What happened to NetNut
Domains held by the FBI since July 2026; netnut.io serves the seizure notice.
NetNut was not a small storefront. It was one of the largest residential networks in the industry, run by a public company, and after the IPIDEA takedown in early 2026 it became the default wholesale source for a whole tier of proxy brands. Then in June 2026 three security firms published the same finding: the pool was fed by the Popa botnet, at least two million cheap Android TV boxes and smart-TV apps carrying proxy SDKs their owners never knowingly agreed to. Two weeks later the FBI acted.
| Date | What happened |
|---|---|
| 19 June 2026 | Three security firms, Synthient among them, publish evidence tying NetNut's residential pool to the Popa botnet — at least two million smart TVs and streaming boxes running proxy SDKs with little or no owner consent. |
| 2 July 2026 | The FBI and IRS Criminal Investigation seize netnut.com and hundreds of related domains. Google's Threat Intelligence Group disables the Google accounts NetNut used for command-and-control and pulls apps that bundled its SDKs. Lumen and Shadowserver assist. |
| 3–4 July 2026 | Alarum Technologies (NASDAQ: ALAR), NetNut's parent, confirms the seizures and announces a temporary operational pause of certain network services. |
| 8 July 2026 | netnut.io, the main commercial domain, is moved to FBI name servers and starts serving the seizure banner. alarum.io follows. ALAR loses roughly two thirds of its value in a week. |
| September 2026 | netnut.io still returns “Seized by the Federal Bureau of Investigation”. No charges or named defendants have been made public; a seizure is not a conviction. Alarum says it is cooperating. |
Why your NetNut proxies, dashboard and API stopped working
Everything NetNut sold was addressed through its domains: the customer dashboard, the REST API resellers provisioned from, and the gateway hostnames in millions of tool configs. When those domains moved to FBI name servers, all of it stopped resolving at once. Reinstalling, rotating credentials or waiting for “maintenance” will not help; there is no backend on the other end to reach.
Google reported it has high confidence many popular residential proxy brands were white-labelling the NetNut botnet. That is why a lot of people who never heard of NetNut watched their proxies die in the first week of July. If your provider's pool shrank, success rates collapsed or sticky sessions stopped holding between 2 and 8 July 2026, you were on NetNut whether the invoice said so or not.
Balances, refunds and accounts
Here NetNut differs from the storefronts that vanished with IPIDEA. Alarum Technologies is a listed company with directors, lawyers and shareholders who have already started legal proceedings against it. That does not guarantee you a refund, but it means there is someone to write to. Keep your invoices, email their legal contact, and if you paid by card ask your bank about a chargeback for services not delivered. Crypto payments are, as always, gone.
What you should not do is pay anyone who offers to “recover” a NetNut balance for a fee. That scam followed 911 S5, followed 922 and PIA S5, and it is following NetNut now.
Watch for “new NetNut” clones
“NetNut” is still a high-volume search, so look-alike domains appear: the old logo, a slightly different spelling, a registration date from last month, and a checkout that takes payment for proxies that never arrive. A network dismantled by the FBI does not come back on a week-old domain. Check the domain's age before paying anyone claiming to be NetNut relaunched.
Working NetNut alternatives in 2026
What NetNut customers actually bought was rotating residential access, billed per gigabyte, with country targeting, sticky sessions and SOCKS5, plus static residential and an API for resellers. Here is the like-for-like map:
| You used on NetNut | Replace with | Notes |
|---|---|---|
| Rotating residential, per GB | Rotating residential | From $0.70/GB, traffic does not expire monthly, $2 test gigabyte |
| Country / city targeting | Targeting in the credentials | 50+ verified countries, chosen in the panel, no ticket needed |
| Sticky sessions | Sticky lines up to 7 days | Set rotating or sticky per line; see the setup guide |
| Static residential (ISP) | Static ISP proxies | Same IP for the life of the plan |
| SOCKS5 endpoints | SOCKS5 and HTTP(S) on one login | Our SOCKS5 buyer guide covers the trade-offs |
| Reseller API | Reseller programme | Wholesale from 300 GB, provisioning by API |
How do you know we are not a NetNut white-label ourselves? We do not buy from NetNut or Alarum, and the lines we sell are answering today, months after the seizure, which the NetNut pool cannot do. But nobody can audit every hop of a supply chain, and you do not have to believe us: take the test gigabyte, run your real workload, look at the exits. We keep the $2 package specifically so nobody has to trust a proxy brand on its word again.
We have been here before
IP2World's own history is the cautionary tale. The old IP2World, 922 S5 and PIA S5 were three logos on one network, IPIDEA, and when that network was disrupted in early 2026 all three went dark on the same day. NetNut then soaked up the displaced demand, and six months later the same thing happened to it. The pattern is not “small providers are risky”; two of the three largest networks in the world are the ones that got seized. The pattern is single points of failure that customers could not see.
So: know whose network you are actually on, and ask in writing. Never leave a large prepaid balance sitting with anyone. Keep a second provider's credentials on file. And buy in amounts you would not mind losing until a pool has proven itself on your own targets. The current IP2World runs on infrastructure unrelated to IPIDEA and to NetNut, and we wrote up our own relaunch honestly for the same reason.