A sprawling network of intermediary servers facilitates users in China’s access to advanced AI models in the United States, ensuring their identities and locations remain concealed. The volume of activity through the network indicates systematic attempts to create less capable versions of frontier AI models at significantly lower cost than developing them independently, according to Team Cymru's recent report. Account attribution, usage metering, rate limits, abuse detection, regional availability, and the terms governing these are enforced on the party holding the credentials.
Team Cymru initially pinpointed 10,867 transfer stations across 457 autonomous systems, or ASNs, but later expanded the count to over 80,000 relays after conducting additional research.
The company examined a cluster of relay servers hosted by several US virtual private server providers and discovered more than 4,000 IP addresses in China and Hong Kong that connected to these servers. Related: More Than a Third of Industrial Organizations Report Cybersecurity Risks as a Major Barrier to Growth, Study Reveals According to Team Cymru, the traffic observed going directly to an Anthropic API was particularly noteworthy due to its high volume. Team Cymru interpreted the 58:1 upload-to-download ratio as potentially indicative of large-scale model distillation attempts, where attackers use a frontier model's outputs to develop a cheaper, less capable model that mimics its behavior.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)






