Most free proxy lists are lists of open proxies. They come from a few places: servers whose owners left a proxy running without authentication, home routers and IoT devices that have been compromised and turned into relays, and honeypots run by people who want to see what others send through them.
Why they are risky
- Your traffic. On plain HTTP, the operator can read and change everything. On HTTPS they see every hostname you visit, and some will ask you to trust a certificate so they can see more; that is a man-in-the-middle setup.
- Reputation. Open proxies are scanned for constantly and land on blocklists quickly, so their reputation is poor and sites block them.
- Reliability. They appear and vanish within hours.
- Whose machine it is. Relaying through a compromised device uses someone else's connection without their consent.
Make sure yours is not open
Commercial proxies require credentials or an IP allowlist so they cannot become open proxies. If you run your own, test it from a machine that is not on its allowlist, with no credentials:
curl -s -o /dev/null -w '%{http_code}\n' -x http://HOST:PORT http://example.com/
A 407 means it asked for authentication. A 200 means anyone can use it, and they will, usually within days.
Common confusion
"Free" and "open" overlap but are not the same: some free proxies are run deliberately by services that make their money elsewhere, often from your data. Free proxies covers where the lists come from and how to test one safely if you must.