Millions of smart TVs from major brands like Roku, Fire TV, LG, and Samsung have been found to be infected with malware that could allow them to be part of a botnet—a network of devices controlled remotely by cybercriminals. These infected devices can be used to route internet traffic through the TV, potentially allowing malicious actors to conduct activities like web scraping or coordinated attacks. The affected platforms include Roku, Fire TV, Tizen (used by Samsung), and webOS (used by LG). In response, some manufacturers have begun removing the problematic apps from their platforms. Reports of this issue have been circulating for several months, with an April report highlighting that many apps and games included a feature known as "residential proxy." This feature allows data to be transmitted through a device, like a smart TV, making it appear as though the traffic originated from the TV itself. Cybercriminals can exploit this to bypass restrictions on IP addresses, making their activities harder to detect. One such example is the IPIDEA service, which reportedly used millions of smart TVs to help AI training or support attacks from countries like China, North Korea, Iran, and Russia. A notable example of a compromised app was a children's Pac-Man game featured by Samsung as an Editor's Choice. According to security firm Spur, nearly a quarter of Samsung Tizen smart TV apps and over 40% of LG webOS apps could be used in this way. While residential proxies are not inherently malicious—they can be used for legitimate purposes like testing or advertising—they provide attackers with a scalable method to hide their activities, bypass geographic restrictions, and avoid detection by security systems that rely on device reputation. In response, LG and Samsung have pledged to remove any smart TV apps that include residential proxy features. IPIDEA has already been banned from platforms like Amazon, Roku, and Google TV, and similar restrictions have been placed on the Bright Data network. LG is working with developers to eliminate the functionality from their apps and will suspend any apps that fail to comply. Samsung has also restricted new app registrations and is actively identifying and removing apps that include these components.