Stolen AI credentials feed growing LLM proxy economy
Team Cymru estimates more than 80,000 proxy servers hide stolen AI credentials and enable model distillation.
Team Cymru identified transfer-station proxies running Claude Relay Service and sub2api, later estimating more than 80,000 such servers. The relays authenticate customers locally but call frontier APIs with pools of stolen keys and subscriptions, with clusters tied to China and Hong Kong while many gateways sit on US VPS hosts. Palo Alto Networks, Okta, and Gambit Security separately documented token-jacking, including hundreds of valid Anthropic, OpenAI, Gemini, and other credentials harvested by infostealers and phishing. NSA, CISA, and FBI recently accused six China-based AI companies of industrial-scale distillation of US models through similar stations.