Threats · 8h ago

Relay Networks Hide AI Abuse at Scale

Team Cymru found more than 80,000 relay servers that let users in China reach frontier AI services, including Anthropic Claude and OpenAI, while hiding who they are and where they sit. The traffic pattern points to systematic output harvesting for model cloning, not isolated proxy use.

The relay layer sits between the real user and the model provider, so the service sees the relay account or API key instead of the person making the request. That lets operators pool credentials, spread volume across many servers, and make one account look like ordinary traffic while usage metering, rate limits, regional controls, and abuse detection miss the real requester.

For providers that bill and police access by account identity, the exposure is in the control plane: the same assumptions that support pricing and abuse enforcement can be gamed by a brokered credential network. If your platform depends on the credential holder being the consumer, this is the failure mode that breaks that model without breaking the login.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-09-23

Editions

Related stories