Do Residential Proxy Providers Resell the Same IPs?

By Serpent API Team · · 12 min read

Often, yes — and in at least one documented case, thirteen storefronts turned out to be one network. On 29 January 2026, Google's Threat Intelligence Group published the infrastructure behind a network it called IPIDEA and named thirteen separate consumer-facing brands running on it.

That is the clearest published answer to a question buyers have been asking for years: when I compare two providers' pool sizes, am I comparing two pools or one?

This post assembles every public measurement we could find, from a 2019 academic paper to a threat-intelligence write-up published this month. Each finding is attributed to whoever published it. We bought no plans and ran no tests for this piece — it is a reading of the public record, and it says so wherever that matters.

Snippet answer: Residential proxy pool overlap is common and, in several cases, documented. Google's Threat Intelligence Group found thirteen consumer proxy brands running on one shared network (29 January 2026) and later reported that "many popular residential proxy brands are in fact whitelabeling the NetNut botnet" (3 July 2026). IPinfo measured 170 million proxy IPs across 101 providers and reported that 46% appeared in two or more provider networks. Proxyway's 2026 market report concluded the market "supports only 10 to 15 companies with their own networks." Overlap in measurement data proves shared inventory; it does not by itself prove a reseller contract between any two named companies.

What "pool overlap" actually means

"The same IPs" hides three different claims, and mixing them up is how this topic gets people into trouble.

  1. Same address. The literal IP 203.0.113.7 is seen exiting through vendor A and through vendor B. This is what almost every published study measures.
  2. Same device. The same physical phone, router or set-top box is enrolled in both networks. Much harder to establish, because a home address is assigned to a connection, not stamped on a device.
  3. Same supplier. Vendor A buys wholesale capacity from vendor B, or both buy from vendor C. This is a commercial fact about contracts, and measurement data is only ever circumstantial evidence for it.

Peakhour put the distinction plainly on 3 August 2026: "An IP match is not a device match." Its argument is that public addresses "are assigned to connections, not permanently engraved on devices," so the same address appearing in two pools is consistent with several stories — one shared device, two different devices behind one household or carrier address, or ordinary address reassignment by the ISP.

Keep that ladder in mind for the rest of this post. Nearly all the numbers below are claim 1. The strongest evidence for claim 3 does not come from address sampling at all — it comes from investigators who took apart the infrastructure.

Nine published measurements, in one table

As far as we can tell, nobody has assembled these side by side. Every row is somebody else's finding, dated, with the sample it rests on and — the column that usually goes missing — what it actually establishes.

Published byDateSample / methodHeadline findingSupports which claim
Google Threat Intelligence Group29 Jan 2026Malware and infrastructure analysis; ~7,400 Tier-Two servers13 consumer proxy brands running on one shared networkSame supplier (operator-level)
Google Threat Intelligence Group, with the FBI and Lumen3 Jul 2026Disruption of a network of "at least 2 million devices""Many popular residential proxy brands are in fact whitelabeling the NetNut botnet"Same supplier (stated by investigator)
Bitsight (Valter Santos)7 May 2026Malware-family attribution across the IPIDEA brand setReports “strategic partnerships with the operators” of named malware families, and “deep affiliations” with the threat groups running themSame supplier
Lumen Black Lotus Labs2026 (page undated)Botnet telemetry, victim attribution via Spur"Most large providers develop their own botnets, while reselling bots from other providers to bolster their numbers"Same supplier
IPinfo (Tiago Martins, Fernanda Donnini)Jan 2026Subscribe-and-observe across 101 providers; 170M+ IPs over 90 days46% of proxy IPs seen in two or more provider networksSame address (largest sample)
Proxyway (Adam Dubois)31 Mar 2026~7M requests over one week, February 202638.21% of one vendor's 2,023,029 sampled IPs also appeared in a public IPIDEA datasetSame address
Layer3 Intel, reported by Peakhour3 Aug 2026Re-observation of NetNut addresses within 14 days of takedown78.81% of addresses seen in the final days reappeared through other networksSame address, over time
Proxyway Market Research 2026Mar–Apr 20263.6M requests over 21 days, plus vendor census"The market supports only 10 to 15 companies with their own networks"Market structure
Yang et al., ACM CCS 2022Sep 2022399 proxy services identified; 9,077,278 IPs96.70% of those IPs were absent from every public dataset of the dayMeasurement is incomplete

