Relays Are Masking Chinese Access to Frontier AI Models in the US

A vast network of intermediary servers, known as relays, is allowing users in China to access cutting-edge artificial intelligence (AI) models in the US without revealing their identities and location. This practice, likely aimed at cloning or distilling these advanced AI capabilities, raises concerns about intellectual property theft and potential misuse.

Researchers from cybersecurity firm Team Cymru have identified over 80,000 LLM relay servers that act as intermediaries between users and AI providers such as Anthropic, OpenAI, Google, and xAI. These relays enable operators to pool credentials for multiple AI accounts and route user requests through the servers to frontier services. By doing so, they can obscure who is accessing models, evade potential geographic restrictions, and even share or resell credentials.

The proxies can undermine the controls that frontier AI providers rely on to detect and restrict misuse. Relay servers break the assumption that the account making a request belongs to the party consuming the answer. This allows users to bypass account attribution, usage metering, rate limits, abuse detection, regional availability, and terms of service enforcement.

Team Cymru’s analysis reveals high-volume Chinese traffic to OpenAI, Anthropic, and other AI providers. The company initially identified 10,867 transfer stations across 457 autonomous systems but updated the number to over 80,000 relays after further investigation. A cluster of relay servers hosted by US virtual private server providers was found to have more than 4,000 IP addresses in China and Hong Kong connecting to them.

The observed traffic suggests systematic attempts to use outputs from frontier AI models to create less capable versions at a significantly lower cost. The researchers noted an especially high volume of traffic going directly to an Anthropic API, with users uploading some 81GB of data over an eight-day period. This could be indicative of large-scale model distillation attempts.

The open-source software packages Claude Relay Service and sub2api have been identified as key components of this relay network. These tools allow for user management, billing, subscription conversion, and prompt auditing, and have gained widespread interest among developers. However, it is unclear how many people are actively using the software to access frontier AI models.

This development comes just days after the US government accused Chinese AI companies of attempting to clone US AI capabilities via systematic distillation campaigns. The discovery highlights the importance of monitoring and controlling access to advanced AI technologies, particularly when it involves sensitive intellectual property. It also underscores the need for AI providers to implement robust controls and detection mechanisms to prevent misuse.

For individuals and organizations using frontier AI models, this news serves as a reminder to be cautious about who has access to these powerful tools. By taking steps to secure their accounts and credentials, users can minimize the risk of being used as unwitting participants in large-scale model distillation attempts. Moreover, it is essential for AI providers to remain vigilant and adapt their controls to prevent misuse by relay servers and other proxy networks.


Source: Dark Reading — 2026-09-22