๐ช TI-2026-026D โ The IP Marketplace: How IPXO Became the Amazon of Bulletproof Hosting
Executive Summary: IPXO UAB โ a Lithuanian IP address marketplace managing 14 million+ IPv4 addresses with $55 million in annual revenue โ sits at the center of the infrastructure we've been tracing. Its co-founder Vincentas Grinius routes ARIN blocks through both bulletproof ASNs (PIO-Hosting and HBING) via a single RIPE maintainer object. He simultaneously serves on the RIPE NCC Anti-Abuse Working Group. This is the story of how a legitimate marketplace became the plumbing for bulletproof hosting โ and how academic researchers noticed before regulators did.
Chapter 1: Portrait of a Marketplace
IPXO UAB (company code 307097001) is registered in Kaunas, Lithuania. It presents itself as a legitimate IP address marketplace โ the "Airbnb of IP addresses" โ where organizations with unused IPv4 blocks can lease them to those who need them.
The company operates through a constellation of entities:
| Entity | Jurisdiction | Role |
|---|---|---|
| IPXO UAB | Kaunas, Lithuania (#307097001) | Platform operator, headquarters |
| IPXO LLC | Austin, Texas, USA | US sales and marketing |
| Internet Utilities Europe and Asia Ltd | London, UK (#12540160) | RIPE LIR, European transit |
| Internet Utilities NA LLC | Wilmington, Delaware, USA | ARIN resources, Americas transit |
| Formerly: HEFICED / Digital Energy Technologies | Various | Pre-rebrand name (still in RDAP) |
Co-founder Vincentas Grinius lists his address as 6th Floor, 9 Appold Street, London EC2A 2AP โ a WeWork-style serviced office near Liverpool Street station. This is the contact address in RIPE and ARIN RDAP records for Internet Utilities.
The scale is significant: 14 million+ IPv4 addresses under management, $55 million revenue, presence in all five RIR regions. IPXO is not a back-alley operation. It's an industry.
Chapter 2: The netutils-mnt Proof โ One Object, Two Bulletproof Networks
In the RIPE database, a maintainer object (mnt-by) is the key that controls routing records. Whoever holds the mnt can update route objects โ deciding which ASN announces which prefix.
netutils-mnt is the maintainer for Internet Utilities / IPXO's prefixes. It controls:
| Prefix | Routed Via | Origin |
|---|---|---|
| 66.92.164.0/24 | AS198584 (PIO-Hosting, DE) | ARIN โ Internet Utilities NA LLC |
| 72.9.233.0/24 | AS198584 (PIO-Hosting, DE) | ARIN โ Internet Utilities NA LLC |
| 185.114.146.0/23 | AS208949 (HBING, UK) | RIPE โ Internet Utilities EU |
| 102.129.200.0/24 | AS208949 (HBING, UK) | AFRINIC โ HEFICED/IPXO |
| 102.165.51.0/24 | AS208949 (HBING, UK) | AFRINIC โ netutils-mnt |
The same maintainer. The same person (Grinius). Routing through both bulletproof ASNs.
This is not speculation or inference โ it's a direct, verifiable record in the RIPE database. Anyone can query whois -h whois.ripe.net netutils-mnt and see the connection.
โ Could IPXO/Internet Utilities be an innocent victim whose leased IPs ended up on bad networks?
No. The route objects (pointing IPs to specific ASNs) are controlled by netutils-mnt โ which is IPXO's own maintainer. They chose to route through AS198584 and AS208949. They didn't lose control of their blocks; they specifically configured them to announce from bulletproof infrastructure. The administrative contact on these objects is Vincentas Grinius himself.
Chapter 3: African IP Space on European Bulletproof Hosting
Two AFRINIC blocks (102.129.200.0/24 and 102.165.51.0/24) โ space allocated for African internet users โ are routed through HBING's AS208949, a UK-registered ASN whose infrastructure sits in Frankfurt, Germany.
The geographic discrepancy is extreme:
| Layer | 102.129.200.117 |
|---|---|
| Geolocation (MaxMind) | Netherlands ๐ณ๐ฑ |
| BGP Prefix Registry | South Africa ๐ฟ๐ฆ (AFRINIC) |
| RDAP Registrant | United States ๐บ๐ธ (IPXO) |
| ASN Registration | United Kingdom ๐ฌ๐ง (HBING) |
| Physical Infrastructure | Germany ๐ฉ๐ช (Frankfurt) |
Five countries for one IP address. This is the "phantom" pattern that triggered our investigation. When every source gives a different country, it means the IP has been routed through enough layers of indirection to confuse all automated classification systems.
The RDAP contact for these IPs lists "IPXO Incident Response Team" with support@ipxo.com. IPXO takes responsibility for abuse handling โ meaning they are the operational controller, not merely a marketplace platform that connects buyers and sellers.
