A follow-up to https://mastodon.bsd.cafe/@82mhz/117002938483503805 @82mhz
The linked article (June 2026) began:
The work at Include Security has us working with AI day in and day out (hacking it, using it, training it, etc). ..
– 18–23 minutes, according to Firefox Reader.
I used AI to get a concise timeline. The text below is taken from Claude's response.
…
The general practice: 2015
The root of it all is Hola VPN / Luminati (Bright Data's predecessor). In May 2015, it was discovered that Hola — a free "VPN" — was quietly turning users' devices into paid exit nodes sold through a sibling brand, Luminati, at up to $20/GB. The discovery came after 8chan's admin, Frederick Brennan, traced a wave of DDoS/spam attacks against his site back to Hola users being abused as a botnet, and outlets like The Register, Fortune/Motherboard, and TechRadar covered it within days. Hola's Luminati brand was described as "the world's largest VPN network," routing HTTP, HTTPS, or TLS requests through millions of idling end-user devices. Luminati (founded 2014) was Hola's mechanism for selling access to its userbase as exit nodes, charging $20 per gigabyte for bandwidth from its free VPN users, and it later rebranded as Bright Data. So the general "your free app is secretly selling your connection as a proxy" pattern is a 2015 story, not a 2026 one.
The smart-TV-specific angle: February 2026
The TV angle specifically is much newer, and predates the IncludeSecurity teardown by about three and a half months. Independent tech journalist Janko Roettgers broke it in his Lowpass newsletter (syndicated by The Verge) in late February 2026: with Bright's SDK, a viewer's smart TV becomes part of a massive global proxy network that crawls and scrapes the web, alongside apps on desktop PCs and mobile devices, with the company claiming roughly 150 million such residential proxies worldwide, gathering data later resold to train AI models. Multiple later write-ups explicitly credit this as the origin point: "Lowpass, syndicated by The Verge, first surfaced the smart-TV angle in February, and this is the technical teardown."
The AI-scraping tie-in and platform response: 2025–early 2026
Around the same period, the broader AI-scraping-via-residential-proxy story was already building: Krebs reported in October 2025 on botnets like Aisuru fueling large-scale AI data harvesting, and Google dismantled the criminal IPIDEA proxy network in January 2026. By April 2026, FlatpanelsHD was reporting that Amazon, Google and Roku had restricted Bright Data and similar residential proxy networks from their app SDKs (Fire TV, Google TV, Roku OS), while Bright Data continued listing LG's webOS and Samsung's Tizen as partners, with over 200 apps on webOS alone.
Your June 2026 post: the deep technical teardown
The IncludeSecurity/Buchodi post you linked was the first to actually reverse-engineer the SDK rather than just report on the business model — documenting the peer channel's weak authentication and the iOS VPN bypass — which is why it got picked up so widely (Hacker News, Krebs, CyberSecurityNews, etc.) even though the underlying phenomenon was already known.
Aftermath
A follow-up Spur.us platform scan in June 2026 quantified the scale: Bright Data, Bright Data Ltd, and Bright SDK accounted for 367 proxy-flagged apps in their dataset, with residential proxy SDKs found in nearly half of scanned LG webOS apps and over a quarter of Samsung Tizen apps. And just last week, Krebs on Security reported LG moving to ban these SDKs from its smart TV apps entirely.
So the short answer: the general practice (apps quietly monetizing users' devices as residential proxy exit nodes) was first exposed in 2015 with Hola/Luminati; the smart-TV-specific version of that story broke in February 2026 via Lowpass/The Verge; and your June 2026 link is the deep technical forensic follow-up, not the original discovery.