How Offshore Casinos Bypass Geo-Blocking — VPNs, Residential Proxies, and Why It Barely Works
Regulators block 50,000 domains; 80% return within minutes. Inside the engineering of evasion — VPNs, residential and mobile proxies — and why the real brake isn't network blocking at all.
Every time a regulator takes down another batch of illegal betting domains, the pattern repeats within hours: the same site reappears under a nearly identical name, a fresh link circulates on Telegram, and traffic barely dips. This is not a failure of execution. It is the nature of a barrier that was never built to stop someone with a financial reason to cross it. And most of the tools used to breach that barrier are not harmless to the people whose devices end up powering them — a fact regulators worldwide are only now starting to reckon with.
Brazil as the test case for a global problem
Brazil offers the clearest recent example of what happens when a large market tries to wall itself off from unlicensed gambling — and the lessons apply anywhere offshore operators target a regulated jurisdiction, from Southeast Asia to Latin America to Europe.
Since January 1, 2025, betting in Brazil has been legal only on platforms licensed by the SPA (Secretaria de Prêmios e Apostas, under the Ministry of Finance). Foreign licenses — Curaçao, Malta, and others — are not recognized. To enforce this, Brazil passed "Lei Jungmann" (Law 15,358/2026) alongside Anatel Resolution 569/2026, mandating technical blocking at the DNS, IP, and SNI level, plus mirror-site detection. Roughly 50,000 domains have been notified or blocked under this framework.
Yet an estimated 80% of blocked platforms remain reachable, through redirect chains, Telegram-distributed links, and endless domain variations. Brazil has already seen how fast users route around a block: when the country blocked X (formerly Twitter) in 2024, VPN usage spiked 1,600% in a single day. Industry analysts have taken to calling domain-level enforcement "mopping up ice" — it melts back into place almost as fast as it's removed.
Geo-blocking: the first, easiest barrier to breach
The baseline defense most jurisdictions rely on is IP geolocation — services like Cloudflare or MaxMind map an IP address to a country and block accordingly. It's cheap and universal to deploy, which is exactly why it's also trivial to defeat: any consumer VPN or proxy service changes the apparent origin of a connection in seconds. And because the operator on the other end is already running an unlicensed platform, there is no legal deterrent stopping them from advertising workarounds directly to users.
VPN detection: works, but only up to a point
More sophisticated platforms don't stop at a single IP lookup. They build a confidence score from multiple signals: IP and ASN databases that flag known datacenter ranges (AWS, Hetzner, DigitalOcean) as infrastructure rather than residential traffic; DNS and WebRTC leaks that expose a user's real location despite the VPN; mismatches between claimed country and system timezone or language settings; and protocol fingerprinting that recognizes OpenVPN or WireGuard traffic patterns.
This works well against cheap, off-the-shelf datacenter VPNs, which get caught more than 90% of the time. But that success has simply pushed serious evaders toward a much harder target: residential and mobile proxies.
Residential and mobile proxies: the real hole in the wall
A residential proxy routes traffic through a real person's home internet connection rather than a datacenter server. That access is typically sourced in one of three ways:
SDK monetization — developers embed a proxy SDK (providers such as Castar, Pawns, or Packet) inside free mobile apps. Users unknowingly "share" their bandwidth and IP address, a consent buried deep in terms of service most people never read.
Malware and trojanized hardware — proxy software preinstalled on cheap Android TV boxes and other IoT devices, most notably through the BADBOX malware campaign.
"Earn from idle bandwidth" apps — services in the style of Honeygain that pay users a small amount to leave their connection available for third-party traffic.
The resulting architecture is straightforward: a client connects to the proxy provider's backconnect gateway, authenticates, and is routed through a residential node — a real device belonging to a real person inside the target country, for instance a laptop in São Paulo. From the gambling platform's perspective, the incoming connection is a legitimate residential IP address from a real ISP (Vivo, Claro, or equivalent), with normal reputation history, indistinguishable from an actual neighbor down the street. Country, city, and even mobile carrier can be selected on demand.
Mobile proxies push the problem further
Mobile proxies are harder still to block. Because of carrier-grade NAT (CGNAT), thousands of real phones can share a single public IPv4 address. Blocking that address would lock out thousands of legitimate paying customers on that carrier — commercially unworkable for any platform — so mobile traffic tends to get the benefit of the doubt by default. Rotation makes detection even less reliable: reconnecting to the network assigns a fresh carrier IP, and a single 4G modem can cycle through more than 100,000 IP addresses in under a second.
Consumer warning: your smart TV could be the exit node
These proxy networks are frequently built on botnets of hijacked consumer devices — a fact that should concern anyone outside the gambling industry too. Google's Threat Intelligence Group took down the IPIDEA network in January 2026: an estimated 6.1 million IP addresses active daily, roughly 5 million infected devices, recruited through more than 600 malicious Android apps and 3,075 Windows binaries, plus malware embedded in TV boxes via BADBOX 2.0. The network was reportedly used by more than 550 criminal groups for activity ranging from espionage to credential-stuffing attacks and DDoS campaigns.
John Hultquist of Google Threat Intelligence described residential proxy networks as having "become a pervasive tool for everything from high-end espionage to massive criminal schemes." The FBI issued a matching warning in 2026: ordinary home devices are being converted into tools for criminal infrastructure without their owners ever noticing.
The takeaway for consumers is blunt: the IP address someone uses to reach an illegal casino right now could belong to a smart TV or router sitting in a family's living room — a family with no idea their bandwidth is being resold.
The real final boss is KYC, not the network
Because IP address is no longer a reliable signal, detection at serious platforms has shifted toward behavior: behavioral biometrics (mouse movement, typing cadence), geo-velocity checks (impossible travel patterns, an ASN switching from residential to hosting mid-session), and device fingerprinting combined with link analysis to catch the same device, card, or email reused across multiple accounts.
But none of these network-layer defenses are the actual wall that stops determined evasion. That wall is KYC — identity verification requiring a government ID and proof of address. No residential proxy, however convincing, can fabricate a passport or a utility bill. That is where location fraud typically hits its real limit — not at the router, but at the document check.
Conclusion
Domain blocking on its own is mopping up ice: necessary, visible, and largely cosmetic against a determined and well-resourced adversary. The measures that actually constrain illegal offshore betting are financial and regulatory — payment-rail blocking (Pix and crypto on-ramps, enforced through central bank cooperation), rigorous KYC, and new liability frameworks that reach beyond the operator itself, such as Brazil's Ordinance MF 1,766/2026, which creates joint tax liability for intermediaries and promoters who route traffic to unlicensed sites.
For the everyday bettor, the practical risk is twofold: using an illegal platform carries no legal right to recover winnings, and running the wrong "free VPN" or bandwidth-sharing app carries a real chance of unknowingly lending your own device to a criminal network.
Related reading
- What Triggers KYC at Crypto Casinos? An Ex Pit Boss Explains
- Crypto Casino Won't Pay Out? 7 Withdrawal Traps and How to Get Your Money
- 13 Ways Crypto Casinos Scam You in 2026 — The Complete Taxonomy
Sources: Google Threat Intelligence (IPIDEA takedown, Jan 2026); FBI (residential proxy alert, 2026); Brazil Ministry of Finance / SPA (Ordinance MF 1,766/2026); Anatel (Resolution 569/2026, Law 15,358/2026 "Lei Jungmann").