The Consent Screen NetNut Never Shows You

At least 2 million home devices, quietly enrolled. Your smart TV might be one, and no tool lets you check.

Share

Introduction

Somewhere in NetNut's enrollment code sits a screen that asks your permission before it turns your TV into someone else's proxy server. Investigators pulled the software apart and found the screen right where you'd expect it, and found that on the devices already enrolled, it never runs. NetNut's parent company says it "places significant emphasis on appropriate notice and consent mechanisms." The forensics group that actually read the code, Qurium, wrote that "while the library contains consent components none of them are invoked."

What a Residential Proxy Actually Is

If you own a smart TV, a streaming box, or you have ever installed a "free" VPN or a modded streaming app, there's a real chance one of your devices has already been doing shift work for NetNut, and nobody, not the FBI and not the company, can tell you for certain whether it has. On July 2, 2026, the FBI and IRS Criminal Investigation seized hundreds of domains tied to NetNut, a residential proxy network owned by the Nasdaq-listed Israeli company Alarum Technologies (ALAR). Google's Threat Intelligence Group, one of the partners in the takedown, puts the network's size at "at least 2 million" home devices worldwide.

A residential proxy is a plain idea with an ugly middle. Instead of routing through an obvious data center, a paying customer's traffic gets pushed out through your home connection, wearing your IP address like a costume, so the site on the other end sees an ordinary person in an ordinary house. That disguise sells. It goes to ad-verification companies and large-scale scrapers, including the "AI recruitment market" NetNut advertises to by name. It also reaches worse buyers: in one week in June, Google counted 316 distinct threat clusters routing through suspected NetNut exit nodes, "including cybercriminal and espionage groups."

Devices get enrolled two ways, and consent goes missing in both. Some arrive with the proxy code baked in before the box is ever opened. Others pick it up when someone in the house installs an app carrying hidden proxy code, which is how Krebs on Security described the Popa devices being compromised, "with little or no consent from victims." Qurium traced that same code into pirated streaming apps, a torrent client, and RoboVPN, a consumer VPN operated by CyberKick, which Alarum owns outright. That RoboVPN line is the one I keep returning to: a product people install specifically to protect their privacy, carrying the code that quietly resells their connection.

The Screen That Never Loads

Qurium's forensic report is the document the cybercrime coverage mostly skipped, and it's the one that matters if the device is yours. Its analysts took the SDK apart line by line. The consent components are in there, and none of them get called. The tunneling protocol they examined had "no authentication mechanism ... no registration for the service, no consent. Nothing!" A consent screen that ships but never displays is worse than none at all, because someone wrote that screen and then shipped the version that never calls it.

The traffic path isn't in dispute either. Synthient, a separate forensics outfit, captured a test device running the Popa SDK and watched it egress straight through "NetNut's gateway at gw[.]netnut[.]net:9595." Synthient was careful about what that proves, calling it "evidence of the traffic path, not proof of what NetNut knew or intended." Alarum, for its part, told Krebs the findings were "demonstrably inaccurate assertions and flawed deductions rather than verified facts," and says NetNut runs customer due diligence and monitors for misuse. Alarum disputes intent, not the underlying facts. In no filing or statement I've seen has it disputed that the consent code sits unused or that the traffic reached its gateway.

The Executive Behind the Domain

Qurium didn't stop at the code. It traced a domain used as Popa infrastructure, ninjatech[.]io, and the Latvian entity that registered it in 2020, back to Moshe Yehuda Kramer, NetNut's co-founder. Alarum's own website lists him as SVP of R&D and Chief Strategy and Innovation Officer. Qurium sent Kramer a right-of-reply request on June 15. That same day, NinjaTech's LinkedIn page vanished. The next day, he wrote back that the company "ceased operations many years ago" and cautioned against reading too much into old associations.

