Back to Blog

Where Residential Proxies Come From: Traffic Costs and Why 15% of Nodes Are Infected

Residential proxy is someone's home internet. Let's break down the numbers from 2026, where the addresses in the pool come from: how much "passive income" services pay per gigabyte, why retail is 15-30 times more expensive, what the listing of 53 million nodes by Bitsight showed, and why 65% of corporate networks are already participating in this traffic.

📅August 9, 2026
Where Residential Proxies Come From: Traffic Costs and Why 15% of Nodes Are Infected

A residential proxy is someone's home internet. Not an abstract "pool of 100 million IPs," but a specific router, TV, or phone through which someone else's traffic is currently flowing. The question that is almost never asked when purchasing is: who agreed to give up this channel and for how much. The answer determines the quality of the pool, its legal status, and the likelihood that you are sharing the exit node with someone else's malware.

In 2026, reliable figures first emerged to answer this question. Bitsight TRACE listed the nodes of 30 proxy services, Infoblox examined the issue from the perspective of corporate networks, and the payouts from "passive income" services are publicly available. Let's compile everything together and analyze the economics.

Three Sources of Residential IPs

Any residential pool is formed in one of three fundamentally different ways.

  1. Voluntary sharing for money. A person installs an application like Honeygain, Pawns.app, or EarnApp and receives payments for the traffic they share. Consent is given, it is informed, and the owner can turn off the application at any time.
  2. SDK within free software. A developer embeds a proxy library into their application — VPN, file converter, streaming client — and earns money for each installed device. The user has formally "consented" by accepting the EULA, but did not make an informed choice.
  3. Infection. A device enters the pool through an infostealer or a backdoor pre-installed on a cheap TV box. There is no consent at all.

These three categories are sold under the same label "residential proxies" and at the same price. The difference is only visible through indirect signs — and that is why it is important to know how to read them.

How Much is Paid for a Gigabyte of Home Traffic

The rates for the first channel are public and easy to verify:

  • Pawns.app — fixed $0.20 per gigabyte, minimum payout $5.
  • EarnApp — about $0.36 per gigabyte in the USA and up to $0.24 in other regions; according to other estimates, the range is wider, $0.30–0.90 depending on the geo. Minimum payout is $2.50.
  • Honeygain — 3 credits for 10 MB, demand and actual rates vary significantly by country (traffic from the USA costs more than Indian traffic). Minimum payout is $20.

A realistic total for a home connection in the USA with several applications running simultaneously is about a dollar a day. This is the upper limit of "passive income": not a business, but pocket change for a subscription.

Now for the second half of the equation. The retail price of residential traffic from major providers in 2026 ranges from $3.75 per gigabyte at Decodo (formerly Smartproxy) to $8 per gigabyte at Bright Data on a pay-as-you-go plan. Data center traffic costs about $0.60 per gigabyte.

Compare: the channel owner receives $0.20–0.36, while the end buyer pays $3.75–8. The gap of 15–30 times is not the greed of the intermediary, but the cost of everything in between: rotation infrastructure, filtering out dead nodes, geo-targeting, support, legal risks. But understanding the scale of these figures explains the main point: part of the market has a strong temptation not to pay the device owner at all. This is where the second and third channels originate.

The voluntary pool also has a structural limitation that is rarely discussed. A person willing to keep an application running for a dollar a day is a narrow audience, and it is unevenly distributed: there are many participants where internet is cheap, and few where the demand for addresses is highest. Hence the constant shortage of "expensive" geos and the temptation to acquire them through SDKs in free software, where the device owner does not need to be paid at all. When a provider promises tens of millions of addresses in a specific Western country at a price significantly below market, the arithmetic of a voluntary channel does not explain such a volume.

15% of Nodes are Infected: Measurement Instead of Guesswork

Bitsight TRACE conducted a listing of nodes from January 19 to March 15, 2026 — 55 days of observation, 53,346,368 unique IP addresses, and nearly 990 million events across 30 proxy services. The largest pools by peak activity: NetNut — 2.3 million nodes, LunaProxy — 1.85 million, 711Proxy — 1.65 million, 922Proxy — 1.64 million, ThunderProxy — 1.47 million.

