Invalid Traffic: Why Residential IPs Aren't Proof of a Human

Article Objective:
Help paid media and marketing ops teams understand why residential proxy traffic evades IP-based filters, and how to separate it from real visitors in their campaign data.
Estimated Read Time:

Two stories landed within ten days of each other this January. A new industry report put the cost of invalid traffic in paid media at $63 billion a year, and Google disrupted IPIDEA, one of the largest residential proxy networks in the world. Read together, they explain why a visitor with a home broadband IP address is not automatically a real prospect, and this article walks through what that means for your campaigns, your analytics and your filters.

What the $63B invalid traffic figure actually measures

On January 20, 2026, MediaPost reported on Lunio's Global Invalid Traffic Report 2026, which found that 8.51% of paid ad traffic was invalid. Lunio puts the resulting waste at $63 billion in global ad spend, or nearly one in every twelve clicks with no genuine purchase intent behind it.

The methodology matters. According to the full Lunio report, the data covers 2.7 billion clicks between August 1, 2024 and July 31, 2025, across Google, Meta, Bing, TikTok, LinkedIn and X, in eight industries and ten countries. It was collected in monitor-only mode, meaning protection was switched off and the figures reflect unfiltered exposure. Lunio defines invalid traffic (IVT) as any click, conversion or website event that does not come from a genuine user with real intent.

A few findings stand out for anyone buying traffic:

  • Lead generation is hit harder. Lead-gen businesses saw invalid traffic rates 32.07% higher than transactional ecommerce. The report points to form-based conversion paths as the weak spot, because a bot that fills a form produces something that looks like a result.
  • Platform averages vary widely. Advanced Television's summary of the report lists TikTok at 24.2%, LinkedIn at 19.88%, X at 12.79%, Bing at 10.32%, Meta at 8.2% and Google Ads overall at 7.57%, with Google Search lowest at 5.21%.
  • Inventory type matters inside a single platform. Google Display averaged 12.02% and Video 20.62%, well above Search.
  • Industry spread is large. Gaming and iGaming averaged 18.49%, while retail sat at 6.03%, as reported by MediaPost.

The ANA's coverage of the report repeats the headline: an 8.5% average across channels and $63 billion lost. One thing the report does not do is break invalid traffic down by network type. That is where the second story comes in.

The IPIDEA takedown in plain terms

On January 28, 2026, the Google Threat Intelligence Group (GTIG) published its account of disrupting the IPIDEA residential proxy network. A residential proxy network routes a customer's traffic through IP addresses that internet service providers assign to homes and small businesses. To a website, the request looks like it came from someone's living room.

The numbers give a sense of scale. The Hacker News coverage of the takedown reported that IPIDEA advertised more than 6.1 million daily updated IP addresses and 69,000 new ones each day. GTIG identified more than 600 Android apps connecting to IPIDEA's command-and-control servers, 3,075 unique Windows binaries, and about 7,400 second-tier servers hosting the shared exit-node pool. It also linked a set of apparently separate brands to the same operators, including 922 Proxy, 360 Proxy, Luna Proxy, ABC Proxy, IP 2 World and the Galleon and Radish VPN apps.

How ordinary devices ended up in the pool

GTIG describes several ways consumer devices were enrolled as exit nodes:

  • App developers were paid per download to embed IPIDEA-controlled software development kits (SDKs) such as Castar SDK, Earn SDK, Hex SDK and Packet SDK.
  • Trojanized apps, including utilities, games and VPN apps, enrolled devices without the owner understanding what was happening.
  • Some uncertified Android TV boxes shipped with proxy payloads preloaded.
  • Some users installed the software knowingly after being promised payment for their spare bandwidth.

Google says its legal action, domain takedowns and Google Play Protect enforcement reduced the pool of devices available to the operators "by millions." It shared findings with Spur, Lumen's Black Lotus Labs and Cloudflare. In Google's consumer-facing post on the takedown, the company summarizes the problem simply: the network let criminals hijack people's home internet connections to carry out criminal activity.

Why advertisers should care

GTIG observed more than 550 threat groups using IPIDEA exit nodes in a single seven-day window in January 2026, and focuses on espionage and intrusion. But the same infrastructure is sold to anyone. Help Net Security's report on the disruption lists ad fraud among the uses, alongside credential stuffing, data scraping and ticket scalping. It also notes that US, Canadian and European IP addresses are considered especially desirable. Those are the geographies many advertisers target and pay the most for.

This is not a one-off. In March 2025, HUMAN's Satori team disclosed BADBOX 2.0, a botnet of more than one million off-brand Android devices. Its operators sold residential proxy access and also ran hidden ad fraud and click fraud schemes from the same devices, generating up to 5 billion fraudulent bid requests a week at peak.

