Cheap Gadgets Are Quietly Renting Out Your Home Wi-Fi

A digital photo frame and a small streaming box on a home shelf with power and network cables running behind them in dim light.

Five bargain devices off Amazon and Walmart. All of them were already wired to route someone else’s crime through your internet.

A WSJ investigation bought five cheap consumer gadgets and found every one quietly enrolled in a residential proxy network, letting strangers route crime through home Wi-Fi. The cause is hidden software baked into knockoff devices. The bill for all five came to under $800.

Picture this. You buy a digital photo frame to cycle through pictures of your kids. It sits on the shelf doing exactly that. Meanwhile, somewhere on the other side of the planet, a stranger is using your internet connection to run bank fraud, and to anyone tracing it, the trail stops at your front door.

What Happened

A reporter went shopping for a stress test. Two digital photo frames from Amazon, three “super boxes” from Walmart, all for less than $800. After plugging them in, he found the pre-installed software quietly connecting each device to a residential proxy server.

A residential proxy rents out your internet connection to third parties. They use it to mask activity like bank fraud, gambling, and access to illicit sites. Your IP address takes the blame for someone else’s behavior, and you never agreed to any of it.

Then it got worse. Hackers started hijacking the same devices for their own purposes.

The Backstory

Elliot Peterson, interviewed in the piece, walks through how law enforcement tries to identify victims and build evidence in cases like these. The hard part is obvious once you hear it. The “criminal” the data points to is usually just a person who bought a $40 gadget and has no idea their network is being sublet.

The core problem is consent. Without the device owner agreeing to share their connection, there is no legitimate reason for this to be happening at all.

The Plan

To prove what the devices were actually doing, Comcast’s team dropped them inside a Faraday cage to isolate the signals from everything else. The findings were not subtle.

The devices were running denial-of-service attacks (DDoS) and repeatedly trying to break directly into the hardware controls. This was not theoretical risk. It was live, observable misbehavior captured in a shielded room.

The scale is the scary part. Estimates put infected devices worldwide somewhere between tens and hundreds of millions. Those access points get pooled for large operations, including crimes between nations and state-sponsored attacks.

The Business Model Angle

Here is the part founders should sit with. There is a real, scaled business model hiding underneath this story, and it is not the photo frame.

Residential proxy networks are a legitimate industry. Companies pay good money for residential IP addresses to do market research, price monitoring, ad verification, and cybersecurity work. We have written about how businesses use proxies for competitive intelligence and data security before, and that demand is genuine.

The pattern is the oldest one in tech. When the hardware is suspiciously cheap, you are not the customer. You are the inventory. Bandwidth has quietly become the new data exhaust, a resource that gets harvested and resold while you think you bought a finished product. The device is a loss leader. The recurring value is your IP address, and you are paying the electricity bill to keep it online.

Cheap, connected, and “free” almost always means the monetization moved somewhere you cannot see it.

The Risk

Now the honest counterweight, because the BMA take is not “panic and unplug everything.”

Not every budget gadget is compromised. The legitimate residential proxy business runs on actual user consent, where people opt in to share idle bandwidth for a perk. The shady version skips that step. The infection numbers, tens to hundreds of millions, are estimates, not a counted figure, and your personal odds depend heavily on what you buy and from whom.

The real takeaway is sharper than fear. Treat a no-name connected device the same way you would treat a free app that wants every permission. Cheap hardware with an internet connection is a business decision someone made about you, and it pays to ask who is collecting on it.

Quick Questions

Can a cheap photo frame really be used for crime?

Yes. The investigation found pre-installed software linking bargain devices to residential proxy servers, which route third-party traffic through your connection without your consent.

What is a residential proxy in plain English?

It is a way for someone to borrow your home internet connection so their activity looks like it came from your house instead of theirs.

How do I know if one of my devices is doing this?

The story does not hand you a checklist, but the red flags are knockoff brands, suspiciously low prices, and software that wants to “phone home” the moment you plug it in.

Why would anyone want to hijack a photo frame?

Scale. Pool tens or hundreds of millions of cheap devices and you have a massive, hard-to-trace network for fraud, DDoS attacks, and even state-sponsored operations.

The Business Model Analyst Take

The lesson for founders is not really about photo frames. It is about where value hides. Someone built a business where the product on the shelf is the bait and your bandwidth is the revenue, all without your knowledge or consent. That is a monetization model, just an ugly one. The operators who win the next decade will be the ones who can spot what is actually being sold in any “cheap” or “free” offer, and who make sure that when they build the next great connected product, the value exchange is one their customers would actually agree to in daylight.

UNLOCK THIS FREE DOWNLOAD

DOWNLOAD NOW

Fill Your E-mail to Receive this Download Directly in Your Inbox.

RECEIVE OUR UPDATES

The Biz Model Club

Get daily, no-fluff insights on the latest business models, startup strategies, and trends delivered straight to your inbox.