Samsung today said it has restricted new app registrations that contain residential proxy functionality and is working to remove existing apps carrying the same components, after Norwegian security firm Mnemonic traced proxy code from Bright Data inside a Pac-Man game the manufacturer had promoted in its Editor's Choice section.

The statement, issued to TechCrunch after the publication approached the company about research published today, commits Samsung to a platform-wide developer policy change across Tizen, the operating system that runs its televisions. It arrives thirteen days after LG Electronics USA made a comparable commitment for webOS, and roughly a month after the first published measurement of how widespread the practice had become on both platforms.

What the code does

residential proxy network rents out the internet connections of ordinary households. Traffic from a paying customer enters the network and leaves through a consumer device, arriving at its destination with a residential IP address attached rather than one belonging to a data centre. Within the industry the shorthand is resproxy, and the enlisted device is described as an exit node.

The research by Mnemonic, an offensive security consultancy based in Norway, describes what happens when that arrangement is embedded in television software. According to the report, apps containing resproxy code can convert a Samsung smart TV into an always-on tunnel for outsiders, and the tunnel continues to operate after the app itself has been closed. Some of the affected apps claim installation counts in the hundreds of millions, according to figures published by their own developers.

The mechanism that allows this to pass review is structural rather than technical. Many of the apps are shells of a few lines of code whose only function is to load content hosted elsewhere. An app store reviewer inspecting the submission sees the wrapper. The behaviour lives on a remote server.

"What was reviewed is not necessarily what is running," wrote Harrison Sand, an offensive security consultant at Mnemonic.

Sand rooted the software on a Samsung television to reach its internals, then captured and analysed every packet entering and leaving the device. That method produced an unusual artefact: a first-hand view of traffic moving through a commercial proxy network from the perspective of the household paying for the bandwidth.

The Pac-Man case

The app Sand examined was a Pac-Man game. Samsung had endorsed it and displayed it prominently in the Editor's Choice section shown to customers on their television screens. Inside it, Sand found proxy code belonging to Bright Data, an Israel-based company that sells access to residential proxy networks and, separately, operates a marketplace for scraped datasets. Those datasets are assembled using enlisted devices as exit nodes, pulling public data from many sources simultaneously in a pattern designed to work around systems built to detect and block scraping.

The activation sequence matters for any assessment of consumer exposure. Sand found that the Bright Data code loaded when the game opened, but did not by itself convert the television into an exit node. The code remained dormant until the user accepted a consent screen. Acceptance activated it immediately, and it then ran in the background until the app was deleted.

That dependency on a single remote trigger is where Sand located the systemic risk. He warned that a "simple code change on a web server" could instantly activate hundreds of millions of smart televisions into a potentially malicious botnet.

The traffic Sand observed was itself informative. Much of what passed through his television appeared to be large-scale harvesting of LinkedIn profiles and collection of AI training data. Sand noted that he saw only a small fraction of what moves across Bright Data's network. Bright Data did not respond to a request for comment from TechCrunch.

Samsung's response

Samsung confirmed the policy change in an emailed statement, describing action already taken and action under way.

"We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," said a Samsung spokesperson. "We are currently implementing strict platform-wide developer policies explicitly banning residential proxy SDKs, and we are working to identify and remove all apps currently available in our store that contain these components."

Three distinct commitments sit inside that statement: a registration gate for new submissions, a written developer policy prohibiting the software development kits outright, and a retrospective sweep of the existing catalogue. No completion date was attached to the third.

The LG precedent and the underlying measurement

Samsung's move follows LG Electronics USA, which said in the week of July 21, 2026 that it would suspend webOS apps that turn a television into an always-on residential proxy node.

Both manufacturers were responding to the same measurement. On July 2, 2026, KrebsOnSecurity published research by the security firm Spur examining how common residential proxy SDKs had become in smart TV software. Spur found that more than 42 percent of apps available for download on LG smart TVs contained SDKs turning the television into a proxy node indefinitely, and that more than a quarter of apps built for Samsung's Tizen operating system carried similar components. Bright Data accounted for a majority of the proxy SDKs identified across both platforms.

LG framed its position through John Taylor, a senior vice president at the company.

"A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform," Taylor said. "If this option is not removed, these apps will be suspended."

Taylor described the company's review of those apps as "well underway now," and said LG would strengthen its evaluation process for developer-submitted apps, including those incorporating residential proxy SDKs.

The commercial logic driving adoption is visible in the same research. Proxy providers pay app developers to include their SDKs, creating a monetisation route that does not depend on advertising or subscriptions. Spur found the kits bundled with games, screensavers and file utilities. In the Pac-Man case documented on LG hardware, the app presented users with a binary choice: watch advertisements inside the game, or allow the television to serve as a residential proxy node.

Bright Data defended its practices in a statement shared with KrebsOnSecurity, saying its network is built on consent and responsibility and operates within LG and Samsung terms.

"Every peer opts in through a dedicated screen and receives value in return; every customer is vetted, and our practices have now undergone a second independent audit by PwC," the statement reads. "We remain committed to an open, transparent internet where legitimate businesses, researchers, and institutions can responsibly access data that lives in the public domain."

Spur's argument is not that residential proxy networks are illegitimate, but that they are being embedded at scale in hardware consumers do not treat as computers and cannot audit.

"A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight," wrote Spur's Trevor Sutter. "The risk is amplified when consent comes from individuals within the household who use the device but shouldn't give consent, such as minors."

