80,000 Relay Servers Enable China Users to Bypass U.S. AI Model Region Restrictions
What Happened – Team Cymru identified more than 80 000 “relay” servers that act as transfer stations for U.S. frontier AI models. The relays pool API credentials, mask end‑user location, and let Chinese actors query the models at scale, facilitating large‑scale knowledge‑distillation attacks that violate provider terms of service.
Why It Matters for Trust & Control Assurance
- The ecosystem demonstrates a supply‑chain risk where third‑party infrastructure subverts geographic usage controls, a scenario continuous control‑assurance programs are built to detect and document.
- Monitoring and evidencing third‑party AI service relationships helps provide a defensible audit trail that satisfies multiple framework objectives (e.g., vendor oversight in NIST CSF 2.0).
- Leveraging a dedicated Vendor Risk capability enables organizations to continuously verify that external AI relays comply with contractual and regulatory usage restrictions.
Who Is Affected – Technology‑SaaS firms offering AI APIs, AI model developers, and any enterprise that integrates U.S. frontier models into products or services.
Recommended Actions –
- Inventory all external AI service providers and relay‑type intermediaries used to access model APIs.
- Implement continuous monitoring of API call origins, geographic tags, and usage patterns to detect anomalous relay activity.
- Enforce contractual clauses that prohibit knowledge‑distillation and require evidence of compliance with regional restrictions.
Source: Help Net Security
Technical Notes – The relays (Claude Relay Service, sub2api) are open‑source projects on GitHub, forked thousands of times, and hosted across 457 networks. They obtain credentials via promotional abuse or token theft, then expose them through a shared API gateway that obscures end‑user IPs. Source: same as above