Residential proxy networks remain a major source of web scraping traffic, overwhelming websites with millions of distinct IP addresses that mimic legitimate users.
Residential proxy networks remain a major source of web scraping traffic, overwhelming websites with millions of distinct IP addresses that mimic legitimate users. On July 2, Google announced that, together with the U.S. Federal Bureau of Investigation and other partners, it dismantled a residential‑proxy service called NetNut, temporarily lowering attack volume. The problem, first highlighted in a 2025 article on AI scraper bots, has persisted as attackers use compromised home devices and poorly secured streaming hardware to route traffic through central command nodes. Operators include criminal groups that install malware on devices, and commercial services such as Bright Data that market "ethically sourced" IPs and invite users to route traffic through their devices as part of a VPN. While large AI developers generally scrape sites openly and honor robots.txt, the scale of residential‑proxy attacks far exceeds their traffic. Website operators have responded with proof‑of‑work systems like Anubis, CAPTCHA challenges, login requirements and data‑poisoning tools, but these measures can hinder real users and legitimate crawlers. LWN, which has faced its heaviest scraper attack in July, has optimized its site and deployed defenses that minimize impact on logged‑in users while occasionally affecting anonymous visitors. The funding source for the proxy networks is unclear, and there is no public evidence that leading model companies are using these networks. The industry continues to face an arms race, and a lasting solution remains pending.
- Publisher
- Hacker News
- Reliability
- high
- Published
- 7/11/2026, 10:00:36 AM
- Retrieved
- 7/11/2026, 10:00:36 AM
- Relevance
- 80%
- Confidence
- 85%

