One of the most striking findings was that the proxy code was found in a Pac-Man game that Samsung had featured in its "Editor's Choice" section — the manufacturer's own curated list of recommended apps .
Mnemonic security researcher Harrison Sand warned that because the proxy functionality is controlled server-side, the same mechanism that allows legitimate remote activation also opens a severe security risk. A malicious actor could flip the same switch across millions of devices through a server-side code change, effectively turning the entire installed base into a botnet without users ever knowing .
This is not a theoretical concern. Sand's warning highlighted that the infrastructure to control millions of smart TV exit nodes already exists — the only missing piece is who controls the server.
Mnemonic's traffic analysis suggested that the residential proxy network was already being actively used for commercial purposes. The analysis showed strangers' HTTP requests flowing through TV owners' home connections, consistent with commercial web scraping and data collection . This means the bandwidth the household pays for was being used — without explicit informed consent — to support third-party data operations.
The company described the move as a platform-wide security measure to protect users' internet connections from being used without their consent .
Samsung's announcement came roughly two weeks after LG Electronics USA took similar action. In July 2026, LG announced it would suspend any webOS apps that turned TVs into residential proxy nodes .
LG's decision followed research by threat-intelligence firm Spur Intelligence, which scanned 6,038 apps across LG webOS and Samsung Tizen and found that 2,058 — about 34% — contained residential proxy SDKs . The breakdown was stark:
LG Senior Vice President John Taylor told KrebsOnSecurity at the time that "a residential proxy network is not an intended use for LG smart TVs" and that developers who failed to comply would have their apps suspended .
The residential proxy SDK from Bright Data has not been limited to smart TVs. Researchers have also found it in :
A residential proxy is software that routes another person's internet traffic through a home internet connection, making the requests appear to originate from that household rather than a datacenter . When embedded in a smart TV app, the SDK uses the device's network link to carry traffic from third parties without the user necessarily understanding the scope or persistence of the arrangement.
Mnemonic researchers emphasized that the proxy routing could remain active even after the user closed the visible app — meaning simply using a recommended game could turn the TV into a node that continues running in the background .
The twin bans from LG and Samsung represent the largest coordinated consumer-protection response to the residential proxy SDK issue to date. The research that prompted these actions came from three separate security organizations — Spur Intelligence, Mnemonic, and Include Security — all publishing findings between June and August 2026 .
The key takeaway for smart TV owners is that not all apps in official storefronts have been vetted for this behavior. While both LG and Samsung have now committed to removing and blocking proxy apps, the code has been found on other platforms (Roku, iOS) that have not yet taken similar public action.