Bright Data's iOS SDK Quietly Conscripts Smart TVs Into a Scraping Proxy Network

A reverse-engineering of the SDK shows how consumer apps — including always-on televisions — relay traffic for the proxy giant now courting AI customers.

ThreatVectr Newsdesk· 3 min read
Bright Data's iOS SDK Quietly Conscripts Smart TVs Into a Scraping Proxy Network
Share

A researcher has pulled apart the iOS SDK that Bright Data embeds in third-party consumer apps, and the resulting writeup details how user devices get drafted into the company's residential proxy network without most users grasping what they agreed to.

Bright Data, the rebrand of Luminati, sells what it bills as the world's largest residential proxy network. The buyers, increasingly, are AI firms hungry for fresh web data to train and ground models. The supply side is the part that gets less press.

That supply comes from real consumer devices. App developers integrate Bright Data's SDK, the user gets a free tier or some perk, and the device becomes an exit node. Traffic from a paying scraping customer egresses through the user's IP. To a target website, the request looks like an ordinary home broadband user in, say, Phoenix or Manchester.

The wrinkle the research highlights: smart TVs.

Televisions sit on the network 24/7, often on fast residential connections, and rarely get audited the way a phone does. An SDK shipped inside a free streaming or utility app on tvOS can keep relaying scraping requests long after the user has wandered off to bed. The researcher's teardown documents the relay mechanics, the handshake with Bright Data's infrastructure, and the categories of traffic the network carries.

This is not new in concept. Residential proxy networks have run on consent-laundering for years — bundled into VPN clients, browser extensions and mobile SDKs, with disclosures buried in EULAs. Honeygain, IPRoyal and a long tail of smaller brokers operate similar pipelines. What is new is the scale of demand from the AI sector, which has turned proxy supply into a growth business.

Bright Data has consistently argued its consent flows are lawful and that it polices abuse. The company has also won notable court fights, including against Meta and X, over the legality of scraping public data through its network. Regulators in the EU and US have so far not moved against the residential-proxy model itself, though several class actions targeting SDK disclosure practices remain live.

For defenders, the practical takeaway is that residential IP space is no longer a useful trust signal. Credential stuffing, scraping, ad fraud and inventory hoarding increasingly arrive from genuine home networks, including ones behind smart TVs that the household forgot was even online. Behavioural detection and device fingerprinting carry the load that IP reputation used to.

For consumers, the surface area is harder to police. There is no easy way to tell whether a given free app embeds a proxy SDK short of a researcher tearing it apart. App store disclosures rarely name the broker.

The television in the living room may be working a second job.

© 2026 Threat Vectr