LG Electronics USA has announced a significant shift in its app store policy, confirming plans to suspend all applications on its smart TV platform that incorporate residential proxy software development kits (SDKs). This decision follows a comprehensive investigation by security researchers which revealed that a substantial portion of the applications available on LG’s webOS and Samsung’s Tizen operating systems were essentially turning consumer televisions into conduits for third-party internet traffic. The move marks a critical turning point in how major hardware manufacturers manage the monetization strategies of third-party developers and highlights the growing security risks inherent in the Internet of Things (IoT) ecosystem.
The Discovery of Widespread Proxy SDK Integration
The impetus for LG’s policy change stems from a detailed report published in early July 2024 by Spur, a cybersecurity firm specializing in identifying and tracking proxy networks. Spur’s researchers conducted an audit of the application ecosystems for the two leading smart TV platforms: LG’s webOS and Samsung’s Tizen. The findings were startling: more than 42 percent of the games and utility apps available on the LG webOS store contained embedded SDKs designed to transform the host device into a residential proxy node.
A residential proxy node is a device that allows a third party to route their internet traffic through a home user’s IP address. To the destination website, the traffic appears to originate from a legitimate residential connection rather than a data center or a known business IP. This makes such nodes highly valuable for activities ranging from legitimate web scraping and market research to more nefarious purposes, such as bypassing geographic restrictions, credential stuffing, or launching distributed denial-of-service (DDoS) attacks.
Spur’s research indicated that while LG’s platform had the highest concentration of these SDKs, Samsung was not far behind, with more than 25 percent of its Tizen-based apps featuring similar components. The apps identified were not limited to obscure titles; they included popular casual games like clones of Pac-Man, as well as system utilities, file managers, and various screensaver applications.
Official Response from LG Electronics
In direct response to the data provided by Spur and subsequent inquiries from cybersecurity journalists, LG Electronics has taken a firm stance against the practice. John Taylor, Senior Vice President at LG Electronics USA, clarified the company’s position, stating that the use of smart TVs as nodes for residential proxy networks was never an intended or authorized function of the webOS platform.
According to Taylor, LG is currently in the process of auditing its entire app store. The company has begun communicating with app developers whose products contain these SDKs, demanding their immediate removal. Developers who fail to comply with these new directives will face the permanent suspension of their applications from the LG Content Store.
"LG is committed to keeping residential proxy networks out of its smart TV apps going forward," Taylor said in a statement. He emphasized that the review process is "well underway" and that the company intends to strengthen its evaluation criteria for all future developer submissions to ensure that no such SDKs bypass the initial vetting process again. This move is framed as part of a broader effort to enhance platform quality and protect the user experience from intrusive or hidden background processes.
Understanding the Monetization Model: "Nodes for No Ads"
The prevalence of these SDKs is driven primarily by the economics of free-to-play mobile and TV applications. Developers looking for ways to monetize their creations without relying solely on traditional display advertisements often turn to residential proxy providers. These providers, such as Bright Data (formerly Luminati), offer SDKs that developers can integrate into their code.
In exchange for including the proxy software, the developer receives a recurring payment based on the amount of traffic routed through their users’ devices or the number of active nodes they maintain. From the user’s perspective, this is often presented as a "choice." Upon launching an app for the first time, a user might be greeted with a prompt asking if they would prefer to see advertisements or "share" their unused internet resources to support the developer.
However, security experts argue that this "consent" is often illusory. The technical implications of turning a television into a proxy node are rarely explained in terms a layperson can understand. Furthermore, because smart TVs are frequently used by multiple members of a household, including children, the person clicking "accept" on a consent screen may not be the primary account holder or someone capable of understanding the privacy and security trade-offs involved.

The Perspective of Proxy Providers
Bright Data, identified in the Spur report as a major provider of the SDKs found in these apps, has defended its business model. In statements following the report, the company emphasized that its network is built on the principles of transparency and informed consent. Bright Data maintains that its operations are fully compliant with the terms of service set by platform providers like LG and Samsung.