Next, the researchers compared these addresses with telemetry on malware:

  • 15.49% of addresses (8,222,677 IPs) showed signs of active infection;
  • 12.78% (6,785,708 IPs) — riskware activity;
  • among the identified families — Vo1d, Badbox, RootSTV/Pandoraspear, Gamarue.

Caution is needed in interpretation here. The global baseline infection rate across all addresses is comparable — 14–21%, meaning that the percentage alone does not prove that the pools consist of botnets. More importantly, specific service nodes confidently overlap with specific families of TV malware. A notable episode is the January 2026 operation against IPIDEA: before its shutdown, its infrastructure accounted for 302,238 Vo1d infections, or 55% of the entire global botnet, and a third of RootSTV nodes. By January 24, the service had recovered to 2.24 million nodes and the previous ~300,000 Vo1d infections.

A similar picture emerged in the most high-profile incident of the year: on July 2, 2026, the Google Threat Intelligence Group, along with the FBI, IRS-CI, and Lumen, shut down NetNut — a network based on more than two million hijacked smart TVs, streaming boxes, and Android devices. During one week in June, 316 separate threat clusters were identified using exit nodes for masking. A detailed analysis of how platforms like LG began to remove proxy SDKs from televisions was conducted separately.

65% of Corporate Networks are Already Involved

The most underestimated part of the story is that "home traffic" often turns out to be office traffic. Infoblox analyzed DNS queries from its cloud clients and obtained results that are hard to ignore:

  • more than 65% of clients in 2026 accessed domains of residential proxy services;
  • in pharmaceuticals and the food industry — over 90% of organizations;
  • in the banking and public sectors — over 60%;
  • at least in any vertical — 40%;
  • the total volume of DNS queries to proxy domains grew from about 300–400 billion per month at the beginning of 2025 to over 500 billion by April 2026.

The mechanics are simple: an employee installs a traffic monetization application on their work laptop, a browser extension, or a free streaming client with an embedded SDK — and the corporate address starts servicing external requests. For the security service, this means that the company's outgoing traffic suddenly no longer belongs to the company, and its IP can end up on blacklists due to someone else's actions.

What should an administrator do about this: look for DNS logs of requests to domains of traffic monetization services, block them at the resolver, prohibit the installation of such applications through policy, and separately check devices that suddenly generate a lot of outgoing connections during non-working hours. For legitimate work tasks that require an external address, managed proxies at the network level are available — with logs, control, and clear accountability.

What This Means for Proxy Buyers

The practical takeaway is not that "residential proxies are bad" — they remain a working tool where a real home address is needed. The takeaway is that the origin of the pool has ceased to be an abstraction and directly affects what you will get for your money.

The practical effect of a dirty pool: your exit node is simultaneously used by someone else's malware for password spraying or spamming; the address ends up on block lists; your success rate drops, and you attribute this to "weak anti-bot systems." Plus, there is reputational and legal risk: traffic goes through a device whose owner does not know about you.

What to ask the provider before purchasing:

  1. Where is the IP from. A clear answer sounds like "partner applications with payouts" or "ISP ranges by contract," not "the largest network in the world."
  2. Is there filtering. Does the provider remove nodes that have appeared on block lists and malware feeds — and how often.
  3. What about traffic guarantees. Refunds for failed requests and transparent billing indirectly indicate that the provider is confident in the quality of the nodes.
  4. Is a residential type even necessary. For many tasks, data center proxies at six times lower prices are sufficient, and where a live home address is required, the origin issue is resolved by choosing the provider, not the type of proxy.

It is also worth checking how your pool looks from the protection side: detectors in 2026 identify residential nodes not by ASN, but by behavioral and network characteristics — how modern IP intelligence works has been detailed elsewhere. If the pool is contaminated, it will be evident to you through metrics and to the anti-bot system through its data.

In Brief

A residential pool is an economy, not magic. The owner of a home channel is paid $0.20–0.36 per gigabyte, the same gigabyte is sold to the buyer for $3.75–8, and this gap encompasses all the differences between an honest partner pool and a network of infected devices. Measurements from 2026 showed that 15.49% of the 53 million listed nodes showed signs of active infection, and 65% of corporate networks are already involved in this traffic in one way or another.

The practical conclusion is clear: ask about the origin of the addresses before purchasing, not after the first mass ban. Residential proxies should be obtained where they are truly needed, and from a provider who can explain where their IPs come from — we have compiled selection criteria in a separate checklist.