To Krebs, Kramer gave a fuller answer worth putting on the table. The SDK he built and sold years ago, he said, was designed to run only after the host app obtained user consent, and once software is licensed out, "the original developer has no control over how others later modify, rebrand, or deploy it." He denied registering the newer domains or operating the current infrastructure at all. That is the strongest innocent reading available: that later operators stripped out consent mechanics he says were there originally. Even so, the person forensic investigators tie to Popa's origins still holds two senior titles at Alarum today.

Who Benefits

Follow the money and it points one direction. NetNut is Alarum's core business and its fastest-growing line: the company reported first-quarter revenue up 64 percent year over year, to $11.7 million, and full-year 2025 revenue of $40.76 million. Alarum had spent since 2023 winding down its consumer VPN side specifically to lean into the proxy business. Before the seizure, Canaccord Genuity carried a price target around $27 to $28 a share, Wall Street pricing in more device enrollment, not less.

The mechanism is simple: a residential proxy network's only real asset is control over millions of home IP addresses, so more enrolled devices means more sellable inventory. Every consent screen you actually show is friction, a chance for the owner to say no and shrink that inventory. The forensic finding and the business model lock together: the version of the code that skips the prompt is the version that makes the number go up. That incentive shows up directly in the company's own revenue reports.

The reward has since run in reverse. Alarum's stock closed at $8.02 the day before the news and $6.35 the day after, then slid to about $2.62 within a week and under $2 by late July. The company disclosed cuts to roughly a third of its workforce and a multi-day pause of the network. By its July 22 filing, it reported two legal actions in Israel: a shareholder discovery motion and a securities class action against Alarum, its CEO and its CFO, seeking up to NIS 120 million on behalf of investors who bought shares between March 2022 and the day of the seizure. Every one of those actions is about money owed to shareholders, none about the person whose television was doing the work.

Why LG's Ban Stops Short

The bigger problem sits one level above NetNut. NetNut is one operator inside a large and ordinary industry. Spur Intelligence unpacked 6,038 LG and Samsung smart-TV apps and found residential proxy SDKs inside 2,058 of them, 34 percent overall, and 42.5 percent of the LG apps it scanned. Three vendors accounted for almost all of it: Bright Data, Massive, and Honeygain, a subsidiary of Oxylabs. Those vendors are NetNut's competitors rather than its suppliers, and Spur is explicit that its findings document an industry pattern, not proof that any of those apps route through NetNut. You don't need a hack or a federal seizure for a smart-TV app to quietly resell your bandwidth; that's an entire business category built around doing exactly that.

On July 22, LG said it would remove the proxy option from webOS apps and suspend the ones that don't comply. Read the fine print on the fix, though: it stops new enrollments and does nothing for the TVs already inside a network. Samsung, whose Tizen apps Spur also flagged, hadn't drawn the same line as of that reporting. Amazon and Roku already ban the category outright. And Google warns that when one proxy operator gets disrupted, the others simply "begin buying capacity from their competitors, effectively becoming a reseller," so the enrolled devices don't come home; they just change landlords.

This is the part no outlet covering the seizure flagged. There is no tool, anywhere, that lets an ordinary person check whether their own TV, box, or router is enrolled. The FBI's only consumer guidance on residential proxies, a March 2026 advisory that predates this case by months, offers no self-check, only a suggestion to file a complaint after the fact and a warning that a factory reset may not remove firmware-level code. Spur says outright that it does not provide consumer support. The scale is counted in millions, and the number of people who can confirm their own exposure is roughly zero.

The Bottom Line

Strip away the espionage angle and the FBI banner, and what's left is a publicly traded company that built a fast-growing revenue line on home devices enrolled through a consent screen its own code never displayed. The market rewarded it for exactly that, right up until the week it didn't. The lawsuits will sort out what shareholders lost, but the people whose connections actually ran the traffic aren't party to any of it and still have no way to check whether they're carrying it right now.

NetNut will probably survive its own bad month. The harder question is what a smart-TV owner is supposed to do with the knowledge that a screen asking their permission was written into the code and then shipped switched off, and that the only people with standing to be angry in a courtroom are the ones who owned the stock.