80,000+ proxy servers hide stolen AI credentials fueling LLM abuse, Team Cymru finds
ChuckDBrooks · x · 2026-09-29
A Team Cymru report covered by CSO Online reveals malicious actors are using proxy servers ("transfer stations") to mask traffic to frontier AI models.
- Researchers first found 10,867 servers running the open-source Claude Relay Service (CRS) and its successor sub2api; the total is now estimated at over 80,000
- The proxies likely run on AI credentials harvested via infostealers, phishing, and supply-chain attacks, abusing stolen enterprise AI subscriptions
- They also enable model distillation attacks by laundering large-scale API calls
- "A transfer station breaks the assumption every frontier-model control depends on: that the account making a request belongs to the party consuming the answer," said Team Cymru's Scott Fisher
More from Infra
- Merge Gateway adds self-hosted model support for unified enterprise AI governance — shensi · 2026-09-29
- Chinese CNC factory declines part over export controls; poster builds it anyway — wavefnx · 2026-09-29
- Ben Lorica: the AI data problem has moved downstream — from raw material to usable-data labor and licensed access — bigdata · 2026-09-29
- Researchers Build Backdoor Method to Rank AI Model Energy Use as Big Three Stay Silent — relianceschool · 2026-09-29
- Agent spins up 322 Hugging Face Jobs in 90 minutes for about $4 — victormustar · 2026-09-29
- antirez: stop obsessing over t/s — short thinking phases and fast prefill are what matter — antirez · 2026-09-29