Two things fall out of reading it as a set. First, the evidence has got dramatically better in 2026 — six of the nine rows are from this year, and three of them come from investigators with infrastructure-level visibility rather than from sampling exit IPs. Second, every single row was published by somebody other than a proxy vendor's marketing department, which is not something you can say about pool-size claims.

Thirteen brand names, one network

This is the case that answers the headline question without any inference at all, because the finding is about operators rather than addresses.

In its 29 January 2026 report on disrupting the IPIDEA network, Google's Threat Intelligence Group named thirteen consumer-facing brands it attributed to the same operation: 360 Proxy, 922 Proxy, ABC Proxy, Cherry Proxy, Door VPN, Galleon VPN, IP 2 World, Ipidea, Luna Proxy, PIA S5 Proxy, PY Proxy, Radish VPN and Tab Proxy.

GTIG's own summary of the technical position is worth quoting exactly, because it is the difference between "these pools look similar" and "these pools are one pool":

"This indicates that despite different brand names and Tier One domains, the different SDKs in fact manage devices and proxy traffic through the same infrastructure."

Its analysis of the malware samples and the four named SDKs "found a single shared pool of Tier Two servers." GTIG also reported roughly 7,400 Tier-Two servers and, in one seven-day window, over 550 individually tracked threat groups routing through the exit nodes.

Bitsight's follow-up research, published 7 May 2026 by Valter Santos, described the same set of brands as a conglomerate and reported that the operators maintained affiliations with specific malware families rather than sourcing devices independently — and that after the disruption, infected devices were "simply shifted" onto other wholesale proxy clients. If you want one sentence for why brand-level comparison is weak, that is it: the inventory survived the brand.

None of this says anything about the mainstream commercial vendors most scraping teams buy from. It does establish, at primary source, that a proxy brand is not automatically a proxy network.

46% of proxy IPs appear in more than one network

The largest measurement of address-level overlap we found is IPinfo's January 2026 analysis by Tiago Martins and Fernanda Donnini. IPinfo sells IP intelligence data, not proxies, and its method is stated openly: it subscribes to proxy services and actively connects through them, then records which addresses it sees.

Over a 90-day window it observed 170 million-plus residential proxy IPs (86M IPv4, 87M IPv6) across 101 providers. Its two headline numbers, as IPinfo reported them:

Those two findings pull in opposite directions and both are important. Heavy cross-provider presence says the pools are not independent. Extreme churn says any snapshot you take of a pool is mostly stale within a week — which is the practical reason a static "pool size" number in a pricing table tells you almost nothing about what you will get on any given day.

It is also why the reputation of an address is a moving target, and why two vendors quoting identical per-GB rates can behave completely differently on the same target. If you are budgeting rather than benchmarking, the gap between advertised and effective cost per GB is a separate trap worth reading first.

The 38.21% figure, and exactly whose finding it is

The most-quoted overlap number on this topic comes from Proxyway. It is a real, carefully documented measurement, and it is also the single easiest number in this field to repeat incorrectly — so here is the careful version.

Read this before you repeat the number. The domain Proxyway tested is smartproxy.org. That is not Decodo, the company that traded as Smartproxy on smartproxy.com before its 2024 rebrand. Decodo has publicly stated that smartproxy.org and smartproxy.cn are not affiliated with it. We make no claim about who operates those domains. Nothing in Proxyway's research concerns Decodo, and nothing in this post should be read as suggesting that Decodo resells anyone's addresses.