๐ Read Between the Lines
- AFRINIC has been in crisis since 2021 โ its CEO was arrested for IP space fraud. The registry's oversight capacity is near zero. This is precisely when you exploit that registry for address space.
- African IP space has one advantage: it's rarely in European blocklists. Spamhaus, SORBS, and regional abuse-reporting systems focus on RIPE/ARIN space. AFRINIC blocks fly under the radar โ until they're used from European servers.
- If IPXO is the "RDAP contact" for abuse, and they route these IPs through a bulletproof ASN, then IPXO is the abuse-handling entity for a network that by design ignores abuse complaints. The incident response team's job is to respond to incidents by... not responding.
Chapter 4: The Academic Warning โ "Sublet Your Subnet"
In 2024, researchers at CAIDA (University of California, San Diego) published a paper at the ACM Internet Measurement Conference: "Sublet Your Subnet: Inferring IP Leasing in the Wild."
The paper documents โ with academic rigor โ exactly what we're observing: IP leasing marketplaces (IPXO/HEFICED specifically named) enabling bulletproof hosting operations by:
- Providing constantly rotating IP space (making blocklisting ineffective)
- Obscuring the relationship between IP user and IP owner
- Creating jurisdictional complexity that defeats abuse-handling processes
- Enabling "reputation laundering" โ clean IPs for dirty operations
The researchers measured the scale: millions of IPs changing hands through these marketplaces, with significant portions ending up in malicious campaigns. They noted that existing RIPE/ARIN transfer policies were designed for permanent sales, not for the dynamic leasing model that IPXO pioneered.
In essence: the regulatory framework hasn't caught up with the business model. IPXO operates in the gap between what's technically permitted and what's ethically defensible.
โ Does academic documentation of the problem create legal liability for IPXO?
It establishes knowledge. After a peer-reviewed paper at a major conference explicitly names your platform as an abuse enabler, claiming "we didn't know our infrastructure was being used for bulletproof hosting" becomes significantly harder. In tort law, this is the difference between negligence and willful blindness. In regulatory terms, it shifts from "we need better policies" to "we were told and didn't act."
Chapter 5: The Fox Guarding the Henhouse โ RIPE Anti-Abuse Committee
Vincentas Grinius โ whose Internet Utilities entities route blocks through two bulletproof ASNs โ participates in the RIPE NCC Anti-Abuse Working Group.
This working group develops policy for handling abuse on RIPE-allocated resources. Its recommendations directly influence how RIPE responds to complaints about... networks like PIO-Hosting and HBING.
The conflict of interest is structural:
- RIPE's anti-abuse policies determine when an LIR can lose its resources
- Stricter policies would directly threaten IPXO's business model
- Grinius votes on these policies while his company routes through the exact networks those policies should target
This is regulatory capture โ not the subtle, lobbying-over-decades kind, but the direct kind where the regulated entity sits on the regulatory body.
โ Is this unusual in internet governance? Don't all industry players participate in standards bodies?
Industry participation is normal and expected. What's not normal is participating in abuse policy while your infrastructure is classified as bulletproof by every threat intelligence platform. Cloudflare sits on standards bodies but doesn't route through networks with 95/100 risk scores. AWS participates in policy but doesn't have academics publishing papers about their role in enabling bulletproof hosting. The distinction is between "industry input" and "the arsonist writing fire codes."
Chapter 6: The Economics โ $55 Million in Revenue From What, Exactly?
IPXO's stated business: matching organizations with unused IPv4 space to those who need it, taking a commission. Legitimate use cases exist โ temporary projects, testing, CDN expansion.
But the economics tell a different story. IPv4 addresses cost $35-45 each to buy outright. IPXO's lease rates are approximately $0.50-2.00/IP/month. For a $55M annual revenue at those rates, IPXO manages somewhere between 2.3 million and 9.2 million actively leased IPs per month.
Who needs millions of IPs on a temporary basis?
| Use Case | IP Needs | Duration |
|---|---|---|
| Legitimate CDN scaling | Hundreds to low thousands | Months-years |
| VPN providers | Thousands | Semi-permanent |
| Spam operations | Tens of thousands (rotating) | Days-weeks |
| Bulletproof hosting | Thousands (burn and replace) | Weeks-months |
| Scanning campaigns | Hundreds per campaign | Days |
The legitimate use cases (CDN, VPN) account for thousands, not millions. The illicit use cases require exactly what IPXO provides: scale and rotation.
This doesn't mean all of IPXO's revenue is illicit. It means that the business model โ particularly at the $55M revenue scale โ mathematically requires either extremely large legitimate customers (who would typically buy rather than lease) or a significant volume of short-term leases to entities that burn through IP reputation.
