Team Cymru tracks 80,000+ AI relay servers tied to China-based region-ban evasion, stolen credentials and model distillation
Team Cymru estimates more than 80,000 relay servers running sub2api and Claude Relay Service help users in China bypass U.S. AI model region bans, using pooled and reportedly stolen credentials in ways researchers and U.S. agencies link to industrial-scale…
Team Cymru researchers have uncovered a vast ecosystem of 'transfer station' relay servers that help users in China bypass geographic restrictions on U.S. frontier AI models. The relays run open-source tools including sub2api and Claude Relay Service; researchers first identified 10,867 such servers before raising the estimate to more than 80,000. The relays authenticate customers locally while calling frontier model APIs with pooled AI accounts that hide user identities. The two reports differ in emphasis: Help Net Security (2026-09-23) describes pooled AI service accounts used in violation of providers' terms of service for activities such as model distillation, while CSO Online (2026-09-28) reports the relays call the APIs with pools of stolen keys and subscriptions, with clusters tied to China and Hong Kong even though many gateways sit on US VPS hosts. Traffic data underscores the scale: more than 4,000 China and Hong Kong IP addresses hit 304 US-hosted relays, moving about 14TB of data, and seventeen Anthropic relays uploaded about 81GB while receiving 1.4GB - a 58-to-1 ratio consistent with distillation. Separately, Palo Alto Networks, Okta, and Gambit Security documented token-jacking in which infostealers and phishing harvested hundreds of valid credentials spanning Anthropic, OpenAI, Gemini, Groq, OpenRouter, xAI, and AWS. The findings corroborate a joint advisory from NSA, CISA, and FBI: Help Net Security characterizes it as a warning about large-scale Chinese AI distillation campaigns, while CSO Online reports the agencies accused six China-based AI companies of industrial-scale distillation of U.S. models through similar stations.
- Team Cymru first identified 10,867 Claude Relay Service and sub2api servers; the estimate now exceeds 80,000 relay servers.
- The relays run the open-source tools sub2api and Claude Relay Service.
- The relays authenticate customers locally but call frontier AI APIs with pooled accounts; CSO Online reports the keys and subscriptions are stolen, while Help Net Security describes pooled AI service accounts - the sources differ on…
- More than 4,000 China and Hong Kong IP addresses hit 304 US-hosted relays, moving about 14TB of data.
- Seventeen Anthropic relays uploaded about 81GB and received 1.4GB, a 58-to-1 upload-to-download ratio.
- Stolen credentials included Anthropic, OpenAI, Gemini, Groq, OpenRouter, xAI, and AWS; Palo Alto Networks, Okta, and Gambit Security separately documented token-jacking with hundreds of valid credentials harvested by infostealers and…
- The activity violates AI providers' terms of service, per Help Net Security.
- NSA, CISA, and FBI issued a joint advisory; CSO Online reports the agencies accused six China-based AI companies of industrial-scale distillation of U.S. models through similar stations, while Help Net Security frames it as a warning about…
Coverage timelineoldest first · each row is one article
- · 6d ago80,000 relay servers help users in China slip past U.S. AI region bans
Help Net Security· 70
Over 80,000 relay servers enable users in China to bypass region bans on U.S. AI models, facilitating potential model distillation and abuse.
- · 1d agoStolen AI credentials feed growing LLM proxy economy
CSO Online· 74
Team Cymru estimates more than 80,000 proxy servers hide stolen AI credentials and enable model distillation.