Team Cymru identified an ecosystem of AI relay services that lets users in China access U.S. large-language-model providers despite regional restrictions. The researchers initially confirmed 10,867 relay servers and later estimated that the network exceeds 80,000 servers. The services pool accounts held with Western AI providers, distribute customer requests across models, and provide customers with their own API keys, obscuring the actual users’ identities and locations from the providers.
Most observed relays used the open-source Claude Relay Service or its successor, sub2api, published by a developer known as Wei-Shaw. Network traffic from a U.S.-hosted relay cluster showed substantial connections from China and Hong Kong and high outbound volumes to Anthropic’s API, potentially consistent with automated large-scale querying, though Team Cymru could not determine whether model distillation occurred. The routing infrastructure undermines attribution, metering, rate limits, abuse detection, geographic controls, and provider terms; Team Cymru has shared relay IP addresses with affected providers and plans to continue tracking the infrastructure.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Team Cymru found that a Beijing CHINANET host, which sent more than 19 GB to a sub2api relay node, separately accessed a U.S.-hosted medical-imaging data repository that purportedly required authenticated access. The firm said the activity remained under analysis.
Team Cymru shared the IP addresses of identified relay infrastructure with affected AI-model providers and said it would continue searching for newly deployed relay servers. The organization assessed that the architecture hinders enforcement of regional restrictions, attribution, metering, rate limiting, and abuse detection.
Team Cymru published its “Relaying to the Frontier” report describing Chinese model routers, or transfer stations, that relay access to Western AI models and separate credential-owning accounts from the actual users. The organization initially confirmed 10,867 relays and later estimated that the ecosystem exceeded 80,000 servers; most identified relays used Claude Relay Service or sub2api.
Over an eight-day period in late August, Team Cymru observed more than 4,000 addresses in China and Hong Kong connecting to 304 relays in a U.S.-hosted VPS cluster. The users uploaded about 14 TB and downloaded more than 7 TB; 17 relays sent traffic directly to Anthropic's API, with traffic patterns potentially consistent with automated large-scale querying.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcenetaskari.substack.com
Open sourceteam-cymru.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.