With that established: in research published on 31 March 2026, Adam Dubois routed roughly 7 million requests through that vendor over one week in early February 2026 and surfaced 2,023,029 unique IPs (2,019,488 IPv4 and 3,541 IPv6). He compared that set against Antoine Vastel's publicly released IPIDEA dataset of 16,192,293 addresses, published 29 January 2026, and found 773,087 addresses — 38.21% of the sample — present in both.

Proxyway's stated conclusion, verbatim:

"The most straightforward interpretation – Smartproxy.org either resells IPIDEA's infrastructure directly or sources a substantial portion of its IPs from the same network Google took action against in January 2026."

Note how carefully Proxyway itself hedged: either resells directly or sources from the same network. That is the right shape for this class of evidence, and we are reproducing it as Proxyway's finding against a third party's dataset. We did not inspect Vastel's dataset ourselves and cannot independently confirm either side of the comparison.

One more piece of context that gets dropped when this number travels: Proxyway discloses on its research pages that it uses affiliate links. That does not make the measurement wrong, and disclosing is better than not disclosing. It is simply a thing a reader should know, and the same caveat applies to nearly every "best provider" ranking you will find.

Reselling is a business model, not an accusation

It is easy to read all of this as scandal. It mostly is not. Wholesale capacity is a normal way to run a network business, and several operators say so themselves.

In its 3 July 2026 report on the disruption of NetNut — carried out with the FBI and Lumen, against a network Google estimated at "at least 2 million devices" — GTIG wrote:

"In addition to selling access to the network under the NetNut brand, NetNut has a robust reseller program that allows whitelabeling of its network. Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet."

Lumen's Black Lotus Labs describes the resulting graph in one line: "Most large providers develop their own botnets, while reselling bots from other providers to bolster their numbers." Lumen reports that one service it examined had "direct connections to at least NetNut, IPIDEA and IpMoYu," and that a disrupted service "found a way to survive" by reselling others. Its page carries no visible publication date, which is worth flagging when you cite it.

The clearest market-level statement comes from Proxyway's 2026 market report, built on 3.6 million requests over 21 days in March and April 2026:

"The market supports only 10 to 15 companies with their own networks. Even then, a half of them overlap to various extents due to sharing upstream sources."

Proxyway also counted "at least 56 companies that emerged between 2025 and March 2026" and found the newcomers selling residential capacity "were predominantly white labels." Read that against the number of brands you can find on any comparison page and the arithmetic answers the question on its own: there are far more storefronts than there are networks.

Where the inference stops

This is the section most write-ups on this topic skip, and it is the reason the topic is worth writing carefully.

Shared addresses are evidence of a shared upstream. They are not proof of a reseller contract. Peakhour's 3 August 2026 piece works through the alternatives: the same device may genuinely be in both networks; different devices may sit behind one household or carrier address; or the address may simply have been reassigned between observations. Address reappearance, in its framing, establishes inventory overlap and stops short of device identity, supplier ownership, device-owner consent, or the motive behind any request.

The same article reports a Layer3 Intel measurement that shows how fast inventory moves between networks: of the addresses seen through NetNut in its final day or two before the takedown, 78.81% reappeared through other networks within 14 days, with an estimated 1.06 million addresses leaving the wider ecosystem beyond ordinary churn.

There is a second limit, and it is a measurement problem rather than a logical one. Yang et al., "An Extensive Study of Residential Proxies in China" (ACM CCS 2022) identified 399 proxy services where prior work had catalogued 38, and collected 9,077,278 addresses of which 96.70% appeared in no publicly available dataset. Any overlap percentage is computed against whatever reference list the author could obtain, and every reference list is partial. A low overlap score can mean two independent pools, or it can mean your reference data was thin.

