Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LLM relay gateways put an intermediary between a person and an AI provider. The provider can then see the relay’s credential and network address instead of the person’s own account and source IP, making it harder to attribute use or apply controls tied to identity and location. Team Cymru reported more than 80,000 relay-related tags in an expanded aggregation in September 2026, but that is not the same count as its earlier scan of 10,867 confirmed transfer stations.

How do LLM relay gateways hide who is using an AI model?

A relay gateway accepts requests from downstream users and forwards them to an upstream model provider. In the setup described by Team Cymru, the user signs in to the gateway; the gateway makes the provider request using its own pooled API key or logged-in subscription session. The provider therefore sees the gateway’s credential and IP address, not necessarily the identity or source IP of the person who prompted it.

This breaks the direct link between the provider-facing account and the person consuming the answer. As Scott Fisher of Team Cymru put it in “Relaying to the Frontier,” published September 22, 2026: “A transfer station breaks the assumption every frontier-model control depends on: that the account making a request belongs to the party consuming the answer.”

Team Cymru identified Claude Relay Service (CRS 1.x) and its successor sub2api (CRS 2.0). The report says sub2api includes user management, per-user billing, subscription-to-API conversion, and prompt auditing. Those are capabilities of the toolkit, not proof that a particular operator misused it.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does the 80,000 relay figure actually count?

The two headline figures describe different populations. Team Cymru’s September 22 report first gives the result of an eight-day scan of confirmed transfer stations, then separately describes a broader aggregation of gateway and relay tags. The latter’s listed active volumes are dated September 21, 2026. It should not be read as a directly comparable re-count of the original CRS/sub2api stations.

Figure What it represents
10,867 confirmed transfer stations Team Cymru’s initial eight-day scan, reported in 2026.
9,456 sub2api generation 2.0 stations A component of the 10,867-station scan, reported by Team Cymru in 2026.
1,353 CRS generation 1.x stations A component of the same scan, reported by Team Cymru in 2026.
457 distinct ASNs The number of autonomous systems represented in the initial scan.
More than 80,000 relay-related tags Team Cymru’s broader gateway-and-relay aggregation, with listed active volumes dated September 21, 2026; not the initial confirmed-station count.

The initial population was spread across many hosting networks: Team Cymru said no single hosting provider accounted for more than about 11% of those transfer stations. The report also listed 26 commercial sponsors on sub2api’s GitHub page: 15 API relay resellers, seven residential proxy vendors, two AI-account providers, one relay-optimized CDN, and one media-generation API. These categories and listings do not establish what any sponsor intended or did.

Which controls can an intermediary weaken?

When a provider sees a shared gateway credential rather than each user’s own identity, several provider-side controls may become less effective or less attributable:

  • Account attribution: provider logs may identify the gateway account, not the individual user or workload.
  • Usage metering and billing: pooled use can make per-person consumption harder for the provider to distinguish.
  • Rate limits and abuse detection: activity from many users may be aggregated behind a credential or network origin, while a user may appear to originate from the gateway.
  • Regional availability controls: routing through a relay can obscure the user’s source location from the provider and may enable attempts to reach services from another region.

These are risks created by the architecture, not proof that every gateway operator or user is acting maliciously. Team Cymru’s geographic and policy conclusions are its analysis of observed infrastructure, not a court or regulator finding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did Team Cymru observe about traffic?

A secondary incident synthesis dated September 23, 2026, reported about 4,000 China/Hong Kong IP addresses and 304 U.S.-based transfer stations, alongside about 14 TB uploaded and more than 7 TB downloaded over an eight-day observation window. Those reported transfer volumes are not a direct measurement of traffic to frontier-model providers; bytes exchanged with transfer stations do not by themselves identify the upstream destination or the content.

The same synthesis said 17 relays connecting to Anthropic showed 81 GB of uploads and 1.4 GB of downloads. The available observations do not independently reveal prompt contents or establish the purpose of those transfers. Volume alone cannot show that model extraction or distillation occurred.

Did the report prove credential theft or model distillation?

No. Team Cymru described credential sharing or resale, regional-policy evasion, and collecting model outputs at scale as possible uses of relays, and discussed distillation as a consequential possibility. The secondary synthesis says prompt contents were not visible and the actual purpose was not identified; it also says the source of credentials was unknown. The observations therefore do not establish that credentials were stolen or that a model was distilled.

It is useful to separate several investigative questions that can otherwise get conflated: whether a gateway was present, whether it authenticated upstream, whether it consumed quota, whether a credential was compromised, whether policy was evaded, and whether outputs were used for model extraction. Evidence for one does not automatically prove the others.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can a company detect unauthorized AI gateway use?

No single log source is likely to identify the user behind a pooled relay credential. An investigation is stronger when endpoint and network evidence can be correlated with identity-provider records and provider-side AI usage.

  1. Inventory identities and credentials. Identify AI accounts, API keys, OAuth grants, sessions, and applications. Check whether credentials are being sent to gateways the organization has not approved.
  2. Review provider-side activity. Compare source IPs, regions, token volumes, billing, rate limits, and audit logs with credential issuance records and legitimate sharing arrangements. A location or consumption anomaly is a lead, not proof of compromise.
  3. Inspect endpoints and correlate network activity. Look for AI credentials in browsers, command-line tools, extensions, environment variables, configuration files, and local settings; compare findings with outbound connections and known relay infrastructure.
  4. Look for patterns across accounts and networks. Investigate one credential appearing from many IPs or ASNs, geographically inconsistent use, sharp consumption spikes, or connections to relay infrastructure. Corroborate indicators before treating them as an incident finding.
  5. Contain only after validation. Separate credentials by user and use case, narrow their scope and lifetime, rotate them, and revoke suspicious keys or sessions when the evidence supports doing so.

Are all AI gateways a security problem?

No. A gateway can be a legitimate routing and governance layer. Vercel’s official AI Gateway architecture material describes API translation, provider failover, and recording model, token, and dollar cost per request; it also documents attribution by user, feature, or key, budget controls, and provider credentials injected at routing time. That is one vendor’s description of its own product, not a guarantee about every managed or self-hosted gateway.

When evaluating a gateway, assess whether identity survives each hop, whether logs connect a request to its user, model, credential, region, and spend, and whether upstream keys are isolated and scoped. Also check how regional policy and per-user or per-key limits work, and whether failover can change the provider, region, credential, or billing behavior. A gateway that routes centrally can improve visibility only if those controls are deliberately preserved.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.