Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

> That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home

That is not enough. You need to air gap devices that have legitimately no business communicating with anyone or anything outside the house. TVs, thermostats, and other Internet-of-Crap gadgets do not need "firmware updates." Either they work out of the box, offline or within the LAN, or they get sent back for a refund wherever they came from.

I don't think this would make a big difference for the threat model described in the OP? They'd still be able to use your IP Address and potentially do nefarious things through your role as an unwitting proxy.

Using one device as a proxy is a few steps away from trying to exploit and infiltrate the other devices on your machine as well. An unwitting proxy is already crossing the line to putting a fox in the henhouse.

Limiting what outbound access devices can/can't have is an important skill to learn.