CDN1 Review: Decent Performance, but Trust Issues You Can't Ignore
How good is CDN1 (cdn1.com)? chahu.com takes an objective look at CDN1's CDN service across performance, security and trust, ties to illicit operations, and ideal use cases—plus alternative recommendations
Bottom line up front: CDN1 performs adequately in simulated performance tests, but security intelligence reveals serious trust issues—it has been flagged as a suspicious website by multiple security organizations and is alleged to have infrastructure ties to the FUNNULL group, which the U.S. government has designated as a major enabler of cybercrime. For legitimate commercial operations,chahu.com recommends: proceed with caution, and do not rush to integrate before fully understanding the risks.
1. What Is CDN1?
CDN1 (cdn1.com / cdn1.ai) positions itself as an overseas CDN provider, specializing in acceleration without ICP filing. Its operating entity is CDN1.com Limited, established in July 2020 and registered in the Hong Kong Special Administrative Region, formerly known as "神豬網路有限公司." According to public information, CDN1's ASN is AS154206, with IP ranges located in Hong Kong. Its official website claims coverage of 200+ nodes and speed improvements of over 95%.
However, it is worth noting that its technical architecture is based on the open-source project GoEdge, not proprietary development. Security researchers point out that "using it directly in a legitimate commercial environment is inherently inadequate." As an open-source CDN management system, GoEdge has a certain community base, but lacks the operational depth and security hardening required for enterprise-grade CDN. From this perspective, CDN1 is more of a "open-source wrapper + bandwidth resale" lightweight CDN solution rather than a professional CDN vendor with independent core technology.
2. Performance: Simulated Data for Reference Only
The available CDN1 performance data comes from a third-party comparative review (data source: "official published parameters + simulated testing," tested on a standardized static website with approximately 5MB of resources):
Metric | CDN1 | Cloudflare | Gcore |
|---|---|---|---|
Beijing TTFB (ms) | 95 | 54 | 100 |
Guangzhou TTFB (ms) | 100 | 60 | 100 |
Hong Kong TTFB (ms) | 30 | 22 | 30 |
First Contentful Paint (s) | 1.6 | 1.4 | 2.2 |
Cache Hit Rate (%) | 72 | 80 | 65 |
Success Rate at 200 Concurrent Connections (%) | 98.8 | 99.7 | 97.0 |
Based on this data, CDN1's performance is below average. The Hong Kong node TTFB is acceptable (30ms), but TTFB in major mainland cities is noticeably higher than Cloudflare. The 72% cache hit rate is also on the low side, meaning more requests will hit the origin, potentially increasing origin server load.
However, it must be emphasized: this is simulated test data with limited testing conditions and cannot represent real-world network performance. In actual use, CDN performance is affected by multiple factors including node distribution, line quality, caching strategy, and origin response speed, and results can vary significantly. CDN1's claimed "200+ nodes"—their specific distribution and bandwidth capacity—cannot be verified from public information.
3. Security and Trust: This Is the Biggest Problem
Performance is only one aspect. What truly warrants caution with CDN1 is its security track record.
3.1 Ties to the FUNNULL Cybercrime Group
Analysis reports published by multiple security research organizations indicate that CDN1.AI is very likely not an independent third-party CDN, but rather a "new front" established by the notorious FUNNULL group (also known in Chinese as "方能科技," designated by the U.S. government as a major enabler of cybercrime) to evade tracking.
The evidence chain includes:
Highly synchronized infrastructure migration timing: Domains historically used by FUNNULL to host malicious JavaScript scripts collectively migrated from funnull cdn to cdn1.ai within a similar time window;
Inferior technical architecture yet rapidly trusted: CDN1.AI's technical architecture is based on open-source GoEdge, and its operations are unprofessional—even the official website's SSL certificate was not renewed in time after expiration;
Anomalous migration pattern: CDN1.AI was only created in June 2025, yet was fully adopted by a mature cybercrime organization like FUNNULL within an extremely short period. Security researchers note that for FUNNULL, which rakes in substantial profits, "infrastructure choices must be made with extreme caution, with relatively high stability requirements." The fact that CDN1 could win their trust so quickly suggests both likely belong to the same group.
3.2 Low Trust Scores
Third-party security assessment organizations also give unfavorable ratings:
Scamadviser's assessment of CDN1-related domains concludes "very low trust" and "likely a scam," noting that its owner uses paid services to hide WHOIS identity, multiple low-rated websites exist on the same server, and DNSFilter reported the website as malicious within the past 30 days;
Gridinsoft gives the related domain a trust score of 1/100, classifying it as a "suspicious website" and recommending against its use.
3.3 Indirect Connection to Supply Chain Poisoning Incident
In the maccms.la supply chain poisoning incident involving the FUNNULL group, attackers exploited the official upgrade channel of a video CMS to distribute malicious PHP backdoors and JavaScript scripts, affecting millions of users. While there is currently no direct evidence that CDN1 participated in the poisoning attack itself, the fact that its infrastructure was used to host and distribute these malicious scripts is sufficient cause for serious concern.
4. Who Is CDN1 Suitable For?
Overall, CDN1's applicable scenarios are very limited:
May be considered in rare cases:
Personal testing environments or non-critical operations requiring only basic no-ICP-filing acceleration;
Small projects with no requirements for data security, compliance, or SLA;
Temporary use where the risk of service interruption at any time is acceptable.
Clearly unsuitable scenarios:
Any legitimate commercial operation: E-commerce, corporate websites, SaaS platforms, and any scenario involving user data and transaction security should not use a CDN with such serious trust issues;
Businesses involving user privacy: Using a CDN means a third party can access your cached content and user request data. Handing traffic to a provider flagged as suspicious by multiple security organizations leaves user data security unprotected;
Projects with high compliance requirements: Industries such as finance, government, and healthcare with strict compliance requirements must choose legitimate CDN providers with clear legal entities and security audits;
Businesses requiring stability: CDN1's operational professionalism has been questioned by security researchers (even an expired SSL certificate was not addressed), casting doubt on the credibility of its 99.9% availability commitment.
5. Alternative Recommendations
If you are looking for a no-ICP-filing CDN solution, here are more reliable options:
For global audiences: Cloudflare's free tier is easy to set up, has broad global node coverage, and industry-leading DDoS protection;
For domestic acceleration without ICP filing: Consider professional CDN providers with Hong Kong or Japan nodes, but ensure the vendor has a clear corporate entity and SLA commitments;
Gaming and streaming scenarios: Vertical providers like StoneCDN offer specialized optimization for dedicated line acceleration;
Small projects with limited budgets: Some domestic providers offer lightweight CDN with traffic-based billing, transparent pricing, and guaranteed compliance.
Whichever you choose, chahu.com recommends: run a POC test first. Run real business traffic for 7–14 days, focusing on evening peak latency, packet loss rate, cache hit rate, and origin pull pressure, before deciding whether to use it long-term.
Final Verdict
CDN1 is a CDN provider with adequate performance and potentially attractive pricing. But its core problem is not performance—it is trust.
A CDN provider handles all traffic to your website—user requests, cached content, access logs. When you hand your traffic to a CDN, you are effectively trusting that it will not steal data, tamper with content, or have ties to malicious organizations. Based on currently available public security intelligence, CDN1 fails this trust test.
Performance can be a little slower, prices can be a little higher, but data security and business compliance leave no room for compromise. If your project deserves to be taken seriously, CDN1 should not be on your shortlist.



