Skip to content
Logo
Are Free Proxies Safe? What 53 Million Exit Nodes Reveal

Are Free Proxies Safe? What 53 Million Exit Nodes Reveal

Every few weeks a free proxy list makes the rounds — a few thousand IP:port pairs, no signup, no card. It looks like a shortcut. It is one, but not the kind most people think.

The honest question is not "do free proxies work?" Some of them work, briefly. The question is what is paying for them, and in 2026 there is finally hard data on the answer.

The measurement: 53 million exit nodes, 55 days

Between 19 January and 15 March 2026, Bitsight's TRACE research team enumerated the infrastructure behind 30 residential proxy services selected specifically for weak know-your-customer verification. Across that 55-day window they catalogued 53,346,368 unique IPv4 addresses operating as exit nodes.

They then cross-referenced those addresses against devices actively beaconing to sinkholed command-and-control domains. The overlap:

  • 15.49% of distinct egress IPs (8,222,677) were simultaneously flagged for active malware infections
  • 12.78% (6,785,708) showed riskware activity

The researchers were explicit that these are strict lower bounds. The method only catches a device if it happens to beacon to a sinkholed domain inside a 24-hour window. The real proportion is higher — the question is by how much.

Named co-infections included Vo1d, Badbox, RootSTV/Pandoraspear, OpenCandy, Gamarue and m0vy. Several of these are families known for compromising Android TV boxes and cheap consumer routers — devices that sit on a residential connection, stay powered on, and whose owners will never notice the extra traffic.

Where free proxy supply actually comes from

Bitsight identified three recruitment mechanisms, and they are worth separating because they carry very different ethics:

  1. Voluntary proxyware. Someone installs an app that pays them a few dollars a month to share bandwidth. Informed, consensual, and the smallest slice of supply.
  2. Bundled SDKs. A free game, VPN or utility ships a proxy SDK. Technically disclosed somewhere in an EULA; practically, nobody knows.
  3. Unauthorised device compromise. Malware turns the device into an exit node without the owner's knowledge. Bitsight identified this as the dominant supply-chain method.

When a list is free, category three is doing most of the work. That is the actual transaction: you get an IP, and a stranger's compromised router carries your traffic.

What the operator can see

This part is widely misunderstood in both directions, so it is worth being precise.

A proxy terminates your connection and makes a new one to the target. For HTTPS, a plain forward proxy opens a CONNECT tunnel and passes encrypted bytes through — it cannot read the page contents. That protection is real, and it is why "free proxies steal your passwords" is an overstatement.

What the operator can do, without breaking any encryption:

  • Log every hostname you request, with timestamps — a complete browsing profile
  • See your real IP on one side and your destination on the other, linking the two
  • Inject content, ads or redirects into any plain http:// response
  • Attempt TLS downgrade, hoping your client falls back
  • Refuse, delay or corrupt specific destinations
  • Capture in full anything you send unencrypted

Academic work has found the same pattern independently. The Free Proxies Unmasked longitudinal study documented instability, vulnerable hosts and active content manipulation across free proxy services.

So: your bank login is probably not being read. Your complete browsing history, and the ability to tamper with anything unencrypted, is on the table.

The operational problems, before you even get to security

Even setting the malware question aside, free lists fail on the things production work depends on.

An IP that stays up for the length of your job. Nodes vanish mid-run, and the list is stale within hours of publication.

Predictable latency. You get whatever a stranger's home uplink happens to be doing right now.

A clean IP reputation. The address is shared with whatever else the malware on that device is doing.

The country you asked for. Free list geolocation is frequently mislabelled.

Someone to ask when it breaks. There is nobody.

That last one costs the most. When a job fails at 3am on a free proxy there is no failure you can diagnose and no one to escalate to — you just start again.

The IP reputation point matters more than it looks, too. Anti-bot systems score the network an address belongs to, not just the address itself. If your exit node shares an ASN and a subnet with active malware traffic, you inherit that reputation before your first request.

When a free proxy is genuinely fine

It would be dishonest to say never. A free proxy is a reasonable tool when all of these hold:

  • You are checking whether a page renders differently from another country, once
  • You are not logged into anything
  • You are not sending data you would mind a stranger keeping
  • Nothing depends on it succeeding

That is a real use case, and for it a free proxy is fine. It is just not the use case most people reach for one for.

The alternative is not "expensive"

The usual objection is cost. It is worth checking that assumption against what you actually need, because the gap between free and adequate is smaller than the gap between free and working.

If your work is stateless and the target is not aggressively defended — internal tools, uptime checks, most public APIs — datacenter proxies are fast, cheap and billed per IP. You do not need residential capacity for that, and paying for it is a common overspend.

If the target does fingerprint aggressively — retail, travel, social, ticketing — you want residential IPs that are sourced with consent rather than scraped out of a botnet. That is the whole distinction this article is about, and it is worth asking any provider directly. Ours is answered in how we source residential IPs.

If you need the same address to persist over days — account management, dashboards, anything the target ties to a known IP — that is ISP proxies, and no free list will ever give you it.

How to evaluate any provider, including us

Five questions. A provider that cannot answer them plainly is telling you something.

  1. Where do your residential IPs come from, and how is consent obtained? Vague answers here are the single biggest red flag.
  2. What do you log, and for how long? Ours is documented in what we log.
  3. What happens when I open a ticket at 3am?
  4. Can I test against my actual target before committing? A few hundred real requests tell you more than any specification sheet.
  5. How am I billed — per IP or per gigabyte — and which is cheaper for my volume? See how pricing works.

The short version

Free proxies are not free. In 2026 the measured price is that roughly one in six exit nodes in the weakly-verified segment is running on a device its owner did not knowingly volunteer — and that is the conservative floor, not the ceiling.

For a one-off geo check, that may not matter to you. For anything with an account, a deadline or a client attached to it, you are building on infrastructure that is unstable by design and compromised by supply chain.

If you want to test the difference against your own target rather than take our word for it, start with a plan sized to your workload or ask us what to use — we would rather point you at datacenter capacity you actually need than sell you residential you do not.

Sources

Post Quick Links

Jump straight to the section of the post you want to read:

    FAQ's

    About the author

    LimeProxies Editorial Team

    We are the engineers and support staff who run the LimeProxies network — the people who provision residential, datacenter, ISP and mobile capacity across 100+ countries and answer the tickets when something breaks. We write about what we see from that seat: why requests get blocked, how detection actually works, and what the numbers say rather than what marketing would prefer. Every claim that comes from research is linked to its primary source so you can check it yourself, and we will tell you when the honest answer is that you do not need what we sell.

    View all posts
    Icon NextPrevWeb Data Collection for AI in 2026: The Closing Web
    NextWeb Scraping With Proxies: The Complete Guide for 2026Icon Prev
    No credit card required · Cancel anytime

    Start scaling your operations today

    Join 5,000+ businesses using LimeProxies for competitive intelligence,
    data collection, and growth automation — at any scale.

    Setup in under 2 minutes
    99.9% uptime SLA
    24/7 dedicated support
    G2 CrowdTrustpilot