A new investigation has uncovered that nearly one-third of smart TV applications on LG and Samsung platforms are secretly monetizing users’ home internet connections by embedding residential proxy software.
Researchers at Spur Intelligence Labs scanned 6,038 apps across LG’s webOS and Samsung’s Tizen operating systems and found that 2,058 contained verified proxy SDK code quietly routing third-party internet traffic through household IP addresses, often without users realizing what they had agreed to.
The apps involved are not obscure or suspicious-looking. They present as screensavers, fish tanks, clocks, solitaire games, and novelty displays, the kind of passive, ambient content people leave running on a television for hours.
LG and Samsung Smart TV Apps Selling Users’ IP Addresses
Beneath that calm interface, however, a proxy SDK silently sells access to the home’s internet connection, making money in the background while the user stares at animated fish. Researchers did not rely on app store descriptions or permission screens to reach these findings.
They downloaded actual LG webOS and Samsung Tizen application packages, unpacked the files, and scanned for confirmed SDK fingerprints, including Bright Data’s brd_api.js, Massive SDK service markers, and Honeygain/Oxylabs package identifiers.

Three proxy vendors dominated the findings. Bright Data, including its affiliated entities Bright Data Ltd and Bright SDK, accounted for 367 flagged applications.
Massive SDK appeared across numerous apps on both platforms. Honeygain, a subsidiary of proxy giant Oxylabs, was listed as the direct publisher on 16 additional apps.
The publisher detail is significant because it suggests these are not ordinary apps that happened to include a monetization SDK; in many cases, the proxy company built the app itself, shipping thin utility shells and casual games at scale purely to give the SDK somewhere to run.
The danger goes beyond IP address exposure. Because these SDKs run inside the home network, a compromised or misconfigured proxy session could potentially reach local devices, routers, network-attached storage drives, cameras, and printers that were never intended to face the internet.
In January 2026, KrebsOnSecurity reported on the Kimwolf botnet, which exploited residential proxy infrastructure to tunnel back into home networks and move laterally across locally connected devices.
While Bright Data’s SDK includes a hardcoded blocklist for private IP ranges, researchers noted that the analyzed Massive and Honeygain samples did not contain equivalent local-network protections.

The real boundary, therefore, is each vendor’s server-side policy enforcement, something a TV owner cannot audit or verify.
Spur states that Amazon explicitly bans proxy-facilitating apps under its Device and System Abuse Policy, and Roku reportedly blocked Bright SDK and similar services after being contacted by researchers.
LG and Samsung have issued no equivalent public policy, leaving the same software category that rivals prohibit operating freely on their platforms. All three SDK vendors cited KYC processes, traffic filtering, and third-party audits in their responses.
Those measures may reduce abuse, but they do not change the core reality: millions of smart TVs are silently participating in commercial proxy networks their owners never knowingly joined. The app disappears when you close it, the proxy does not.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.