Bright Data SDK Turns Smart TVs Into Scraping Proxies

SkimNews Take
The integration of web-scraping SDKs into consumer apps effectively turns user devices into a distributed, low-cost infrastructure for data collection, blurring the lines between personal electronics and corporate data operations.
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Include Security and researcher Buchodi published a June 5 teardown of Bright Data's iOS SDK, finding the peer channel that carries scraping jobs has no real authentication — weaker, the researcher said, than the command-and-control channels used by most malware
- Bright Data markets a residential proxy network of 400M+ IPs, with the SDK contributing a "consent-sourced pool" of 150M+ IPs embedded in free apps behind opt-in screens, including smart-TV apps from partners PlayWorks Digital, CloudTV, and Longvision
- The opt-in flow in apps such as Roku's Petflix told users the device would be used "occasionally," while the SDK's settings permit up to 200 GB of traffic per month — and on iOS the traffic bypasses configured VPNs and eludes standard app-monitoring tools
- Bright Data disputed the characterization in an email to The Hacker News, saying the opt-in names the company, the SDK reaches only approved domains, traffic averages ~50 MB/day on Wi-Fi, and pointing to a PwC report, AppEsteem certification, and ISO and SOC 2 attestations
- Google, Amazon, and Roku restricted background proxy SDKs and Bright Data dropped those platforms, though it still lists Samsung's Tizen and LG's webOS — and the article notes home users can block the SDK by sinkholing domains like proxyjs.brdtnet.com and clientsdk.bright-sdk.com
- The business model traces back to Hola VPN, which in 2015 was caught selling free users' bandwidth through Luminati (Bright Data's predecessor) at $20/GB; today's buyers are AI scrapers routing through residential IPs to evade anti-bot defenses from Cloudflare, DataDome, and others
Why it matters: Bright Data's 150M+ opt-in IP pool, embedded in free apps and running on always-on smart TVs, supplies AI scrapers with residential capacity that evades anti-bot defenses. The researcher found the control channel lacks authentication and is weaker than most malware C2 — meaning these 150M devices are a single exploit away from being weaponized beyond scraping.


