← Back to Blog

LG Cleans Proxy SDK in Smart TVs: What Happens to Residential IPs

On July 21, 2026, LG announced that it would remove from webOS applications that turn the TV into a residential proxy network node. A Spur study found proxy SDKs in 2058 out of 6038 LG and Samsung applications — 42% and 25% respectively. For the first time, the gray supply channel of residential IPs is blocked not by the FBI, but by the platform owner. Let's analyze how the pool is shrinking and what to ask the provider now.

📅July 31, 2026
LG Cleans Proxy SDK in Smart TVs: What Happens to Residential IPs

On July 21, 2026, LG Electronics USA did something unexpected for television manufacturers: the company announced that it would be removing webOS applications that turn users' TVs into nodes of a residential proxy network. Formally, this is just an amendment to the app store rules. In reality, it marks the first instance where a "gray" channel supplying residential IPs is shut down not by the FBI or a court, but by the platform owner. For the residential proxy market, this means more than just another takedown.

What Exactly Was Found in the TVs

The trigger was a study by Spur Intelligence, published on June 22, 2026. Analyst Trevor Sutter did not trust the descriptions in the store or the developers' statements—he downloaded and unpacked the webOS and Tizen application packages and then searched for known artifacts of proxy SDKs.

The result: proxy SDKs were found in 2,058 applications out of 6,038 analyzed—about one-third of the entire sample. When broken down by platform, the picture is even more striking:

  • over 42% of the applications available for download on LG TVs (webOS) contain an SDK that turns the TV into a proxy node;
  • over 25% of applications for Samsung Tizen contain similar components.

They searched for specific fingerprints: files and services brd_api.js and brd_sdk from Bright Data, Massive clients and .massivesdk services, as well as files and service names from the Honeygain/Oxylabs SDK. The absolute leader in prevalence turned out to be Bright Data: the company is listed as the publisher of 367 applications and, according to Spur, provides most proxy SDKs on both platforms. Honeygain/Oxylabs has 16 applications.

The categories of applications are maximally innocuous: games, screensavers, file utilities. A notable example is Pac-Man on Tizen, where the integration of Bright Data is presented to the user as a monetization method—agree, and the application will gain the right to use your TV's connection "for web indexing."

Why This Is Not "User Consent"

The entire legal framework of the SDK channel relies on the formula "the user gave consent." Spur directly challenges this interpretation in the report: a one-time consent window buried in the TV application's interface does not replace real transparency, ongoing oversight, or platform supervision.

The issue is not only ethical. The TV sits within the home network—behind the router, alongside other devices. Spur describes the risk plainly: if the proxy provider allows requests to private or local addresses or if its filtering fails, the TV becomes a launchpad for accessing what should never be viewed online—router admin panels, NAS, printers, cameras. This is not a hypothesis: researchers refer to the Kimwolf botnet (January 2026) as a real example of exploiting residential proxy networks to access local network devices.

The mechanics of the SDK channel itself—how the application earns money, how much traffic is actually routed through the device, and why "occasionally" in the user agreement does not mean what you think it does—we discussed in detail in a separate article.

How to Check Your Own TV

Manufacturers do not provide a universal indicator of "my TV is functioning as a proxy node," but several practical steps are available to any owner:

  • Review the list of installed applications. Risk categories according to Spur include games, screensavers, and file utilities from lesser-known publishers. Anything you do not use should be removed: the SDK operates as long as the application is installed.
  • Read the consent screen upon first launch. Phrasing like "use the device's connection for web indexing" or "share internet bandwidth" is exactly that monetization. Refusal is usually possible, but the button may not be obvious.
  • Check traffic statistics on the router. A TV that consistently generates noticeable outgoing traffic while in standby mode is behaving abnormally: typical content consumption involves incoming streams.
  • Isolate the TV. A guest network or separate VLAN mitigates the primary risk described by Spur—the access from a compromised device to the router admin panel, NAS, cameras, and printers in the home network.

LG's Response—and Samsung's Silence

LG's Senior Vice President John Taylor told KrebsOnSecurity that a residential proxy network is not an intended use case for LG TVs, and the company is working with developers to remove the proxy option from webOS applications; those who do not comply will see their applications suspended.

Samsung, which has a slightly lower share of infected SDK applications, has not publicly announced any comparable measures. This is an important detail: as long as the cleanup relies on the goodwill of one vendor, it is reversible and incomplete. However, a precedent has been set—and it opens a path for platforms that was previously considered outside their responsibility.

