Team Cymru Finds AI Proxy Layer Hiding Abuse Origins
Team Cymru says the proxy ecosystem used to mask frontier-model traffic has grown from 10,867 identified servers to more than 80,000. The relays, including Claude Relay Service (CRS) and sub2api, sit between the user and the AI provider, so the service sees the proxy’s identity instead of the real requester.
That matters because the proxies are being fed by pools of API keys and consumer subscriptions, many tied to stolen credentials from phishing, info-stealer malware, and supply-chain attacks. In plain terms, an attacker can reuse a stolen AI account through a relay, and the visible source no longer tells the provider who is really behind the request.
For organizations that buy frontier-model access or let staff use consumer AI accounts for work, the exposure does not end with the password theft itself: the same credential can be resold through an obfuscation layer that makes standard account-abuse signals less reliable. AI platform operators inherit the same problem, because the abuse path is built to scale and to blur origin.
80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how organizations can identify their exposure.
Stolen AI credentials feed growing LLM proxy economy
More than 80,000 proxy servers have been observed cloaking the origin of traffic to frontier models, likely using AI credentials harvested via information stealers, phishing campaigns, and supply-chain attacks.