Samsung is cracking down on smart TV apps that secretly share owners' internet connections with strangers, a practice that security researchers warn could turn millions of televisions into tools for cybercrime. The move follows new findings from Norwegian cybersecurity firm Mnemonic, which uncovered a popular Pac-Man game—endorsed by Samsung—that contained code enabling outsiders to route their web traffic through home networks. This marks a significant step for the electronics giant, which had previously allowed such apps to proliferate in its store. Main Developments Mnemonic's research, published Monday, found that several Samsung smart TV apps contain software that turns the TV into a residential proxy, or "resproxy," which funnels outsiders' web traffic through the owner's internet connection. At least one app, a Pac-Man game featured in Samsung's Editors Choice section, included code from Bright Data, an Israel-based proxy provider. This code is dormant until users accept a consent screen, after which it runs in the background—even when the app is closed—turning the TV into an always-on exit node. In response to TechCrunch's inquiry, Samsung issued an emailed statement announcing a ban on apps that share users' internet connections and a removal of existing ones. "We have already restricted new app registrations that incorporate such proxy functionalities on our Smart TV platform," a spokesperson said, adding that the company is implementing strict developer policies banning residential proxy SDKs and working to identify and remove all violating apps. Read also: AI Deployment Startup June Raises $20M to Tackle Enterprise Integration Mnemonic's consultant Harrison Sand gained deep access to a Samsung TV by rooting its software, allowing him to analyze all network traffic. He found that much of the data routed through the resproxy appeared to be large-scale scraping of LinkedIn profiles and collection of AI training data. Sand warned that a simple code change on a web server could instantly activate hundreds of millions of smart TVs into a potentially malicious botnet, even if users had not consented. The research highlights a "perfect storm" of problems in Samsung's app store, where many low-quality apps are bare-bone shells that load content from external servers. Sand noted that app reviews only see the few lines of code within, not the content that runs, meaning "what was reviewed is not necessarily what is running." Background Residential proxy networks are not new. They route internet traffic through ordinary home and office connections, making it appear as though requests come from a real household rather than a malicious actor. While some uses are legitimate—such as evading censorship or enabling AI companies to scrape data for training models—cybersecurity firms increasingly link resproxies to cyberattacks and data breaches, where hackers hide their activities behind innocent users' IP addresses. The practice has spread beyond Samsung. LG announced last month that it would ban resproxy-containing apps after reporting found that roughly 42% of apps on its store enlisted smart TVs into proxy networks. Resproxy code also appears in consumer phone apps, digital frames, and Android streaming boxes, which then share those devices' internet connections. This is a broader industry issue, but Samsung's scale—with apps claiming hundreds of millions of installations—makes its response particularly significant. Why It Matters The stakes are high for Samsung's massive user base. When a resproxy app runs, outsiders can pay to use the TV's internet connection, and the traffic is encrypted, making it nearly impossible to inspect. This means a user's IP address could be used for illegal activities, and the TV itself could be co-opted into a botnet. The risk is not just privacy—Sand's findings suggest that even without user consent, a server-side change could activate millions of devices, turning them into unwitting participants in cybercrime. For consumers, the issue underscores the lack of transparency in smart TV app stores. Users often install apps without knowing their full functionality, and the review process appears to miss hidden code. Samsung's ban is a positive step, but it also raises questions about how many other apps remain on the store and whether the company's enforcement will be thorough. What's Next Samsung says it is now working to identify and remove all apps containing resproxy components from its store. The company has already restricted new app registrations with such functionality, but the timeline for full removal is unclear. Meanwhile, Bright Data, the proxy provider behind the code in the Pac-Man game, did not respond to a request for comment, leaving open questions about its role and compliance. Security researchers like Sand will likely continue monitoring the ecosystem, and consumers may need to be more vigilant about the apps they install. As the industry grapples with resproxies,