Skip to content

Build1 publisher3 min readPublished

Synthient wants residential proxy flags on IPs to carry a provider and a timestamp

Synthient says residential proxy traffic it observed in May 2026 touched about 9.2 million domains through household IPs that real users also share. Its answer is to timestamp each proxy sighting and set friction by what the session is trying to do.

The Engineer · Build desk

What happened

  • Synthient traces proxy supply to bandwidth-sharing apps, proxy SDKs buried in unrelated apps' terms, and compromised routers, Android TV boxes and phones.
  • Botnets keep probing Android Debug Bridge on port 5555 for poorly secured TV boxes, so a proxy endpoint can itself become the next target.
  • Synthient reserves outright blocking for cases where several high-confidence signals agree or the product explicitly prohibits anonymized traffic.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint A blocklist built from old proxy sightings mostly hits households, because the operator's pool has rotated away while the residents keep the address.
  • decision Fraud teams need a risk tier for every endpoint before a proxy signal is usable, since one sighting calls for logging on a browse page and step-up on a gift-card redemption.
  • exposure Owners of cheap Android TV boxes and routers face two risks: their devices can be enrolled as proxy exits, and the proxy path lets attackers probe services such as ADB inside the home.

Reputation feeds were designed for addresses that stay suspicious long enough to earn a score: hosting ranges, known VPN exits, scanners and repeat offenders, according to Synthient, which runs a proxy-tracking and honeypot platform called Helios [3][1]. Residential proxy addresses rotate, vanish, come back, and carry ordinary household traffic in between [3]. The exit sits on a real ISP's ASN and may geolocate correctly to the city [2]. With a large pool, an operator can change address after every request, and resellers can obscure which provider supplied the endpoint [16].

Synthient's fix is to stop treating the label as permanent. In a dev.to post, the company wrote that a proxy label on an IP address should be recorded as an observation with provenance and a time attached [8]. Before acting, it asks what kind of network the address sits on, which proxy, VPN, relay or reseller was seen using it, when that provider was last seen, whether the activity looked programmatic or botnet-related, and what the current session is doing [9]. Age changes the verdict. A sighting from five minutes ago can matter during a password reset. Six months later, the company wrote, it may be "little more than historical trivia" [10].

An IP-only block rule, in Synthient's account, collapses four facts into one label: who owns the network, who is using the connection, which proxy provider is on it, and who is making the current request [11]. Its replacement is, in the company's words, "deliberately boring: enrich first, then choose friction based on the action" [12]. Public browsing continues while the signal is logged. Signup, password reset, payment, gift-card redemption and promotional claims get more scrutiny. A recent proxy sighting combined with a new device, impossible travel or unusual account velocity triggers step-up authentication [13]. In my view this tradeoff is right for a consumer product with login and payment flows. The expensive checks land on the actions tied to credential stuffing, account takeover and promotion abuse [17], and a real resident flagged by mistake meets a prompt they can pass.

The traffic figures need the usual caution for vendor telemetry. The 9.2 million count covers unique domains and subdomains seen through Helios in May 2026 [1]. It measures breadth, and subdomains inflate it. The botnet shares, 41% media and 9.3% advertising, are also counts of targeted domains [5]. Together they cover about half of what that one botnet hit [1]. Neither figure says how many requests or how much fraud landed on each site. For the numbers to transfer to another company's risk model, Helios would need to see a representative slice of proxy traffic, and that botnet would need to resemble the operators hitting that company. Synthient says its policy catches more abuse without pretending every residential customer is suspicious [14]. The post does not describe Helios's sampling, the botnet's size, or a catch or false-positive rate for the policy.

The post ends, as vendor posts tend to, at the API. Synthient's v4 IP API returns network and location context with a risk score, behavioral categories, provider attribution and the last observation time for each provider [15].

What to watch

  • Catch and false-positive rates, from Synthient or a customer, comparing enrich-then-friction against IP-only blocking.
  • Independent proxy-tracking data that confirms or contradicts the 9.2 million domain count and the concentration on streaming and ad targets.
  • Growth in compromised Android TV boxes as a share of residential proxy supply, given continued probing of ADB on port 5555.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories