AI Security · AI-Powered Attack

Team Cymru Finds AI Proxy Layer Hiding Abuse Origins

Team Cymru says the proxy ecosystem used to mask frontier-model traffic has grown from 10,867 identified servers to more than 80,000. The relays, including Claude Relay Service (CRS) and sub2api, sit between the user and the AI provider, so the service sees the proxy’s identity instead of the real requester.

That matters because the proxies are being fed by pools of API keys and consumer subscriptions, many tied to stolen credentials from phishing, info-stealer malware, and supply-chain attacks. In plain terms, an attacker can reuse a stolen AI account through a relay, and the visible source no longer tells the provider who is really behind the request.

For organizations that buy frontier-model access or let staff use consumer AI accounts for work, the exposure does not end with the password theft itself: the same credential can be resold through an obfuscation layer that makes standard account-abuse signals less reliable. AI platform operators inherit the same problem, because the abuse path is built to scale and to blur origin.

2 sources · 10h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-28

Every edition of this story: Team Cymru Finds AI Proxy Layer Hiding Abuse Origins

More from today