributed network of consumer-supplied connections can capture AI demand at scale, and one has, recently, quickly. Whatever is stopping Mysterium is not the category.

What those numbers are admissible for, and what they are not

Every figure in the two paragraphs above comes from companies that sell residential proxy access, or from reporting on them. That makes them good evidence that a large and fast-growing market exists, which is what I am using them for. It makes them inadmissible as evidence that residential access works — a vendor's revenue measures what buyers were willing to pay, not whether the thing they bought outperformed the alternative.

The distinction matters more here than it normally would, because the whole public evidence base on this question was largely written by parties who profit from one answer. A search for whether destinations block datacentre addresses returns page after page of proxy vendors and VPN affiliates asserting that they do. By the same rule, Mysterium's own marketing claims about residential value cannot be evidence for residential value. Only first-party documentation from the enforcing destination, or a measurement we run ourselves, escapes that circle — which is exactly why the calibrated, browser-grade test described in Part five is the load-bearing item on this page.

Worth naming locally: this market's centre of gravity is Vilnius. Oxylabs and Decodo are Lithuanian, and the group that holds Oxylabs also holds Nord and Surfshark with several thousand staff. The competition for Mysterium's actual asset is one city away, capitalised, and growing.

The fork resolves, and it resolves by brand

I expected this to be genuinely open: either sites keep guessing from the address, or they start asking for a signature and residential demand collapses. The evidence says both happen, and the split is not technical. It is reputational.

Named agents

Get a signature

Cloudflare shipped signed agents in August 2025 and a verified-agent category now covers the large majority of identified AI browser traffic. If your agent belongs to a company with a name worth protecting, it identifies itself and is let through.

Everyone else

Buy a household

From 15 September 2026 Cloudflare's defaults for newly onboarded domains block training and agent bots on pages that display ads, while search crawlers stay allowed. Bots are already 57.5% of page traffic against 42.5% human. Everything without a signature has to look like a person, and the only way to look like a person is to be one.

So the answer is not that one branch wins. It is that the wall going up is what creates the demand for the other side of it, and that is exactly why Bright Data grows fifty percent in the same year the signing standard ships. The honest caution attached: Cloudflare's own machine learning classifies more than seventeen million unique addresses an hour in residential-proxy detection across forty-five thousand networks. They are actively hunting this. Anyone selling into it is selling into a contested position, not a safe one.

And the thing nobody is selling

Both sides of that wall assume the software is either concealed or declared a robot. Neither is what a person wants. What a person wants is for their agent to be treated as them. Neither hidden nor labelled a bot: delegated. This is my agent, acting for me, from my connection, and here is something you can check.

That is the exact inverse of a VPN. A VPN's job is concealment. This job is proof. It needs a real network position belonging to a real person, that person's informed and revocable consent, and a credential a destination can verify without learning more than it should. The first two are precisely what a consented residential network is. The third does not exist as a product anywhere.

The demand shape also matches the question's own test exactly. Nobody asks for it today, because today their agent simply fails or gets challenged and they blame the agent. It becomes obvious the first time it works: the flight books, the bank lets it through, the repeat prescription goes in, and the person cannot go back to software being treated as an intruder in their own life.

The candidate with the second-strongest evidence is the one already on the table

Independent of anything on this page, the ranked demand evidence puts provenance and consent for the address itself second only to raw agent demand. The reasoning is that enforcement has consistently gone after how addresses were obtained rather than the fact of selling them — two courts held that selling proxies is lawful, while the seizures all attacked sourcing, from ten million devices sold as proxies in one case to roughly two million in another. One study found proxy software in 42.5% of LG smart-TV apps and 26.9% of Samsung's, consented once and running after the app closes. Buyers that include most of the major labs need paperwork proving their traffic is not that.

Which converges with where the companion page landed from pure physics: the durable advantage is on the consent axis, not the speed axis. Two unrelated methods, the same answer. That is the most reliable signal in either document.

Status of delegated presence, stated plainly so it is not oversold: it is the least evidenced idea on this page. No measured demand, no identified buyer, no tested price, and it depends on destinations agreeing to honour a delegation, which is a standards and business-development problem much harder than the engineering. It is a hypothesis with a cheap test attached, and the test is not to build it. It is to ask ten people who already run agents what actually breaks, and find out whether the answer is network position at all.

One dated risk that cuts against everything in this section. On 15 July 2026 the UK declined to ban VPNs and instead asked Ofcom to report, by October 2026, on how services can detect and prevent VPN use. That is a regulator formally commissioning better proxy detection. It lands inside the planning horizon of any decision taken now.

Part four

What Mysterium actually holds, and the fact that most threatens it.

The companion page ended on the line worth repeating: if there is a durable advantage in a residential node network it is on the consent axis, not the speed axis. Speed is engineering and engineering is copyable. That conclusion survives everything on this page, and it now has a sharper edge, because the alternative story has been tested once and did not hold.

