www.darkreading.com 22 Sept 2026, 21:12 UTC

80,000 Relays May Be Hiding Chinese Users of AI Models

80,000 Relays May Be Hiding Chinese Users of AI Models
CyberSIXT Evidence Panel Source marked as original reporting

TEAM Cymru has identified more than 80,000 relay servers that may be helping users in China access frontier AI models from providers including Anthropic, OpenAI, Google and xAI while concealing their identities and locations. The intermediary servers pool API keys or subscription accounts, then issue customers with their own credentials and route requests through the relay.

Providers therefore see the relay’s IP address and upstream account rather than the end user, weakening controls based on attribution, usage limits, abuse detection, regional availability and terms of service.

The researchers initially found 10,867 relay stations across 457 autonomous systems, later expanding the estimate after further investigation. In a cluster hosted by US virtual private-server providers, more than 4,000 IP addresses in China and Hong Kong connected to the relays. During eight days, those addresses sent about 14TB of data to the stations and received more than 7TB.

Traffic to Anthropic via 17 relays included 81GB uploaded and 1.4GB downloaded, a 58:1 ratio that Team Cymru said could be consistent with large-scale model-distillation efforts. However, the evidence does not prove that all users were attempting to clone models.

The report also highlighted the open-source Claude Relay Service and its successor, sub2api, which support shared gateways, user management, billing and prompt auditing. Sub2api had been forked more than 8,000 times on GitHub and its Telegram channel had nearly 7,000 subscribers, figures indicating widespread interest but not establishing how many users were acting maliciously.

View full article

Article by CyberSIXT