The Third Wave of 2026: Who Is Really Tightening the Pool

To understand the scale, it is worth lining up the events of the year. Pressure on the "gray" segment of residential IPs has come in three different ways, each hitting its target:

  1. Law enforcement and courts. On July 2, 2026, the FBI, in collaboration with the Google Threat Intelligence Group and supported by Lumen Technologies, Shadowserver Foundation, and IRS Criminal Investigation, dismantled the NetNut network and the botnet behind it, Popa: over 2 million consumer devices, hundreds of seized domains, and disabled Google accounts used for management. During one week in June, at least 316 separate threat clusters operated through NetNut's exit nodes—password spraying, credential stuffing, ad fraud, and scraping sensitive data. An analysis of this case and the boundaries between a legal provider and a botnet can be found in our article on the closure of NetNut.
  2. The providers themselves. In April 2026, Bright Data ceased selling mobile proxies to new clients, and the update to the Acceptable Use Policy on April 1, 2026, removed the management of social media accounts, including TikTok and Instagram, from the list of supported scenarios. Major players are cutting the riskiest directions themselves, without waiting for regulators.
  3. Platform owners. LG's move adds a new layer. The app store can eliminate the SDK channel with a single decision, without a court, investigation, or international cooperation. And this works faster than any takedown.

The takeaway for the market is simple: the availability of cheap "gray" residential traffic is decreasing in 2026, while the cost of obtaining it is rising. The declared pools of hundreds of millions of addresses—Bright Data claims over 400 million IPs—have been built over years, including through SDKs in free applications. Each wave of cleanup impacts this part of the pool, rather than the legally rented addresses.

What This Changes for Residential Proxy Buyers

If you are purchasing residential proxies for scraping, multi-accounting, or ad verification, the origin of the IP has ceased to be an abstract ethical question. It directly affects three things.

Stability. A pool gathered through SDKs in applications lasts only until the next cleanup. When LG removes applications and the FBI seizes domains, thousands of exit nodes disappear at once—along with your sessions. "It worked today, but not tomorrow" is a typical symptom of a provider that does not control the source of addresses.

Quality and detection. An IP that was involved in credential stuffing just a week ago from one of the 316 threat clusters is already on IP intelligence lists. You will get banned not for your behavior, but for the address's history. How exactly anti-fraud systems detect residential addresses and their reputation has been discussed in our article on detecting residential proxies through IP intelligence.

Legal risk. Using infrastructure that is under investigation not only results in a blocked account but also poses potential questions for you as a client.

What to Ask Your Provider

  • Where do the addresses come from? A clear answer should include partner networks, leased ranges, agreements with operators. Vague statements like "global p2p network" and "millions of devices worldwide" are reasons to dig deeper.
  • Is there an independent audit of the sources? Having external verification is better than having none, but demand specifics: who conducted the audit and what exactly was checked.
  • What does the consent of the end device owner look like? If it’s a one-time window within a game on the TV—you already know the price of such consent.
  • What happens in the event of a sudden loss of part of the pool? Are there backup ranges, and how quickly are sessions restored?
  • Suspiciously low price. The market in 2026 is roughly divided into three tiers: corporate segment around $8.5–12 per gigabyte, mid-tier $3–6, budget from $1.75. An offer significantly below the lower boundary almost always means that someone paid for the traffic not with money.

It is also worth reconsidering the choice of proxy type itself. Some tasks, for which residential addresses are habitually used, can be easily handled by data center or ISP proxies—where the origin of the address is transparent by definition, and the price is lower. Residential and mobile addresses should be kept for purposes where real provider traffic is genuinely needed. If you value the predictability of the pool and a clear source of addresses, start with ProxyCove residential proxies and choose the type for a specific task, rather than "just in case."

Conclusion

The situation with LG appears to be an isolated incident: one vendor adjusted the store rules. However, it signifies a shift in the mechanics of regulating the market. Previously, the "gray" pool of residential IPs was rarely cleaned, at high cost and slowly—through international investigations like the NetNut case. Now, platforms have a way to reset an entire channel of address supply through administrative decisions, and researchers like Spur have learned to find SDKs simply by unpacking applications.

For TV owners, this is good news. For buyers of residential proxies, it is a signal: the question of "where does the provider get their addresses" has moved from the ethics section to the operational risks section. In 2026, it is no longer about conscience, but about whether your parser will work in a month.