Why this reaches advertising

The television is the same device on which two manufacturers have spent the past eighteen months building advertising businesses. Samsung Ads opened Smart TV home screens to programmatic buying through The Trade Desk and Google DV360 on June 10, 2026, with Magnite SpringServe handling ad serving. Two weeks later, remote-enabled interactive advertisements arrived on Samsung TV Plus through Amazon DSP, with Samsung Ads reporting that the free streaming service had passed 100 million monthly active users. LG Ad Solutions has pursued the same home screen inventory. The proxy SDKs sit alongside that inventory, inside the same operating system, on the same IP address.

That co-location has consequences for measurement. Verification vendors and buy-side fraud systems assess traffic quality partly by checking IP addresses against databases of data centre ranges and known residential proxy networks. An IP flagged as a proxy exit node carries a different risk profile than a clean household address. When the exit node and the CTV impression share a connection, the signals become harder to separate. PPC Land documented in June 2026 that AdSense publishers were given a toggle to share full rather than truncated IP addresses with demand partners precisely because truncation degrades invalid traffic detection resolution.

The verification layer was already under scrutiny before this. An investigation covered in March 2025 found that pre-bid systems from major vendors do not receive browser, device and IP credentials from some of the largest buying platforms, leaving them without the identifiers needed to distinguish a declared bot from a data centre. In connected television specifically, DoubleVerify recorded a 140 percent rise in CTV fraud schemes and variants in the first quarter of 2026against the same quarter a year earlier, while only 21 percent of surveyed advertisers used invalid traffic detection as a key performance indicator for CTV campaigns. Fraud operations built on the same supply chains continue to surface: HUMAN Security disclosed a scheme reaching two billion bid requests a day in July 2026.

Encryption compounds the difficulty. Traffic moving through a resproxy is generally encrypted, which places its contents beyond inspection. A network defender sees a request from a residential connection in a plausible location and has little basis to treat it differently from a human visitor.

The scraping economy on the other end

What Sand observed leaving his television connects the hardware story to a set of disputes the marketing industry has been tracking on its own terms.

Residential proxies are one of the mechanisms by which automated collection reaches sites that have tried to close their doors. Cloudflare research covered in April 2026 showed AI crawlers consuming 4.2 percent of all HTML requests across its network, and Kinsta infrastructure logs published in June 2026 recorded a single bot sending 3.75 million requests to WordPress shopping cart URLs in one day. Those figures count identifiable crawlers. Traffic arriving through residential exit nodes does not present itself as a crawler at all.

Botify data covered in March 2026 found OpenAI bots crawling retail sites 198 times for every referral visit delivered, a ratio that gives publishers a direct commercial reason to block. Blocking, however, only functions against traffic that can be identified.

The legal position around the collected material is separately contested. In July 2026, the European Data Protection Board adopted guidelines concluding that consent is unlikely to serve as a workable legal basis for large-scale scraping used to train generative AI models, and that publishing data on an openly accessible page does not amount to consenting to its collection for that purpose. Google, meanwhile, is litigating against SerpApi over scraping of its search results while itself crawling the open web at scale. LinkedIn profile data, the category Sand saw moving across the network, has been the subject of scraping disputes since the hiQ Labs litigation and remains a commercial dataset sold by proxy vendors.

The consent question raised by Spur is not abstract for an industry that has spent two years arguing about what a valid permission looks like on a television.

Smart TV data practices have already drawn enforcement attention. In December 2025, the Texas attorney general sued Hisense over automatic content recognition affecting approximately 1.27 million residents, alleging that the manufacturer labelled its ACR system as an "Enhanced Viewing Service" during setup and disclosed the underlying technology only after users navigated more than twenty clicks of legal terminology. Last week, the Video Advertising Bureau cautioned buyers that ACR measurement depends on opt-in rates that vary by market and demographic.

A proxy consent screen presented inside a game raises the same category of question with a materially different outcome attached. Accepting ACR terms produces a viewing record. Accepting a proxy prompt produces an open network path through the household connection, one that persists until the app is deleted rather than until the app is closed. Neither Samsung nor LG has published figures on how many households accepted such prompts.

Platform governance is the remaining variable. Both manufacturers have now committed to removing the SDKs, but the review problem Sand identified is unchanged: an app store can inspect submitted code, and the behaviour in question lives on servers the store does not control. Whether registration gates and written developer policies address a loading pattern designed to defeat static review is a question the sweeps will answer in practice.

Timeline

Summary

Who: Samsung Electronics, LG Electronics USA, Norwegian security consultancy Mnemonic and its offensive security consultant Harrison Sand, the security firm Spur and its researcher Trevor Sutter, and the Israel-based proxy and dataset vendor Bright Data.

What: Samsung said it has restricted new app registrations containing residential proxy functionality, is implementing platform-wide developer policies banning residential proxy SDKs, and is identifying and removing existing apps carrying those components. The move follows research documenting Bright Data proxy code inside a Pac-Man game that Samsung had featured in its Editor's Choice section, and earlier measurement showing residential proxy SDKs in more than 42 percent of LG webOS apps and more than a quarter of Samsung Tizen apps.

When: Mnemonic published its research and Samsung issued its statement today, August 3, 2026. Spur's measurement was published on July 2, 2026. LG committed to suspending non-compliant webOS apps on July 21, 2026, with Bright Data responding the following day.

Where: The policy applies across Samsung's Tizen smart TV platform and its app store globally, alongside the parallel commitment covering LG's webOS store.

Why: Apps built as thin shells loading remote content can pass app store review while executing behaviour the reviewer never sees, allowing outside parties to route encrypted traffic through household internet connections. For advertising buyers, the affected televisions are the same devices carrying connected television inventory, and proxy exit node activity on a household IP complicates the invalid traffic signals that verification systems rely on.