July 30, 2026
Stream and scheme
Read This Before You Buy That TV Streaming Stick
That cheap streaming stick might be spying, scamming, and roasting your Wi-Fi wallet
TLDR: Researchers say some H96 streaming sticks may secretly use owners’ internet connections and fake phone identities to run ad-click scams. Commenters were split between laughing at ad networks getting burned and fuming that a cheap TV gadget might be quietly selling out your home connection.
The real plot twist in this streaming-stick horror story isn’t just that some bargain TV gadgets may be secretly using your home internet for shady business — it’s that the comments instantly turned into a mix of rage, dark comedy, and “well… what did you expect?” Security researchers say certain H96 devices appear to pretend they’re mobile phones, then quietly click ads on fake, computer-written websites to make money for the people behind the scheme. In plain English: your cheap movie box might be moonlighting as a scammy little office worker while you’re trying to watch TV.
And the community? Oh, they had thoughts. One camp was furious that this looked like “actual malice” straight from the factory, not just sloppy design. Another delivered the most internet take imaginable: cheating ad companies is not exactly heartbreaking, but using my connection as a proxy is where the joke stops. That tension — “ad fraud, lol” versus “don’t you dare rent out my internet” — became the thread’s juiciest mini-drama.
Then came the side-eye for buyers of “unlimited streaming for a one-time fee,” with one commenter politely calling it a classic too-good-to-be-true trap. But the funniest hit landed on the report’s line about low-skill workers dragging code blocks around to build fake sites. One commenter fired back, “We’re called engineers brian.” Brutal. Between the scam allegations, the AI-generated website weirdness, and the memes about discount gadgets turning into cyber-gremlins, the crowd made one thing very clear: that cheap stick may cost more than the price tag suggests.
Key Points
- •Bitsight TRACE found that H96 streaming devices were used in an ad-fraud operation in addition to earlier-reported internet connection abuse risks.
- •Researcher Pedro Falé registered an expired command-and-telemetry domain and observed data from tens of thousands of H96 devices worldwide.
- •The devices identified themselves as mobile phones from brands such as Samsung, Vivo, Huawei, and Xiaomi rather than as Android TV boxes.
- •Bitsight linked two common apps on the devices to Zhejiang Fengwo IoT Technology, which operates under the Fengwo Group name.
- •Bitsight reported that the apps helped drive fake ad clicks to AI-generated websites and that operators used a Blockly-based system to assemble fraud routines and deploy them as JavaScript.