top of page

Team Cymru Finds 80,000 AI Relay Servers Hiding Access to Frontier Models

4 minutes ago
2 min read

Team Cymru researchers have identified more than 80,000 servers that relay traffic to leading artificial intelligence platforms, creating a sprawling infrastructure layer capable of obscuring who is using frontier models and from where.


The company's new research, Relaying to the Frontier, initially confirmed nearly 11,000 so-called transfer stations running open-source software that pools AI credentials and proxies requests to providers including Anthropic, OpenAI, Google and xAI. Follow-on discovery expanded the count beyond 80,000 relays across several services.


The finding matters because these gateways can weaken controls that AI providers use to enforce regional restrictions, attribute abuse and limit credential sharing. They could also support large-scale model extraction or distillation by making coordinated traffic appear to originate from dispersed infrastructure.


Team Cymru said one observed cluster linked more than 4,000 IP addresses in China and Hong Kong to 304 relay servers. Over eight days, those sources sent roughly 14 terabytes to the relays and received more than 7 terabytes in return.


A smaller Anthropic-related subset was even more unusual. Seventeen transfer stations uploaded approximately 81 gigabytes to Anthropic's API while receiving about 1.4 gigabytes back, a 58-to-1 ratio. Team Cymru estimated that, if the outbound data consisted primarily of text context, it could represent roughly 16 billion to 23 billion input tokens.


The researchers did not establish that every relay is malicious. Relay software can serve legitimate purposes, including simplifying access across accounts. But the scale and anonymity create a monitoring challenge for model providers and enterprise security teams.


For defenders, the research reinforces that AI abuse is increasingly an infrastructure problem. Detection cannot rely only on the content of individual prompts. Providers may also need to correlate token volumes, credential reuse, relay behavior and network relationships to distinguish normal developer traffic from coordinated attempts to evade controls.

bottom of page