๐ Read Between the Lines
- IPXO's rebrand from HEFICED occurred in 2021, exactly when abuse researchers began documenting the platform's role. Rebrands erase Google history. The old HEFICED abuse complaints no longer link to IPXO in search results.
- The corporate structure (Lithuania + Texas + UK + Delaware) isn't necessary for a simple marketplace. It's necessary for tax optimization, jurisdictional complexity, and ensuring no single regulator has full visibility of the operation.
- $55M revenue with no PeeringDB presence for its transit entities, no published abuse statistics, no transparency report. Compare this to Cloudflare, AWS, or any legitimate infrastructure provider at similar scale โ all publish detailed transparency reports.
Chapter 7: What's Running on IPXO's Bulletproof Leases
Our passive DNS enrichment reveals what actually runs on the IPXO-controlled IPs routing through HBING:
| Domain Pattern | Purpose | IPs |
|---|---|---|
client.nodomain.vip | Disposable VPN/proxy endpoint | 102.129.200.x |
mag-tv.net | IPTV piracy infrastructure | 102.129.200.x |
vodnew.nodomain.vip | Video-on-demand piracy | 102.129.200.x |
s120.likea8bitboss.xyz | Gaming bot/cheat infrastructure | 45.148.145.x |
*.staticdns1.io | Dynamic DNS โ C2 indicator | Various |
The nodomain.vip pattern is particularly telling โ it's a throwaway TLD used for infrastructure that doesn't need a memorable name. Legitimate services need brands. Botnets and proxy networks need addresses.
IPTV piracy (mag-tv.net, vodnew) is a multi-billion dollar industry that requires bulletproof hosting โ content owners issue thousands of takedowns daily. Normal hosting providers comply. Bulletproof providers don't.
Chapter 8: The Marketplace Defense โ "We're Just a Platform"
IPXO's likely defense: "We're a marketplace. We connect IP holders with IP users. We can't control what people do with leased addresses."
This is the "we're just a platform" defense โ familiar from Uber ("we're not a taxi company"), Airbnb ("we're not a hotel"), and every tech platform that wants the revenue without the responsibility.
But the defense fails here for specific, documented reasons:
- IPXO controls the routing. netutils-mnt is their object. They decide which ASN announces their blocks. This is not a passive marketplace โ it's active infrastructure management.
- IPXO handles abuse. Their "Incident Response Team" is the RDAP contact. If you report abuse on 102.129.200.x, it goes to IPXO. They are legally the responsible party.
- IPXO chose the transit. They didn't end up on bulletproof ASNs by accident. They configured route objects to point specifically at AS198584 and AS208949 โ networks with documented abuse problems.
- Academic publication. After CAIDA's 2024 paper, the "we didn't know" defense is destroyed. They were publicly told their platform enables abuse.
A platform that controls routing, handles abuse reports, chooses its transit providers, and has been academically documented as an abuse enabler is not "just a platform." It's an infrastructure provider with full knowledge and control.
โ What would RIPE NCC need to do if they took this seriously?
RIPE's existing policy (ripe-716) allows deregistration of resources used for criminal activity. But enforcement requires (a) awareness and (b) political will. The awareness exists โ academic papers, Spamhaus listings, this investigation. The political will is compromised by the working group participation of the entities that would be affected. The circular protection is complete: the policy-making body includes the entity that would be sanctioned by its own policies.
Chapter 9: The Marketplace as Infrastructure
IPXO represents something new in the bulletproof hosting ecosystem: the legitimate-facing enabler.
Traditional bulletproof hosting (McColo, 3FN, CyberBunker) was brazenly criminal. They advertised "anything goes" and were eventually shut down by law enforcement.
IPXO's innovation is structural legitimacy:
- Registered in the EU (Lithuanian company)
- Participates in internet governance (RIPE Working Groups)
- Publishes corporate materials with glossy websites
- Claims compliance programs and abuse-handling teams
- Routes through bulletproof ASNs whose risk scores exceed 95/100
The old model: criminal hosting โ law enforcement โ shutdown.
The new model: legitimate marketplace โ policy participation โ structural protection โ bulletproof transit โ academic documentation โ nothing happens.
IPXO doesn't host the malware. It provides the addresses that the malware runs on, routed through networks that ignore abuse, while participating in the governance that should sanction those networks. Every layer is one step removed from the crime, yet the crime requires every layer to function.
๐ Series Navigation
โ 026A: The Phantom ASN (Overview) ยท โ 026B: The Bulletproof Archipelago (HBING) ยท โ 026C: The German Gray Zone (PIO-Hosting) ยท 026D: The IP Marketplace (IPXO) ยท 026E: The Offshore Chain โ ยท 026F: The Sanctions Question โ