residential status being a prior not proof is really the crux here. IPinfo's jan 2026 study tracked something like 170 milions proxy IPs across over 100 networks, average visibility around 4,56 days, but that splits hard between 7.86 days for IPv4 and 1.29 for IPv6, which tracks since those pools rotate per session. i'd treat those numbers as one source with an obvious incentive to inflate the problem, though krebs, spur and nokia deepfield are all describing the same shared pools and churn independently. bigger issue is provenance, resale and whitelabeling make it almost impossible to verify who's actually running what, and GTIG's july report tying popular brands to netnut infrastructure behind a 2 million plus device botnet is the kind of thing that turns pool sourcing into a legal exposure question not just a technical one. worth noting precursor went GA in july too, and it's built on session scoped behavioral continuity feeding bot scores, so it's actually replacing cloudflare's js detections rather than the ASN or TLS fingerprinting angle you covered
residential status being a prior not proof is really the crux here. IPinfo's jan 2026 study tracked something like 170 milions proxy IPs across over 100 networks, average visibility around 4,56 days, but that splits hard between 7.86 days for IPv4 and 1.29 for IPv6, which tracks since those pools rotate per session. i'd treat those numbers as one source with an obvious incentive to inflate the problem, though krebs, spur and nokia deepfield are all describing the same shared pools and churn independently. bigger issue is provenance, resale and whitelabeling make it almost impossible to verify who's actually running what, and GTIG's july report tying popular brands to netnut infrastructure behind a 2 million plus device botnet is the kind of thing that turns pool sourcing into a legal exposure question not just a technical one. worth noting precursor went GA in july too, and it's built on session scoped behavioral continuity feeding bot scores, so it's actually replacing cloudflare's js detections rather than the ASN or TLS fingerprinting angle you covered