The asset is real at asset level: roughly 6,374 residential nodes online across more than a hundred countries, about 92% of node payouts and 90% of paying connects on residential routes, and around 79% of recorded traffic counters residential. A competitor cannot assemble that in a quarter.

Three cautions travel with those numbers and all three are already documented. The residential label is copied from a location oracle by literal string match, and sixty-eight proposals labelled residential name a company that sells hosting. The discovery endpoint applies a per-country cap with unordered iteration, so an observed US inclusion rate of 6.3% means any "N residential nodes in country X" figure taken from it is a count of returned rows, not of nodes. And node counts do not reconcile across sources at all, ranging from about twenty-two thousand active to 30,212 on-chain identities to a claimed thirty-two thousand.

The fact that most threatens the thesis is not any of those. It is the first screening data on the central mechanism of the current strategy. On 10 September, twelve destinations were tried through three exit classes. On the only two that refused every datacentre exit, including a competitor's, the Mysterium residential exit was refused identically. The one destination that admitted residential while refusing Mysterium's datacentre ranges admitted the competitor's datacentre too, so it separates Mysterium's own ranges rather than residential from datacentre. The residential exit also failed to connect on four of twelve requests, where the datacentre lines did not. The run was curl, two repeats a cell and unguarded, and a red team rejected every causal reading drawn from it, keeping only these recorded contrasts. That is thin. It is also the only data there is, and on the two cells the premise most needed, residential did not help. The next measurement the red team specified is a real browser against curl on the one separating destination, with the interpretation fixed before it runs.

Widen the frame and the picture gets thinner still. The best public measurement of datacentre-versus-residential blocking anywhere is from 2016, and it measured Tor rather than proxies, finding 3.67% of the top thousand sites blocking it. Nothing comparable from 2023 onward could be found. So the blocking-and-challenge tax the whole category prices against has no current public number, and Kairos's own screening used curl rather than a browser. A calibrated, browser-grade measurement is the cheapest test on either page and the one with the largest decision riding on it.

And the null is less strange than it first looks, because the industry has no modern measurement of this either. The best public head-to-head on datacentre-versus-residential blocking is still a 2016 study, and it measured Tor rather than proxies, finding that 3.67% of the top thousand sites blocked it. No comparable measurement from 2023 onward could be found at all. So the entire industry argument about a blocking-and-challenge tax that residential addresses avoid — the argument the whole category's pricing rests on — is running on a decade-old number about a different network. Sixteen destinations finding nothing is not an anomaly against a well-measured background. There is no well-measured background.

Which is why the framing in Part three matters commercially rather than philosophically. The claim "a household address gets you in where a datacentre address cannot" is not supported by the first screening data where it mattered most. The claim "we do not destroy the coherence of a real person in transit" is a different claim, a curl run cannot test it, and it is closer to what the network is actually able to do.

Three routes have landed on the same conclusion. The physics teardown reached it from copyability: speed advantages are engineering, engineering is copyable, consent supply is not. The demand evidence reached it from enforcement: every action of 2025–26 attacked how addresses were obtained while two courts held that selling proxies is lawful. And a scan for protocol limits nobody has broken reached it by absence — nobody has built a consented, paid, legal residential exit pool, and the category's reference point is a network sanctioned in May 2024 running on roughly nineteen million compromised home devices.

Read that as three routes, one prior — not as three independent confirmations. All three ran the same night, on one person's brief, over an overlapping corpus, and I wrote the questions. Convergence under a shared prior is exactly what the mirror problem looks like from the inside: it will feel like outside confirmation and it is not. The routes really are methodologically different, which is worth something. It is not worth what "independent" would claim.

The corollary is uncomfortable and worth saying plainly to Mysterium. If the asset is consent, then the enrolment paths are the asset, and the audit already on record found that the mandatory-disclosure flag is verified only for the command-line, Docker and binary installs. The paths a non-technical node runner actually uses — the Raspberry Pi image, the desktop and mobile apps, the web onboarding — are unverified. That is not a documentation gap. On this reading it is the only part of the balance sheet that matters, and nobody has checked it.

The uncomfortable one

Every improvement on this page and its companion is downstream of a product that currently fails in measured ways: a provider dying mid-session left the real address exposed at three seconds and still at forty-five, a session reported Connected while carrying nothing for seventy-eight seconds, and the network itself terminated all five test sessions, none lasting past four minutes thirteen. Meanwhile the tag vpn slow carries 91.3% churn and 70.7% refunds, gross monthly churn runs near thirty percent against an average subscriber life of about three months, and revenue growth is price-led: purchases up nineteen percent, average ticket up seventy-three. Customer acquisition cost, payback and cohort retention appear zero times in sixty-one decks across seven years. None of the inversions above are worth starting before the thing works and somebody is counting.

