Relays Are Masking Chinese Access to Frontier AI Models in the US
A sprawling network of over 80,000 relay servers is enabling Chinese users to bypass access restrictions and monitoring to access cutting-edge AI models hosted in the US, primarily to clone these models and create cheaper, less capable versions. Team Cymru identified this network, linked to the open-source software packages Claude Relay Service (CRS 1.x) and sub2api, which allows users to pool API keys and route requests through intermediaries to circumvent provider controls and access restrictions. The activity suggests systematic attempts at model distillation and potential fraud.
A vast network of over 80,000 LLM relay servers is facilitating Chinese access to advanced AI models hosted in the US, primarily to clone these models and create cheaper, less capable versions. Team Cymru identified this network, linked to the open-source software packages Claude Relay Service (CRS 1.x) and sub2api, which allows users to pool API keys and route requests through intermediaries to circumvent provider controls and access restrictions. The activity suggests systematic attempts at model distillation and potential fraud.
Researchers from Team Cymru initially identified 10,867 transfer stations across 457 autonomous systems (ASNs), but updated the number to more than 80,000 relays after further investigation. The network allows Chinese users to bypass geographic restrictions and provider controls, enabling them to access models from providers like Anthropic, OpenAI, Google, and xAI. The relays pool API keys and route requests through intermediaries, masking the user's true identity and location.
Team Cymru observed a significant volume of traffic directed to Anthropic's API, with users uploading 81GB of data in eight days and receiving 1.4GB in return, representing a 58:1 upload-to-download ratio. This ratio is indicative of model distillation, where attackers use the outputs of frontier models as training data to develop cheaper, less capable models that mimic their behavior. Chinese users and organizations are, at minimum, violating access blocks and can easily steal outputs to clone their own versions.
The network utilizes open-source software packages Claude Relay Service (CRS 1.x) and sub2api, both developed by Wei-Shaw and published on GitHub. sub2api, in particular, offers advanced features such as user management, per-user billing, subscription-to-API conversion, and prompt auditing. The GitHub repository for sub2api has been forked over 8,000 times, and its Telegram channel boasts nearly 7,000 subscribers, demonstrating widespread interest and potential for malicious use.
Commercial sponsors are also involved, with 15 selling access to models like Claude and OpenAI, seven providing IP addresses, two supplying accounts for users to access AI services, and one offering AI API traffic-optimized infrastructure and services for AI image and video generation. The scale of the network and the involvement of commercial entities highlight the sophistication and potential for sustained abuse.
