China’s 80,000 Relay Servers Bypass U.S. AI Restrictions
Team Cymru reveals a vast relay network enabling Chinese users to circumvent U.S. AI geographic restrictions, raising concerns over AI governance and security.
Relay Infrastructure and Its Purpose
80,000 relay servers facilitate circumvention of U.S. AI geographic restrictions by Chinese users, according to Team Cymru. The organization’s analysis identified a network of infrastructure designed to bypass regional access controls imposed by leading artificial intelligence providers.
Key Findings from Team Cymru’s Research
Scott Fisher, Senior Principal Engineer at Team Cymru, described the system as a coordinated ecosystem enabling unauthorized activities. A joint warning from CISA, the NSA, and the FBI highlighted that Chinese entities are conducting large-scale knowledge distillation operations to extract capabilities from advanced U.S. AI models.
“The relay infrastructure, referred to as transfer stations, aggregates AI account credentials and distributes unique keys to end users. This architecture obscures user identities and locations, complicating enforcement of geographic restrictions and monitoring of model usage.”
Tools and Commercial Sponsors Behind the Network
The system allows multiple individuals to access frontier AI models through a single server, masking the true origin of requests. The relays primarily utilize two tools: Claude Relay Service and its successor, sub2api. Both are hosted on GitHub under the username Wei-Shaw.
Features of sub2api and Its Ecosystem
The sub2api platform includes features such as user management, billing systems, subscription-to-API conversion layers, and prompt auditing. The project has seen over 8,000 forks, with a Telegram channel boasting nearly 7,000 members. Its GitHub page lists 26 commercial sponsors, including 15 entities offering AI model access via relays, seven providing residential proxies, and two specializing in AI service account sales.
“Additional sponsors include a content delivery network optimized for relay traffic and a reseller of image and video generation tools.”
Scale and Distribution of Relay Nodes
Team Cymru’s research confirmed 10,867 relay nodes during an eight-day scanning period, with the total expanding to over 80,000. Of the initial batch, 9,456 operated sub2api and 1,353 used the older Claude Relay Service. These relays were distributed across 457 distinct networks, with no single hosting provider accounting for more than 11% of the infrastructure.
Geographic and Data Transmission Insights
A subset of 304 relays in a U.S.-based virtual private server cluster was linked to over 4,000 Chinese and Hong Kong-based IP addresses. Over eight days in late August, this cluster transmitted approximately 14 terabytes of data to Anthropic’s API, potentially indicating automated large-scale queries.
“However, researchers could not inspect the specific prompts or model responses to confirm if the activity involved model distillation or other forms of misuse.”
Implications for AI Governance and Security
Team Cymru has shared the identified relay IP addresses with affected AI providers and plans to continue monitoring for new nodes. The findings underscore the growing challenge of enforcing geographic access controls in AI ecosystems, as adversaries leverage distributed infrastructure to circumvent restrictions.
Role of Open-Source Tools and Commercial Sponsors
The report also highlights the role of open-source tools in enabling these operations, with commercial sponsors facilitating access to compromised credentials and relay services. The joint advisory from U.S. federal agencies emphasized that knowledge distillation—where attackers extract model capabilities through repeated queries—poses a significant threat to AI providers.
“This method allows adversaries to replicate advanced features at a fraction of the cost of independent development, violating terms of service that prohibit using outputs for training competing models.”
Call to Action for AI Providers and Researchers
The scale of the relay network suggests a coordinated effort to undermine regional restrictions, raising concerns about the proliferation of unauthorized AI access. The research highlights the need for enhanced detection mechanisms to identify and mitigate such infrastructure. AI providers must address vulnerabilities in their access control systems while collaborating with cybersecurity researchers to track and disrupt relay networks.
Geopolitical and Regulatory Challenges
The findings also underscore the broader implications of geopolitical tensions on AI governance, as adversaries exploit technical loopholes to bypass regulatory and geographic barriers.
FAQs
What are relay servers, and how do they bypass AI restrictions?
Relay servers act as intermediaries that mask user identities and locations, allowing access to AI models restricted by geography. They aggregate credentials and distribute keys to users, complicating enforcement of access controls.
Which tools are used in the relay network?
The primary tools are Claude Relay Service and sub2api, both hosted on GitHub. sub2api includes features like user management, billing systems, and prompt auditing.
What role do commercial sponsors play?
Commercial sponsors provide AI model access, residential proxies, and AI service account sales, enabling the relay network’s operations and scalability.
