A massive network of over 80,000 relay servers is being used to mask Chinese access to US-based frontier AI models for the purpose of bypassing restrictions and potential model distillation.
TL;DR
A Team Cymru report reveals a sprawling network of 80,000 relay servers used to facilitate anonymous access to US frontier AI models from China. This infrastructure likely supports systematic model distillation efforts and allows users to circumvent regional access controls.
A recent investigation by Team Cymru has uncovered a massive-scale operation involving over 80,000 LLM relay servers designed to mask the identity and location of users accessing US frontier AI models. This network serves as an intermediary layer between end-users—primarily located in China and Hong Kong—and major AI providers such as OpenAI, Anthropic, Google, and xAI. By routing requests through these transfer stations, operators can pool multiple API credentials and subscription accounts into a single gateway, effectively breaking the ability of providers to perform accurate account attribution, usage metering, and regional enforcement.
The scale of the operation is significant, with researchers observing massive data transfers, including 14TB of uploaded data over an eight-day period. A particularly concerning finding involves a high upload-to-download ratio observed in traffic directed at Anthropic's API, which researchers suggest is consistent with large-scale model distillation. In this process, the outputs from highly capable frontier models are harvested to train smaller, less expensive models that mimic the original's performance.
The technical backbone of this network includes open-source software such as Claude Relay Service (CRS) and its successor, sub2api, developed by Wei-Shaw. These tools provide sophisticated features like user management, per-user billing, and prompt auditing, making them highly effective for commercialized proxy services. The sub2api project has seen significant traction on GitHub and Telegram, supported by a network of commercial sponsors providing everything from IP addresses to optimized AI traffic infrastructure. Ultimately, this infrastructure poses a direct threat to the security models of AI providers by enabling widespread fraud, credential theft, and the unauthorized cloning of proprietary AI capabilities.