New research out today from Team Cymru has uncovered a massive ecosystem of more than 80,000 LLM relay servers capable of allowing users to hide their true location and identity while accessing frontier AI models, creating a potential pathway for everything from region-ban evasion and credential sharing to large-scale model distillation.
In “Relaying to the Frontier,” Team Cymru researchers initially identified nearly 11,000 confirmed “transfer stations” running open-source relay software designed to pool AI credentials and proxy requests to providers including Anthropic, OpenAI, Google and xAI. Since completing the initial analysis, Team Cymru has expanded its discovery to more than 80,000 relays across multiple services.
The researchers also uncovered a cluster showing the system in action. More than 4,000 IP addresses in China and Hong Kong connected to 304 transfer stations, which subsequently reached Western and Chinese AI services. Over just eight days, those source addresses sent roughly 14 TB to the relays and received more than 7 TB back. In one subset involving Anthropic, 17 transfer stations uploaded approximately 81 GB to api.anthropic.com while receiving only about 1.4 GB in return, a 58:1 upload-to-download ratio. Team Cymru estimates that, if the uploaded data was text-based context, it could represent roughly 16–23 billion input tokens.
Relaying to the Frontier: https://www.team-cymru.com/post/llm-gateway-frontier-model-abuse
Related
This entry was posted on September 22, 2026 at 3:59 pm and is filed under Commentary with tags Team Cymru. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Team Cymru uncovers 80,000+ LLM relays enabling frontier AI abuse
New research out today from Team Cymru has uncovered a massive ecosystem of more than 80,000 LLM relay servers capable of allowing users to hide their true location and identity while accessing frontier AI models, creating a potential pathway for everything from region-ban evasion and credential sharing to large-scale model distillation.
In “Relaying to the Frontier,” Team Cymru researchers initially identified nearly 11,000 confirmed “transfer stations” running open-source relay software designed to pool AI credentials and proxy requests to providers including Anthropic, OpenAI, Google and xAI. Since completing the initial analysis, Team Cymru has expanded its discovery to more than 80,000 relays across multiple services.
The researchers also uncovered a cluster showing the system in action. More than 4,000 IP addresses in China and Hong Kong connected to 304 transfer stations, which subsequently reached Western and Chinese AI services. Over just eight days, those source addresses sent roughly 14 TB to the relays and received more than 7 TB back. In one subset involving Anthropic, 17 transfer stations uploaded approximately 81 GB to api.anthropic.com while receiving only about 1.4 GB in return, a 58:1 upload-to-download ratio. Team Cymru estimates that, if the uploaded data was text-based context, it could represent roughly 16–23 billion input tokens.
Relaying to the Frontier: https://www.team-cymru.com/post/llm-gateway-frontier-model-abuse
Share this:
Like this:
Related
This entry was posted on September 22, 2026 at 3:59 pm and is filed under Commentary with tags Team Cymru. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.