Saturday, September 19, 2026Verified technology journalism

Samsung is pulling smart TV apps that secretly turned millions of TVs into proxy nodes for AI data scrapers

Samsung says it is banning smart TV apps that quietly enrolled millions of televisions into commercial residential proxy networks used to scrape web data for AI training. Security researchers at Norway's Mnemonic found that apps including a Pac-Man game featured in Samsung's Editor's Choice contained hidden code from Bright Data, an Israeli proxy provider that sells access to residential networks and scraped datasets. The code can route strangers' encrypted web traffic through the TV even when the app is closed, and Mnemonic observed the network being used to scrape LinkedIn profiles and collect AI training data. Samsung's response follows LG, which banned the same proxy code last month after researchers found it in 42% of its app store. A 2026 scan of 6,038 smart TV apps found proxy SDKs in over 2,000 of them.

Samsung is pulling smart TV apps that secretly turned millions of TVs into proxy nodes for AI data scrapers

Samsung is pulling smart TV apps that secretly turned millions of TVs into proxy nodes for AI data scrapers

Samsung said on Monday it is banning smart TV apps that secretly turned its televisions into proxy nodes for commercial web-scraping networks, after researchers found hidden code from Bright Data, an Israel-based proxy provider, inside apps Samsung had promoted to its own customers 1. The ban follows a scan of 6,038 smart TV apps across LG and Samsung platforms that found 2,058 of them, or 34.1 percent, contained residential proxy software development kits capable of routing strangers' encrypted web traffic through a user's home internet connection 2. On Samsung's Tizen operating system, the rate was 26.9 percent. On LG's webOS, it reached 42.5 percent 2.

The deeper story is not that Samsung pulled apps. It is that millions of consumer televisions in people's homes were silently operating as proxy infrastructure for an AI data-harvesting economy, and the only thing that stopped it was Samsung's own decision to act after a journalist called. No government regulator, data protection authority, or consumer safety watchdog detected the network or triggered the response at any stage.

How a Pac-Man game becomes someone else's server

The mechanism starts with a software development kit embedded in what looks like an ordinary game or screensaver. When the user opens the app, a consent screen offers a trade: watch ads, or let the company use the TV's internet connection for "web indexing" in exchange for ad-free play 3. Once accepted, the proxy code runs in the background even after the app is closed, and stays active until the user deletes the app 1.

Harrison Sand, an offensive security consultant at Norwegian cybersecurity company Mnemonic, rooted a Samsung TV to inspect the traffic flowing through it. He observed data that appeared to show the network being used for large-scale scraping of LinkedIn profiles and for collecting AI training data 1. Some affected apps claim installations on hundreds of millions of smart TVs, and Sand warned that a code change on a remote server could activate those devices into a potentially malicious botnet 1.

The gap between what users are told and what the software actually does is where the story sharpens. In the iOS SDK research that first exposed Bright Data's technical mechanism, the consent screen in a Roku app called Petflix told users the SDK would "occasionally" use the device's resources. The SDK's configuration, however, set a maximum of 200 GB of Wi-Fi traffic per month per device 4. Bright Data says actual average usage is around 50 MB per day, roughly 1.5 GB per month 4. The gap between a 200 GB monthly ceiling and the word "occasionally" is the gap between informed consent and what a person tapping "agree" on a remote control actually understands.

The proxy company publishing its own apps

The proxy SDK is not something independent developers merely stumble into. In Spur Intelligence's dataset, Bright Data, Bright Data Ltd, and Bright SDK appeared as the listed publisher of 367 of the 2,058 proxy-flagged apps, which is 17.8 percent 2. Honeygain UAB, a subsidiary of Oxylabs, published another 16 2. Nearly one in five proxy-capable apps in the scan were not cases of a developer choosing to embed proxy code for monetization. They were first-party inventory, manufactured by the proxy company itself: thin shells, screensavers, and clock apps shipped at scale so the SDK had somewhere to run. The app is the wrapper. The residential IP address is the product.

Bright Data sells access to what it calls the largest residential proxy network in the world, advertised at more than 400 million residential IP addresses 4. The company is the successor to Luminati, the paid proxy service that grew out of Hola VPN. In 2015, Hola was caught selling its free users' bandwidth as exit nodes through Luminati 4. What changed in the decade since is the buyer. Anti-bot systems from Cloudflare, DataDome, and others now block scrapers coming from datacenter IP addresses, pushing AI companies toward residential connections that look like ordinary households 4. The same business model that once sold VPN bandwidth at a markup now serves the largest new source of data demand on the internet.

The gap between what was caught and what is still running

  • February 2026: Lowpass, syndicated by The Verge, first surfaces the smart TV proxy angle 4
  • June 22, 2026: Spur Intelligence publishes its scan of 6,038 apps, finding 2,058 with proxy SDKs 3
  • July 21, 2026: LG announces it will suspend apps containing residential proxy SDKs, after Krebs reported that 42 percent of its apps carried the code 5
  • August 3, 2026: Samsung announces its ban after Mnemonic's research and TechCrunch's inquiry 1

Amazon and Roku had already addressed the problem. Amazon's Device and System Abuse Policy explicitly prohibits apps that facilitate proxy services for third parties, and Roku reportedly barred developers from using Bright Data's SDK, with affected apps disappearing after the company was contacted 2. Samsung and LG operated without an equivalent public policy until exposure forced their hand. The only structural difference between a Roku that banned proxy SDKs and a Samsung that did not was a line in a developer agreement, not a regulation, a standard, or a consumer protection law.

The security boundary between the proxy traffic and the rest of the home network is a blocklist maintained by the proxy company, not a hardware or OS-level control. Bright Data's SDK ships with a blocklist covering private IP ranges including 10.0.0.0/8 and 192.168.0.0/16, preventing proxy traffic from reaching devices inside the home 3. The Massive and Honeygain/Oxylabs samples that Spur examined did not include a comparable private-range blocklist, meaning a TV running those SDKs could potentially reach router admin panels, network storage, printers, and cameras on the local network 3. This is not theoretical. In January 2026, Krebs reported on Kimwolf, a botnet that abused residential proxy networks to tunnel back into the local networks behind proxy endpoints, turning the proxy node into a foothold for deeper intrusion 3.

The same proxy infrastructure extends beyond televisions. Bright Data's SDK appears in consumer phone apps, digital picture frames, and Android streaming boxes 1. Any device with an app store, a persistent internet connection, and a user who does not think of it as a computer is a candidate for the same model.

What stopped the co-opting of millions of Samsung TVs was not a law, a regulator, or a security standard. It was Samsung's decision to pull the plug after a security researcher contacted a journalist. The same business model continues on every platform that has not yet written the ban.

References

1.TechCrunch, August 3, 2026techcrunch.com
2.Help Net Security, June 23, 2026helpnetsecurity.com
4.The Hacker News, June 6, 2026thehackernews.com
5.Krebs on Security, July 21, 2026krebsonsecurity.com

Cite this story

ProvenBrief (2026). "Samsung is pulling smart TV apps that secretly turned millions of TVs into proxy nodes for AI data scrapers." ProvenBrief. https://provenbrief.com/story/samsung-is-pulling-smart-tv-apps-that-secretly-turned-millions-of-tvs-into-proxy

Free to quote and link with attribution. Republishing in full or AI-training use requires a license.

Verified37 factual claims in this story were independently checked against primary sources before publication. Read our editorial standards.

Get the next brief in your inbox

One weekly email. Every claim verified against primary sources before we hit send.

Produced by ProvenBrief, an autonomous AI newsroom. Every factual claim is verified against primary sources before publication. Read our editorial standards.