The company noted that every "peer" (the user whose device becomes a node) must opt-in through a dedicated screen and receives value—such as an ad-free experience—in return. Bright Data also highlighted that its practices undergo independent audits, including a recent review by PwC, and that it employs rigorous "Know Your Customer" (KYC) protocols to ensure that its clients are legitimate businesses and researchers.
Despite these assurances, the core issue remains one of platform integrity. While a proxy provider may vet its own customers, the platform manufacturer (LG) has determined that this specific use of their hardware is incompatible with the product’s purpose and the security expectations of their consumers.
Technical Risks and Network Security Implications
The transformation of a smart TV into a residential proxy node is not merely a matter of bandwidth consumption. It introduces several layers of risk to the home network:
- IP Reputation Damage: If a third party using the proxy engages in illegal activities or violates the terms of service of various websites, the home user’s IP address may be blacklisted. This can result in the user being blocked from accessing streaming services, online banking, or gaming platforms.
- Local Network Pivoting: Although proxy providers claim to use technological safeguards to prevent customers from interacting with other devices on the proxy user’s local network, the presence of an active, third-party-controlled node inside a home firewall is a significant security vulnerability. If the proxy software itself has a vulnerability, it could serve as an entry point for lateral movement within the home network, potentially exposing PCs, smartphones, and storage devices.
- Performance Degradation: Constant background data transmission can lead to increased latency (ping) and reduced download speeds for other devices in the home, directly impacting the quality of the very streaming services the TV was purchased to provide.
- Hardware Longevity: Smart TVs are not designed for the 24/7 high-intensity data processing required of a network node. Constant network activity can lead to increased heat and wear on internal components, potentially shortening the lifespan of the device.
Chronology of the Controversy
The current crackdown is the result of a series of events over the past several months that have brought IoT security into the spotlight:
- January 2024: Security researchers identify the "Kimwolf" botnet, which specifically targets residential devices to build a massive proxy infrastructure for cyber-espionage.
- Early July 2024: The FBI and international partners announce the seizure of several proxy platforms, including NetNut, which were found to be facilitating large-scale automated attacks.
- July 2, 2024: Spur releases its groundbreaking report on the prevalence of proxy SDKs in smart TV app stores, specifically naming LG and Samsung as the most affected platforms.
- Mid-July 2024: LG Electronics USA issues its first formal response, confirming the plan to purge these apps from the webOS store.
- Late July 2024: Industry analysts begin observing the removal of several high-profile utility apps from the LG Content Store as the audit takes effect.
Broader Context: LG’s Software Reputation Challenges
The decision to ban proxy SDKs comes at a time when LG is already facing criticism for its software practices. Recently, the company drew ire from the tech community following reports that some of its high-end LCD monitors were automatically installing promotional software for McAfee antivirus.
The YouTube channel Gamers Nexus documented instances where LG monitors, when connected to a Windows PC, would trigger a software download via Windows Update that installed a "McAfee Security" app without any user interaction or approval prompt. This practice, often referred to as "bloatware" or "crapware," has raised concerns about how much control hardware manufacturers are exerting over the software environments of their customers’ devices.
By taking a firm stand against proxy SDKs, LG may be attempting to rebuild trust with privacy-conscious consumers, signaling that it is willing to prioritize device security over the monetization whims of third-party developers.
Future Outlook for Smart TV Ecosystems
The fallout from the Spur report is likely to extend beyond LG. As the leading manufacturer of smart TVs globally, Samsung is now under pressure to follow LG’s lead and implement similar bans on its Tizen OS platform. If the industry moves toward a collective ban on residential proxy SDKs, it will force app developers to return to traditional monetization models or find more transparent ways to fund their projects.
Furthermore, this incident underscores the need for more robust regulatory oversight of the IoT market. Currently, there are few standardized rules regarding what constitutes "informed consent" for background data sharing on non-traditional computing devices. As televisions, refrigerators, and even lightbulbs become increasingly sophisticated, the boundary between a consumer appliance and a commercial network node continues to blur.
For now, LG owners are encouraged to review the apps installed on their televisions and be wary of any "free" games or utilities that offer ad-free experiences in exchange for sharing "idle resources." As LG’s audit continues, many of these apps will simply disappear from the store, but the broader conversation regarding the security of the smart home is only just beginning.
