Samsung pulls smart TV apps that resell home IPs to AI scrapers
TL;DR
- Samsung is restricting new smart TV app registrations and removing existing apps that embed residential proxy SDKs after research by Norwegian firm Mnemonic.
- A Pac-Man game featured in Samsung's Editor's Choice section shipped Bright Data proxy code that routed strangers' traffic through owners' home connections.
- LG took the same step in July 2026 after finding roughly 42% of apps in its store contained residential proxy software.
A Norwegian security firm rooted a Samsung smart TV, watched the network traffic flowing in and out, and found that several apps in the official store were quietly turning the hardware into an exit node for a residential proxy network. One of them was a Pac-Man game Samsung had previously featured in its Editor's Choice section. That, as TechCrunch reported, was enough for Samsung to say it is restricting new app registrations that ship residential-proxy SDKs and working to identify and remove the ones already live.
The mechanism is worth understanding, because it is the ordinary shape of a lot of AI-adjacent monetization now. The proxy code sits dormant until the user taps a consent screen the first time the app is opened. From then on the TV runs a continuous tunnel that forwards outsiders' web traffic through the household IP, and Mnemonic's Harrison Sand, an offensive security consultant at the firm, observed that traffic being used for LinkedIn profile scraping and AI training data collection. The tunnel keeps running even after the app is closed. Sand's line on why store review does not catch this is short and useful: what was reviewed is not necessarily what is running.
Samsung is not first here. LG made the same call in July after Krebs on Security reported that roughly 42% of apps in its store carried residential-proxy code, and researchers have flagged the same SDKs, most from Israel-based Bright Data, on other TV platforms including Roku, Comcast and Sky. Some of the affected apps have reportedly been installed on hundreds of millions of smart TVs, which is the number that matters strategically. This is the residential end of the AI data-collection supply chain, and it is running on consumer hardware whose owners have no practical visibility into what their television is doing overnight.
The honest caveats are that the reporting does not name most of the offending apps beyond the Pac-Man title, does not give a hard count for Samsung's own store, and treats the botnet-flip scenario as a warning from Sand rather than an incident. It also does not answer whether Bright Data or the developers behind these apps face any consequence beyond delisting, or whether the AI buyers on the other end of the scraping runs will change vendors.
The interesting thing to watch is not the takedown itself, it is whether the pattern generalizes. If TV platforms move to runtime SDK auditing instead of launch-time review, streaming boxes, connected cars, and every other ambient-compute surface with an app store will have to follow, and the cheap-monetization model Bright Data's SDK represents starts looking a lot more expensive to ship.
Shared on Bluesky by 1 AI expert
-
New, by me: Samsung has banned smart TV apps that enlist owners' internet connections into residential proxy networks, which are increasingly linked to cybercrime. Samsung told me it's also removing apps containing resp…
View on Bluesky →
Originally reported by techcrunch.com
Read the original article →Original headline: Samsung Bans Smart TV Apps Carrying Residential-Proxy Code Tied to AI-Training Data Scraping