The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In September 2026, Team Cymru researchers discovered a vast network of over 80,000 AI relay servers enabling Chinese users to access frontier AI models from US companies including OpenAI, Anthropic, Google, and xAI while masking their identities and locations. The relay infrastructure allows systematic circumvention of geographic restrictions and terms of service, with evidence suggesting large-scale model distillation attempts. Over an eight-day period, Chinese IP addresses transmitted 14TB of data through relay stations, with particularly suspicious traffic to Anthropic showing a 58:1 upload-to-download ratio consistent with AI model cloning operations. This campaign leverages open-source software packages like Claude Relay Service and sub2api, distributed through GitHub and Telegram channels with thousands of subscribers, pointing to widespread adoption of these circumvention techniques.

This incident highlights the growing sophistication of AI intellectual property theft operations and the urgent need for enhanced detection capabilities as nation-state actors increasingly target frontier AI models for competitive advantage.

Why This Matters Now

The discovery of systematic AI model access circumvention comes amid escalating US-China AI competition and recent government accusations of Chinese AI companies attempting to clone US capabilities, demonstrating the urgent need for stronger AI access controls and monitoring.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Relay servers act as intermediaries that pool multiple AI account credentials and route user requests, masking the true identity and location of end users while breaking attribution controls that AI providers rely on for abuse detection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would constrain this AI relay attack by limiting cross-cloud lateral movement and controlling egress to frontier AI services. The segmented architecture would reduce the blast radius of compromised credentials and restrict unauthorized data flows between relay infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The deployment of relay server infrastructure would likely face constraints through workload isolation and identity-aware access controls that limit where unauthorized services can be established.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The pooling and sharing of API credentials across systems would likely be constrained through identity-scoped access policies that limit credential reuse and cross-service authentication.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The distributed operations across multiple autonomous systems would likely face reduced connectivity through east-west traffic controls that limit inter-workload communications and cross-provider network paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The operation of large-scale proxy networks would likely be constrained through multicloud visibility that identifies and limits unauthorized traffic routing patterns across different cloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The large-scale data transfers to external AI services would likely face volume and destination restrictions through egress policies that limit high-bandwidth flows to unauthorized or suspicious endpoints.

Impact (Mitigations)

While model distillation activities would face reduced scale due to constrained data flows, some intellectual property exposure would likely remain through any successful exfiltration that occurred before controls activated.

Impact at a Glance

Affected Business Functions

  • AI Model Development and Training
  • Intellectual Property Protection
  • API Access Control and Authentication
  • Geographic Compliance and Export Controls
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $50,000,000

Data Exposure

Systematic exfiltration of frontier AI model outputs from major providers including OpenAI, Anthropic, Google, and xAI. Over 14TB of data transferred through relay networks with evidence of large-scale model distillation attempts. Compromised AI training data, proprietary model responses, and intellectual property related to advanced AI capabilities. Access to cutting-edge LLM outputs being used to clone and reverse-engineer competitive AI models.

Recommended Actions

  • • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized AI model access and enforce least privilege principles across cloud workloads
  • • Deploy Egress Security & Policy Enforcement controls to monitor and restrict outbound traffic to AI services, including FQDN filtering for unauthorized AI endpoints
  • • Enable Multicloud Visibility & Control to detect anomalous traffic patterns and suspicious automation consistent with large-scale model distillation attempts
  • • Utilize Encrypted Traffic (HPE) capabilities to secure data in transit and prevent interception of AI model requests and responses
  • • Activate Threat Detection & Anomaly Response systems to baseline normal AI usage patterns and alert on covert relay tools and excessive data transfer ratios

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image