Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

80,000 Relay Servers Enable China Users to Bypass U.S. AI Model Region Restrictions

Team Cymru uncovered a network of over 80 000 relay servers that mask user location and allow Chinese actors to query U.S. frontier AI models, facilitating knowledge‑distillation attacks. This highlights a supply‑chain risk that must be addressed through continuous vendor‑risk monitoring and audit‑ready evidence of compliance.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

80,000 Relay Servers Enable China Users to Bypass U.S. AI Model Region Restrictions

What Happened – Team Cymru identified more than 80 000 “relay” servers that act as transfer stations for U.S. frontier AI models. The relays pool API credentials, mask end‑user location, and let Chinese actors query the models at scale, facilitating large‑scale knowledge‑distillation attacks that violate provider terms of service.

Why It Matters for Trust & Control Assurance

  • The ecosystem demonstrates a supply‑chain risk where third‑party infrastructure subverts geographic usage controls, a scenario continuous control‑assurance programs are built to detect and document.
  • Monitoring and evidencing third‑party AI service relationships helps provide a defensible audit trail that satisfies multiple framework objectives (e.g., vendor oversight in NIST CSF 2.0).
  • Leveraging a dedicated Vendor Risk capability enables organizations to continuously verify that external AI relays comply with contractual and regulatory usage restrictions.

Who Is Affected – Technology‑SaaS firms offering AI APIs, AI model developers, and any enterprise that integrates U.S. frontier models into products or services.

Recommended Actions –

  • Inventory all external AI service providers and relay‑type intermediaries used to access model APIs.
  • Implement continuous monitoring of API call origins, geographic tags, and usage patterns to detect anomalous relay activity.
  • Enforce contractual clauses that prohibit knowledge‑distillation and require evidence of compliance with regional restrictions.

Source: Help Net Security

Technical Notes – The relays (Claude Relay Service, sub2api) are open‑source projects on GitHub, forked thousands of times, and hosted across 457 networks. They obtain credentials via promotional abuse or token theft, then expose them through a shared API gateway that obscures end‑user IPs. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/09/23/china-ai-relay-frontier-model-abuse/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →