Executive Summary
In September 2026, Team Cymru researchers discovered a vast network of over 80,000 AI relay servers enabling Chinese users to access frontier AI models from US companies including OpenAI, Anthropic, Google, and xAI while masking their identities and locations. The relay infrastructure allows systematic circumvention of geographic restrictions and terms of service, with evidence suggesting large-scale model distillation attempts. Over an eight-day period, Chinese IP addresses transmitted 14TB of data through relay stations, with particularly suspicious traffic to Anthropic showing a 58:1 upload-to-download ratio consistent with AI model cloning operations. This campaign leverages open-source software packages like Claude Relay Service and sub2api, distributed through GitHub and Telegram channels with thousands of subscribers, pointing to widespread adoption of these circumvention techniques.
This incident highlights the growing sophistication of AI intellectual property theft operations and the urgent need for enhanced detection capabilities as nation-state actors increasingly target frontier AI models for competitive advantage.
Why This Matters Now
The discovery of systematic AI model access circumvention comes amid escalating US-China AI competition and recent government accusations of Chinese AI companies attempting to clone US capabilities, demonstrating the urgent need for stronger AI access controls and monitoring.
Attack Path Analysis
Chinese actors leveraged AI relay servers to mask identities while accessing frontier AI models from US providers including OpenAI, Anthropic, Google, and xAI. The attackers established command and control through a network of over 80,000 relay servers across 457 autonomous systems, enabling systematic exfiltration of AI model outputs for distillation campaigns. High-volume traffic patterns (58:1 upload-to-download ratio) suggest large-scale model cloning operations to create unauthorized AI capabilities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers deployed AI relay server infrastructure using open source tools (Claude Relay Service, sub2api) to establish intermediary access points for frontier AI models
MITRE ATT&CK® Techniques
Proxy
Valid Accounts
Credentials from Password Stores
Phishing
Exfiltration Over Web Service
Exfiltration Over C2 Channel
Obfuscated Files or Information
Web Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Security Controls
Control ID: 1.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity.AM-6
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21.2.a
GDPR – Data Protection by Design and by Default
Control ID: Article 25
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
AI model intellectual property theft through relay networks enables unauthorized cloning, compromising competitive advantages and violating API terms of service agreements.
Information Technology/IT
Massive relay infrastructure undermines cloud security controls, enabling geographic restriction bypasses and credential sharing that defeats authentication and monitoring systems.
Government Administration
Nation-state actors using AI relay networks for systematic model distillation poses national security risks requiring enhanced export controls and monitoring.
Financial Services
Encrypted relay traffic masking data exfiltration threatens financial AI models and customer data, requiring enhanced egress filtering and zero-trust segmentation.
Sources
- Relays Are Masking Chinese Access to Frontier AI Models in the UShttps://www.darkreading.com/cyber-risk/relays-masking-chinese-access-frontier-ai-modelsVerified
- Team Cymru Research on AI Relay Networkshttps://team-cymru.com/research/Verified
- CISA Guidance on AI Securityhttps://www.cisa.gov/aiVerified
- OpenAI Security and Usage Policieshttps://openai.com/securityVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain this AI relay attack by limiting cross-cloud lateral movement and controlling egress to frontier AI services. The segmented architecture would reduce the blast radius of compromised credentials and restrict unauthorized data flows between relay infrastructure.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The deployment of relay server infrastructure would likely face constraints through workload isolation and identity-aware access controls that limit where unauthorized services can be established.
Control: Zero Trust Segmentation
Mitigation: The pooling and sharing of API credentials across systems would likely be constrained through identity-scoped access policies that limit credential reuse and cross-service authentication.
Control: East-West Traffic Security
Mitigation: The distributed operations across multiple autonomous systems would likely face reduced connectivity through east-west traffic controls that limit inter-workload communications and cross-provider network paths.
Control: Multicloud Visibility & Control
Mitigation: The operation of large-scale proxy networks would likely be constrained through multicloud visibility that identifies and limits unauthorized traffic routing patterns across different cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The large-scale data transfers to external AI services would likely face volume and destination restrictions through egress policies that limit high-bandwidth flows to unauthorized or suspicious endpoints.
While model distillation activities would face reduced scale due to constrained data flows, some intellectual property exposure would likely remain through any successful exfiltration that occurred before controls activated.
Impact at a Glance
Affected Business Functions
- AI Model Development and Training
- Intellectual Property Protection
- API Access Control and Authentication
- Geographic Compliance and Export Controls
Estimated downtime: N/A
Estimated loss: $50,000,000
Systematic exfiltration of frontier AI model outputs from major providers including OpenAI, Anthropic, Google, and xAI. Over 14TB of data transferred through relay networks with evidence of large-scale model distillation attempts. Compromised AI training data, proprietary model responses, and intellectual property related to advanced AI capabilities. Access to cutting-edge LLM outputs being used to clone and reverse-engineer competitive AI models.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent unauthorized AI model access and enforce least privilege principles across cloud workloads
- • Deploy Egress Security & Policy Enforcement controls to monitor and restrict outbound traffic to AI services, including FQDN filtering for unauthorized AI endpoints
- • Enable Multicloud Visibility & Control to detect anomalous traffic patterns and suspicious automation consistent with large-scale model distillation attempts
- • Utilize Encrypted Traffic (HPE) capabilities to secure data in transit and prevent interception of AI model requests and responses
- • Activate Threat Detection & Anomaly Response systems to baseline normal AI usage patterns and alert on covert relay tools and excessive data transfer ratios