Why residential proxies slip past IP reputation filters

Most basic traffic filters ask one question: where is this request coming from? A known data center or hosting provider is easy to flag, because real shoppers rarely browse from a cloud server. The industry's own standards reflect this. The Media Rating Council's invalid traffic standards addendum classes known invalid data-center traffic as general invalid traffic (GIVT), which can be caught with lists and routine checks.

Residential proxies defeat that question in three ways:

  1. The IP belongs to a real household. The address is assigned by a consumer internet service provider, so it passes an ISP-type or "is this a data center?" check.
  2. The same IP carries real and fake traffic. A family may be streaming and shopping on the same connection that a proxy customer is using to click ads. Blocking the address outright risks blocking a real person.
  3. Addresses rotate constantly. Trend Micro's research on residential proxies notes that attackers use pools of auto-rotating IP addresses to scale user impersonation and cost-effectively bypass many filters. It names ad fraud and click fraud among the main criminal uses.

The MRC puts this kind of activity in the harder category. Its list of sophisticated invalid traffic (SIVT) includes invalid proxy traffic and automated browsing from infected and hijacked devices, which require advanced analytics and multi-point corroboration to identify. A blocklist alone was never designed to catch it.

Residential is a network label, not a verdict

The practical lesson is that "residential" describes the network a request came through, not the person or program behind it. If your tools treat every residential IP as clean, you are giving a free pass to the exact traffic that proxy networks are built to supply. If they treat every proxy-like signal as fraud, you will block real customers, some of whom have no idea their smart TV box is an exit node.

That is why it helps to keep residential proxy traffic in its own bucket, separate from both clean human traffic and confirmed invalid traffic. A separate label lets you:

  • See how much of each campaign's traffic arrives through proxy infrastructure, rather than having it blended into your "real users" baseline.
  • Compare its behavior against clean sessions: time on page, scroll depth, form completion speed, return visits and downstream lead quality.
  • Decide how to treat it, whether that means blocking, excluding it from conversion data sent back to ad platforms, or simply monitoring it.

This mirrors a point we made about AI browsers showing up in analytics: a real browser on a real network can still be driven by software. Behavior over the whole session tells you more than the origin of one request.

What to check in your own traffic this quarter

You do not need a threat intelligence team to act on this. Start with these checks:

  1. Split your invalid traffic view by channel and placement. The Lunio figures show large gaps between Search, Display and Video. If your Display or Video partner placements convert at similar rates to Search but produce worse leads, look there first.
  2. Audit form submissions, not just clicks. Lead-gen accounts carry more exposure. Look for submissions completed in a few seconds, repeated patterns in names or emails, and leads your sales team cannot reach.
  3. Look beyond the IP address. For suspicious sessions, compare device, browser and behavioral signals. Many different IPs sharing an identical device profile and click path is a stronger signal than any single IP.
  4. Watch your high-value geographies closely. US, Canadian and European residential IPs are the most sought after by proxy operators, so do not assume in-geo traffic is safe.
  5. Keep your attribution data clean. If proxy traffic lands with valid UTM parameters and converts, it trains your bidding and budget decisions on fake outcomes. Separate it before it reaches your reporting and your ad platforms' conversion signals.
  6. Set a baseline now. Google's action reduced IPIDEA's pool, but GTIG itself expects the impact to spread across affiliated services through reseller agreements and shared device pools. A smaller pool is not the same as no pool. Record your current mix of traffic types so you can spot when it shifts.

For a broader primer on the schemes behind these numbers, see our guide to how ad fraud works.

How Ðeny separates residential proxy traffic from real visitors

Ðeny classifies traffic to your marketing site in real time, and Residential Proxy is its own category, reported separately from Clean, Good Bot, IVT and Out-of-Geo traffic. That gives you the split described above without having to build it yourself. Ðeny Bot Shield can then block the traffic you do not want, in real time, so it stops skewing your analytics.

Because Ðeny also keeps UTM attribution attached to each visit, you can see which campaigns and channels are sending proxy traffic and what share of their results it accounts for. That turns an industry-wide number like $63 billion into a figure for your own account. You can review the full feature set to see how the classification and reporting fit together.

Conclusion: trust behavior, not the address

The Lunio report shows how much paid traffic is invalid, and the IPIDEA takedown shows one of the reasons it is so hard to filter: millions of real household connections were for rent. A residential IP proves only that a request passed through someone's home network. Treat it as one signal among many, keep proxy traffic visible as its own category, and judge visitors by what they do on your site.

If you want to see how much of your own paid traffic is coming through residential proxies, request a Ðeny demo and we will walk through your traffic mix with you.

Receive better insights, in your inbox
Subscribe to Deny's insights & news.
Subscribe
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Start protecting your funnel today

Put Ðeny to work from day one, and your boss will thank you.

$79/month
Cancel anytime
Credit card required
Get Started