Part five

What is computed, what is sourced, and where I am weakest.

Same discipline as the companion page, because the failure mode of a document like this is that it feels like insight while being unmeasured.

Claim classBasisStatus
Break-even wattage, payback periods, the value-capture percentage, break-even trafficArithmetic over measured payouts, identity counts, published prices and Eurostat electricity ratesRe-runnable. node-economics.py sits beside this page and exposes every assumption.
The monthly payout totalEvery decoded settlement event on the live contract, UTC month bounds, at each month's average token priceMeasured, and internally corroborated: the fee share lands at 21% against a documented 20% service fee. Known undercount risk if off-chain bulk payments exist.
The identity count and the payout rate, and therefore the $1.79 average and the utilisation figureChain-derived earner count, against Mysterium's own payout price sheetBoth are soft. "Node" has three incompatible definitions in the corpus (10,453 online / 30,212 earned in August / 27,944 from the countries endpoint), and the sheet rate disagrees with the blended rate implied by traffic volume by 2.6×. Quote the finding, not the decimal.
Cross-check: $18.01 per participating address on Mysterium's node siteA second, unrelated surfaceAgrees to a rounding error if the site's total covers about ten months. Neither figure states its period, so this is corroboration, not proof.
Hardware prices, wattages, WireGuard throughput, storage endurance, vendor longevity commitmentsVendor documentation, published benchmarks, Eurostat, EIASourced and checkable. Wattages marked ~ are class typicals, not measurements of the specific unit.
Mysterium's payout rates, node counts, churn, cancellation reasons, runtime failures, the null residential testThe existing Kairos corpusMeasured there, not re-measured here. Every one carries its own caveat in the source, and the node-count figures openly disagree across sources.
Protocol-frontier claims: who has broken which convention, the anonymity bound, encryption and post-quantum costs, the measurement critiquesStandards documents, vendor engineering posts, and peer-reviewed measurement workSourced. The research flagged its own gaps: no measured comparison of the newer tunnel transport against WireGuard exists, no independent mixnet measurement, and no measurement paper on any decentralised VPN including Mysterium.
"Four of the five jobs are absorbed or moved"My characterisation of the marketArgument, not measurement. Defensible on the direction of travel; the exact allocation is a judgement and someone could reasonably split it differently.
Competitor revenue, valuations, proxy pricing bands, bandwidth-sharing payout rates, Cloudflare's default-block date, the Ofcom commissionCompany announcements, investor releases, vendor pricing indices, Cloudflare's own posts, regulator coverageSourced. Two cautions the research flagged itself: analyst market-size reports for this sector disagree by more than thirty-fold and were discarded as worthless, and some 2026 Cloudflare traffic percentages reach me through secondary write-ups rather than the primary dataset.
Competitor revenue and valuations as evidence for the residential thesisVendor announcements and reporting on themAdmissible only for market size, never for whether residential access works. The sources profit from one answer. Same rule disqualifies Mysterium's own marketing on the same question.
The three-route convergence on consentThree differently-framed research passesConvergent, not independent. Same night, one brief, overlapping corpus, and I wrote all three questions. Methodologically distinct enough to be worth something; not enough to be called corroboration. Flagged after review.
Delegated presence as the unnamed needInference from the documented fork plus a plausible demand shapeWeakest claim on the page. No measured demand, no identified buyer, no tested price, and it depends on destinations agreeing to honour a delegation. A hypothesis with a cheap test attached, nothing more.
Uplink medians, fibre penetration, IPv6 share, ISP acceptable-use languageOokla via Statista, thinkbroadband via ISPreview, FTTH Council Europe, Google and APNIC statistics, the providers' own published policiesSourced. The upload figures are medians and averages across very different populations, so they describe the shape of the problem rather than any particular household.
Carrier-grade NAT prevalenceThe best empirical measurement available is from 2016Ten years stale and quoted for want of anything newer. Deployment has almost certainly grown. Treat the 17–18% as a floor, not a current figure.
"A paid exit node breaches residential terms of service"Reading two providers' published policiesMy reading of contract language, not a legal opinion, and no enforcement against node operators was found. Latent risk, not demonstrated risk. Two providers is also not a survey.
If only one thing is taken from this page

The hardware question and the strategy question have the same answer, and it is a single number. The average node sells about a third of one percent of the capacity already sitting under it. Forty percent more nodes produced no more money, because the network was never short of nodes.

So the question worth putting to Mysterium is not what a node should cost. It is what a household is actually selling — bandwidth, which is abundant, running at four-tenths of one percent, and pays the household two percent of its downstream value; or consent, which is genuinely scarce, is the one thing a competitor cannot assemble in a quarter, and is currently priced at nothing.