Threat Brief — 2026-09-23 — 80,000 AI Relay Servers Exposed
Executive summary: Researchers have identified a network of over 80,000 relay servers enabling users in China to mask their identities while accessing frontier US large language models, likely for model distillation. This is a meaningful new development in the ongoing story of Chinese entities systematically cloning Claude, GPT, Gemini, and Grok models, first reported by CISA on 2026-09-08. The relay infrastructure reveals the scale and operational mechanics behind the distillation campaign.
Top items
- Massive relay server network enables masked Chinese access to US frontier AI models. More than 80,000 AI relay servers are helping users in China conceal their identities while interacting with cutting-edge LLMs from US providers, presumably to facilitate model distillation — the process of training cheaper clones by querying frontier models at scale. This extends the story first reported on 2026-09-08 by CISA, which named six Chinese companies engaged in large-scale distillation of Claude, GPT, Gemini, and Grok. The relay infrastructure detail illuminates how access restrictions and geo-blocking are being circumvented operationally. (src: Dark Reading)
Themes
AI model protection as a security frontier. The relay-server disclosure adds an infrastructure dimension to a story that has so far focused on which models were targeted and which companies were involved. For organisations deploying or exposing frontier AI APIs, the finding underscores that rate-limiting and geo-fencing alone are insufficient when adversaries can route through tens of thousands of intermediaries. This sits alongside a cluster of recent AI-security stories — including the Bifrost AI Gateway unauthenticated RCE, the Meta Muse backdoor, and OpenAI Codex sandbox escapes — signalling that the attack surface around AI tooling is expanding rapidly on multiple fronts.
