NetNut takedown data: 28% of seized IPs still live on Bright Data
Layer3 Intel measured the NetNut proxy takedown: most IPs reappeared elsewhere, and 28% remained reachable via Bright Data alone.
On July 2, 2026, the FBI, working with Google, Lumen, and Shadowserver, seized the domains behind NetNut, a major residential proxy provider linked to the Popa botnet, which enrolled over two million hijacked smart TVs and streaming devices as exit nodes. Layer3 Intel, which independently observes exit nodes across major residential proxy networks, tracked the shutdown in real time and measured its true impact on the underlying device inventory.
The network didn't vanish instantly; it drained over roughly 60 hours before falling more than 99.9%. Having attributed 63.7 million distinct IPv4 addresses to NetNut over four months, Layer3 compared how often IPs from its final 30-day cohort reappeared on other networks against a pre-takedown baseline that accounts for normal residential IP churn. The result: the takedown removed only about 1.06 million IPs from the ecosystem beyond what churn alone would explain, a small fraction of NetNut's footprint. The rest resurfaced elsewhere within two weeks.
The most notable finding: 27.85% of NetNut's IPs remained reachable through Bright Data alone, the industry's largest residential proxy provider, which markets itself on KYC verification and consent-based sourcing. Cross-network analysis showed that even excluding NetNut, a majority of Bright Data's own exit pool overlaps with other providers, indicating that resold device inventory circulates across supposedly walled-garden networks regardless of stated ethics policies.
For engineers, the takeaway is clear: infrastructure takedowns targeting proxy networks don't meaningfully shrink the underlying device pool, since the same hijacked or resold IPs simply reappear on competing networks, undermining IP-reputation-based blocklists.