Back to Blog

Have I Been Proxied: How to Check if Your IP is Being Used as a Proxy

On September 15, 2026, Spur Intelligence launched haveibeenproxied.com — a free check to see if your home IP is being used as an exit node of a residential proxy network. Let's discuss what the service shows and what it cannot do, why the verdict from mobile internet is almost meaningless due to CGNAT, how the home address ends up in the pool (34.1% of smart TV apps, botnets, extensions), and what to do with the label.

📅September 16, 2026
Have I Been Proxied: How to Check if Your IP is Being Used as a Proxy

On September 15, 2026, Spur Intelligence launched a free service on Hacker News called haveibeenproxied.com — "Have I Been Pwned," but instead of passwords, it checks your home IP address. One query answers a question that hardly anyone cared about a year ago: is your internet connection being used as an exit node for someone else's residential proxy network? The post garnered 61 points and a hundred comments within a day — and the discussion turned out to be more useful than the tool itself.

What the service actually shows

The check takes one click: the site takes your public IP and compares it with Spur's telemetry — a company that sells data about residential proxies, VPNs, and anonymizing infrastructure to anti-fraud teams. The result is broken down into three signals:

  • Residential proxies — whether Spur has seen this address as an exit node of a residential proxy network;
  • VPNs, proxies & hosting — whether the address belongs to a data center, VPN service, or hosting;
  • Tor — whether the address is a known Tor exit node.

Checking from a data center address, for example, yields "No residential proxy detected" for the first point and "Observed — network infrastructure: a datacenter" for the second: the service accurately identifies hosting and does not confuse it with a home connection.

It is important to emphasize what the tool does not do. It does not install anything or scan your devices — this is clearly stated on the page. All it knows is the reputation of the address based on external observations. It will not tell you which device in your apartment is distributing traffic; it will only indicate that traffic is being distributed by someone.

You cannot check someone else's address through the site — it only works with the IP from which the request was made. In the discussion on HN, a representative from Spur suggested a workaround for those who need to check arbitrary addresses: a page in the format spur.us/context/<ip>. Several people asked about a full API and the disclosure of methodology in the thread — there has not yet been a clear answer regarding a paid plan.

The main trap: a shared IP gives a foreign verdict

The most valuable part of the discussion — not the praises, but a complaint that surfaced within the first few hours. Users who accessed the site via mobile internet received a concerning verdict and were alarmed — even though it had nothing to do with their phone.

The reason is that mobile operators and many home providers distribute addresses through CGNAT: one public IP is shared among dozens or hundreds of subscribers simultaneously. If even one of them has a proxy SDK running on their device, the address will be marked in the database — and thus, all others who are behind the same NAT at that moment. The service author acknowledged the problem directly in the thread and added a warning for mobile networks to the page the same day.

The practical takeaway is simple: the verdict "observed" from mobile internet or public Wi-Fi networks says almost nothing about you personally. It's meaningful to check only your home connection, preferably with a static "white" IP, and compare the results before and after disconnecting suspicious devices. By the way, the same logic explains why mobile traffic generally operates under different blocking rules — we discussed this in our article about CGNAT, mobile proxies, and request limits.

How a home address ends up in the proxy pool

There are three main channels, all documented in 2026.

SDKs within regular applications

In the summer, Spur scanned 6,038 smart TV applications on LG webOS and Samsung Tizen platforms. Proxy code was found in 2,058 of them — that's 34.1% of all checked applications: 42.5% on webOS and 26.9% on Tizen. This means that every third application on the TV was ready to pass foreign requests through your apartment.

The names in the report are not anonymous. Bright Data, Bright Data Ltd, and Bright SDK accounted for 367 applications; another 16 were published by Honeygain UAB — a subsidiary of Oxylabs; SDKs from Massive and Oxylabs themselves were also encountered. Among the examples are the game Galactic Harmony and a version of Pac-Man on Tizen, which are quite ordinary content, not dubious utilities. Formally, users are shown a notification and asked to "support the free app," but only a minority read it.

On July 21, 2026, LG announced that it would suspend applications that turn the TV into a constantly operating proxy node and is working with developers to remove this option from webOS. A detailed analysis of this story can be found in the article about the ban on proxy SDKs in LG Smart TV applications.

Botnets and infected devices

On July 2, 2026, the FBI, along with Google and Lumen, conducted a seizure of the infrastructure of the NetNut network (also known as Popa), which operated on at least 2 million devices — primarily smart TVs and streaming boxes. According to the Google Threat Intelligence Group, only in one week of June, 316 separate clusters of malicious actors were recorded on the NetNut infrastructure. Six months earlier, in January 2026, the IPIDEA network was disrupted, where more than 550 separate groups hiding their activity behind foreign home addresses were found during seven days of observation.

The lesson from these operations is sobering: seizing domains hits operators but not the source. After the January incident, the IPIDEA pool recovered by summer and exceeded its pre-destruction size — the devices remained infected.

Browser extensions and cheap boxes

A research note from the Cloud Security Alliance dated August 15, 2026, describes a third channel: 737 Chrome extensions with proxy functionality and more than 75,000 installations, as well as a batch of H96 TV boxes — around 38,000 devices involved in advertising fraud with an estimated turnover of about $50,000 per day. A cheap box with a pre-installed "bonus" is a classic way to get into the pool without installing anything yourself.

What the label on your address practically means

Nothing criminal from a legal standpoint — but it significantly worsens everyday internet use:

  • endless CAPTCHAs and checks on sites under anti-bot protection;
  • denials when logging into banks, exchanges, or government services — anti-fraud sees the address flagged in automation;
  • blocks when paying by card and suspicion of "atypical login" in emails and messengers;
  • restrictions on marketplaces and in games.

A separate issue is inertia. Reputation labels last a long time: an address can remain on the lists for months after the problematic device has been turned off. This same circumstance gave rise to a sound counterargument in the thread: if residential pools number in the hundreds of millions of addresses — Bright Data alone claims over 400 million residential IPs — then marking such a portion of the internet devalues the label itself. The debate is not settled, but for now, websites continue to use this data.

What to do if the verdict is "observed"

  1. Make sure the address is yours. Check from your home connection, not from mobile internet or public Wi-Fi. On CGNAT, the result applies to all subscribers behind that address simultaneously.
  2. Start with your TV and box. This is the main source according to 2026 statistics. Remove applications that you did not consciously install, especially free games and "accelerators." Check the settings for any consent to "traffic exchange."
  3. Check your router. Change the admin password, disable UPnP and remote management, update the firmware. An infected router is a proxy node that operates around the clock.
  4. Review browser extensions on all home machines: remove everything you do not use, especially free VPNs and video downloaders.
  5. Look at the traffic volume. If your provider or router shows statistics, abnormal outgoing traffic at night is a direct sign.
  6. Recheck after a day of cleaning and cross-reference with a second source — for example, a similar checker like Synthient. One verdict is one opinion, not a fact.
  7. Request a new IP from your provider if the label does not go away: for a dynamic address, sometimes a long disconnection of the router is enough.

The flip side: what this means for proxy buyers

The story has a second layer, not obvious to the home user but critical for those who buy proxies. Spur is not a charitable organization: the free checker is built on the same telemetry that the company sells to anti-fraud teams of websites. In other words, the tool shows you exactly what the opposing side already knows about your address.

From this, two practical conclusions arise.

First: the origin of the pool has become a measurable risk, not an abstraction. A pool gathered through SDKs in TVs and infected boxes consists of addresses that end up in such databases simply by existing, and after each takedown, a part of the geography suddenly "crumbles" for the provider. A pool gathered with the explicit consent of device owners behaves more predictably. This question should be asked to the provider before payment, not after the first wave of bans; we discussed the economics of this choice in our residential proxies.

Second: do not confuse "address reputation" with "proxy quality." The Spur label indicates the observed behavior of the address, not whether it will pass on your specific target site. Public reputation checkers, in this sense, often mislead more than they help — why exactly, we explored in detail in the article about the myth of the "clean IP" and reputation checkers.

In short

haveibeenproxied.com is a useful tool with a narrow and honestly stated task: it checks the reputation of the address, not the security of your devices. From a home connection, its verdict is informative; from mobile, it is almost meaningless due to shared addresses. If there is a label, the investigation begins with the TV, box, and router, not with reinstalling Windows. And for those who work with proxies professionally, the launch of such a service is yet another reminder that the origin of the pool has long ceased to be a question of ethics and has become a question of functionality.