The Fish Tank That Sells Your IP: How Smart TVs Became the Residential Proxy Industry's Favourite Host

Wednesday 24 June 2026 topic: Smart TV apps as residential proxy exit nodes — the economics, the botnet pipeline, and why LG and Samsung haven't drawn a line

The fish tank that sells your IP

Spur’s scan of 6,038 smart TV apps across LG’s webOS and Samsung’s Tizen found 2,058 of them shipping residential proxy SDKs. On LG, that’s 42% of the entire app ecosystem. On Samsung, 26%. These are not malware infections — they are legitimate apps, many of them published by the proxy companies themselves, that turn your television into an exit node for other people’s internet traffic. A clock. A fish tank. A game of solitaire. On screen, it’s calm. Under the hood, your home IP address is relaying traffic for whoever paid the proxy provider — AI scrapers, credential stuffers, ad fraud rings, data harvesters. The app is the wrapper; your residential IP is the product.

The reason TVs are ideal hosts is structural. They are always plugged in, always online, sitting on the same home network as everything else, and — critically — nobody thinks of them as computers. There is no battery drain to notice, no cellular bill to spike, no app switcher full of suspicious background activity. As the Spur report puts it, “a TV can stay plugged in, signed in, and online for years while the user thinks of it as furniture.” The consent model exploits this gap. A one-time prompt navigated with a remote — often framed as the “ad-free option” — disappears into the setup flow, and the proxy keeps running long after the app is closed. Pac-Man on Tizen literally presents it as a fork: watch ads, or let Bright Data use your connection for “web indexing.”

Who’s behind the SDKs

Three proxy providers dominate the dataset. Bright Data (formerly Luminati, itself born from the Hola VPN scandal of 2015) accounts for 367 proxy-flagged apps — in many cases appearing as the publisher under names like “Bright Data Ltd” and “Bright SDK.” Honeygain, a subsidiary of Oxylabs, shows up as publisher on 16 more. Massive is the third. In several cases, these are not real apps that happened to bundle a monetisation SDK — they look like first-party proxy inventory: thin shovelware shipped at scale so the SDK has somewhere to run. Bright Data markets its network as 400 million+ residential IPs, with 150 million+ described as “consent-sourced.” That number is not abstract. It is built on apps like these.

The demand side is where the story connects to the AI boom. Anti-bot defences from Cloudflare, DataDome, and others now reliably block scrapers coming from datacenter IPs. So AI companies and data brokers route their harvesting through residential connections instead — connections that look like ordinary home traffic because they are ordinary home traffic, just routed through someone else’s fish tank. Krebs reported in October 2025 that proxies from botnets like Aisuru were fuelling large-scale AI data harvesting. Google dismantled the criminal IPIDEA proxy network in January 2026. The line between “consent-sourced proxy network” and “botnet” is where the industry’s defence lives, and it is thinner than the marketing suggests.

The botnet next door

That thin line became invisible earlier this month. On June 18, Krebs reported that the Popa botnet — which has forced millions of consumer Android TV boxes to relay traffic for ad fraud, account takeovers, and data scraping over four years — is linked to NetNut, a residential proxy provider operated by Alarum Technologies (NASDAQ: ALAR), a publicly-traded Israeli firm. The Popa SDK was originally written by Moishi Kramer, NetNut’s VP of R&D, who says he sold it to third parties years ago and has no control over how it’s deployed. Synthient’s analysis found Popa devices actively forwarding NetNut client traffic — “high confidence” that Popa remains part of NetNut’s proxy pool. Alarum rejected the botnet characterisation, insisting the SDKs facilitate “bandwidth-sharing functionality” with “appropriate notice and consent mechanisms.”