The academic record also complicates the "consenting home users" story that sits under the whole category. Huang et al. (2024) report that "many RESIP nodes are found to be located in corporate networks and are deployed without proper authorization," and the field's founding paper — Mi et al., "Resident Evil: Understanding Residential IP Proxy as a Dark Service," IEEE S&P 2019 — made the same argument seven years ago. That is a sourcing question, and it belongs in the same conversation as the ethics of how collection infrastructure is assembled and where the law currently sits on scraping.

Checking overlap yourself

None of the studies above published raw address lists, so nobody can replicate any of them exactly. You can still run a much smaller version against your own trials, and it takes an afternoon.

The method. Take two vendors you are seriously considering. On each trial, make a few thousand requests to an endpoint that echoes the calling IP, forcing a new session each time. Record the addresses. Then compare the two sets — but compare them twice, once on exact addresses and once on network blocks, because those two numbers can tell you very different things.

Here is a script that does it. It takes two plain text files of one address per line:

#!/usr/bin/env python3
"""pool_overlap.py - compare two lists of exit IPs collected from two vendors.

Usage:  python3 pool_overlap.py vendor_a.txt vendor_b.txt
Input:  one IPv4 address per line, blank lines and '#' comments ignored.
"""
import sys
from collections import Counter


def load(path):
    ips = set()
    with open(path) as fh:
        for line in fh:
            line = line.split("#", 1)[0].strip()
            if line:
                ips.add(line)
    return ips


def net24(ip):
    return ".".join(ip.split(".")[:3]) + ".0/24"


def report(name, a, b):
    inter = a & b
    union = a | b
    jaccard = len(inter) / len(union) if union else 0.0
    coverage = len(inter) / min(len(a), len(b)) if a and b else 0.0
    print(f"{name:>10}: A={len(a):>7}  B={len(b):>7}  shared={len(inter):>7} "
          f" Jaccard={jaccard:6.2%}  share-of-smaller={coverage:6.2%}")
    return inter


def main():
    if len(sys.argv) != 3:
        print(__doc__)
        return 2
    a, b = load(sys.argv[1]), load(sys.argv[2])
    report("exact IP", a, b)
    na, nb = {net24(i) for i in a}, {net24(i) for i in b}
    shared_nets = report("/24 block", na, nb)
    if shared_nets:
        counts = Counter(net24(i) for i in a | b if net24(i) in shared_nets)
        print("\ntop shared /24 blocks by observed addresses:")
        for net, n in counts.most_common(10):
            print(f"  {net:>18}  {n}")
    return 0


if __name__ == "__main__":
    sys.exit(main())

To show what the output looks like — and to make one point that the published studies do not — here it is run on synthetic data: two generated sets, 3,000 and 2,500 addresses, deliberately built so that 40 of each vendor's 100 network blocks are shared. This is not a measurement of any real vendor, and the addresses are from the reserved documentation ranges.

$ python3 pool_overlap.py vendor_a.txt vendor_b.txt
  exact IP: A=   3000  B=   2500  shared=    141  Jaccard= 2.63%  share-of-smaller= 5.64%
 /24 block: A=    100  B=    100  shared=     40  Jaccard=25.00%  share-of-smaller=40.00%

top shared /24 blocks by observed addresses:
       203.0.11.0/24  64
       203.0.28.0/24  61
       203.0.27.0/24  60

Same data, and the exact-address overlap reads 2.63% while the network-block overlap reads 25%. That gap is the whole reason a small self-run test is easy to misread. With IPinfo's measured average visible lifespan of 4.56 days, two independent samples of the same underlying pool will share very few literal addresses, so an exact-match score near zero is close to meaningless at small sample sizes. The network-block view survives churn far better, because the block stays put while the address inside it rotates.

Two honest caveats. A /24 is a crude stand-in for the real unit, which is the autonomous system; if you have access to an ASN dataset, group by ASN instead and the signal gets cleaner. And shared blocks at consumer ISPs are expected regardless of vendor relationships — a big residential ISP is a big residential ISP — so treat concentration in unusual networks as the interesting result, not raw block overlap. Check each vendor's terms before running any test like this; some prohibit enumeration of the pool.

What to do about it as a buyer

The practical consequences are smaller and more boring than the headlines suggest, which is usually a good sign that you are looking at the real ones.

One last note on our own position. We sell a search API, so we are not a disinterested party in a post about proxy infrastructure — we simply do not sell proxies or take affiliate commission from anyone named here. Every number above is somebody else's, linked, and dated.

Finally, a gap we could not close: a Reddit thread in r/ProxyEngineering titled "I audited the ASNs across 4 residential proxy providers" ranks on this query and is doing a version of the same work. We were unable to load it — Reddit is not readable by any tool available to us — so it is not cited or summarised anywhere above. If you can read it, read it; we would rather say that than paraphrase something we have not seen.

Need the search data, not the infrastructure

Serpent returns parsed Google, Brave, Yahoo and DuckDuckGo results over a plain HTTP call, billed per request. There is no bandwidth meter, no IP pool to size and nothing to benchmark before you start. 10 free searches, then from $0.60 per 1,000. See full pricing or the Google SERP API.

Get Your Free API Key

Explore: All SERP APIs · Docs

FAQ

Do different proxy providers use the same IPs?

Frequently, yes. IPinfo, which sells IP intelligence data rather than proxies, analysed more than 170 million residential proxy addresses across 101 providers over 90 days and reported in January 2026 that 46% of them appeared in two or more provider networks. Separately, Google's Threat Intelligence Group published on 29 January 2026 that thirteen consumer-facing proxy and VPN brands were running on a single shared network it called IPIDEA, and stated that despite different brand names the underlying SDKs managed traffic "through the same infrastructure." Address overlap between two vendors is evidence that they draw on shared inventory. It is not, on its own, proof that either one resells the other.

What is residential proxy pool overlap?

It is the share of addresses in one provider's pool that also appear in another provider's pool. It is usually measured by sampling exit addresses from both services over a fixed window and intersecting the two sets, and it is normally reported either as a percentage of the smaller set or as a Jaccard index over the union. The number is very sensitive to how long you sample for, because proxy addresses churn quickly: IPinfo measured an average visible lifespan of 4.56 days and found 60% of addresses appearing only once in 90 days. Comparing network blocks or autonomous systems rather than literal addresses gives a more stable reading at small sample sizes.

How many residential proxy providers actually own their network?

Proxyway's Proxy Market Research 2026, based on 3.6 million requests over 21 days in March and April 2026, concluded that the market "supports only 10 to 15 companies with their own networks" and that "even then, a half of them overlap to various extents due to sharing upstream sources." The same report counted at least 56 companies that emerged between 2025 and March 2026, and found that the new residential providers were "predominantly white labels." Proxyway discloses that it uses affiliate links, which is worth knowing when reading any of its rankings.

Does shared ASN data prove one provider resells another?

No. Shared autonomous systems or shared address blocks are evidence of a shared upstream, not proof of a commercial relationship between two named companies. Peakhour made the point plainly in August 2026: an IP match is not a device match, because public addresses are assigned to connections rather than fixed to hardware. The same address appearing in two pools is equally consistent with one device enrolled in both networks, two different devices behind the same household or carrier address, or ordinary reassignment by the ISP between observations. The strongest published evidence of shared supply does not come from address sampling at all; it comes from investigators such as Google Threat Intelligence Group and Lumen who examined the control infrastructure directly.

How can I check whether two proxy providers share a pool?

Run a small version of the published studies during your trials. Make a few thousand requests through each vendor to an endpoint that echoes the calling address, forcing a new session each time, and record what you see. Then intersect the two sets twice: once on exact addresses and once on network blocks or autonomous systems. Expect the two figures to diverge sharply, because churn destroys exact-address matches long before it destroys network-level ones. Treat concentration in unusual networks as the interesting signal, since shared presence at large consumer ISPs is expected regardless of any vendor relationship. Check each provider's terms first, as some prohibit enumerating the pool.

Related Posts