The security implications extend beyond IP borrowing. These SDKs run inside your home network. Bright Data’s sample ships with an explicit private-range blocklist (127.0.0.0/8, 10.0.0.0/8, 192.168.0.0/16, etc.) — which is reassuring until you realise it means the TV can make the connection, and the only thing preventing it from reaching your router admin panel, NAS, printer, or security cameras is the SDK’s policy code. The Massive and Honeygain samples Spur analysed did not contain a comparable private-range blocklist. In January 2026, Krebs reported on Kimwolf, a botnet that abused residential proxy networks to tunnel back into the LAN behind proxy endpoints — reaching devices that were never meant to be exposed to the internet. The boundary between “public web relay” and “local network foothold” is the proxy company’s traffic filter, and when that fails, the attacker is inside your home.

The Hacker News community reaction was sharp. One commenter wrote: “I cannot think of a legitimate purpose for residential proxies existing. They take advantage of people who don’t understand what they’re being asked to give ‘consent’ to, and then offer up those people’s internet connections to whatever actor wants to abuse it.” Another observed the primary use case plainly: “Botnets to bypass Cloudflare. Nobody is using residential proxies for DDoS because incoming bandwidth == outgoing bandwidth.” A third connected it to the scalper economy: “address jigging is the oldest trick in botting. Nowadays with fingerprint browser, generated credit card number and residential proxy, it is very hard to tell legit buyers from scalpers.”

The platform gap

The most telling finding is the platform divergence. Amazon’s Device and System Abuse Policy explicitly prohibits apps that facilitate proxy services for third parties. Roku reportedly shut the door after being contacted by Lowpass/The Verge. Google has taken legal action against proxy botnets. On those platforms, the SDKs are gone or were never permitted. LG and Samsung have drawn no equivalent public line. The same business model that Amazon bans and Roku blocks is still showing up at scale on webOS and Tizen — 42% and 26% of apps respectively. Bright Data dropped Google and Amazon platforms after restrictions, but still lists Samsung’s Tizen and LG’s webOS as supported. The platforms that haven’t acted are the ones still hosting the supply.

This is a regulatory and platform-governance failure, not a technical one. The traffic is trivial to detect and block — Spur and Include Security both published the specific domains the SDKs connect to (proxyjs.brdtnet.com, clientsdk.bright-sdk.com, etc.), and a Pi-hole or NextDNS configuration stops the relay without affecting the app’s other functionality. The fix is a policy line from LG and Samsung equivalent to Amazon’s, backed by app store review. Neither company has indicated they’re moving toward one. The residential proxy industry, meanwhile, is growing at an estimated 42% annually, with 2.8 billion monthly data-scraping requests routed through residential IPs. That growth is pulled by AI demand: every model trained on web data needs data that anti-bot systems are increasingly good at blocking, and residential proxies are the bypass.

The opinion

The consent defence is the industry’s load-bearing wall, and it’s made of tissue. A one-time prompt on a TV, navigated with a remote, framed as the alternative to ads, that authorises indefinite background traffic relay with no meaningful way to audit what flows through your connection — that is not consent in any functional sense. It is a legal artefact designed to survive scrutiny, not to inform the user. When the proxy provider is also the app publisher, the “partnership” framing collapses entirely: there is no independent developer making a monetisation choice; there is a proxy company shipping a thin app to house its SDK.

The deeper structural problem is that residential proxies create an externality the proxy market never prices. The device owner bears the risk — legal exposure for traffic they didn’t originate, bandwidth consumption, LAN attack surface — while the provider and the buyer capture the value. The industry’s response — independent audits, SOC 2 certifications, PwC reports — certifies the process of consent collection without addressing whether the substance of consent is possible when the user has no practical way to know what traffic their IP is carrying. Bright Data’s CEO says a device in its network “is a device whose owner said yes, understood what they were saying yes to, and can say no again at any moment.” That is a statement about a legal trigger, not about understanding. Nobody buying a smart TV for their living room understands that they are becoming a node in someone else’s scraping infrastructure. The industry knows this. It depends on it.

LG and Samsung need to draw the same line Amazon and Roku already drew. Until they do, nearly half of the apps on their platforms are not apps at all — they are real estate for someone else’s business, running on your electricity, through your network, under your IP address, with your name on the traffic.

Sources