MediumNewsLLM-specific
Stolen AI credentials feed growing LLM proxy economy
- Published
- Record updated
Summary
Team Cymru reports that malicious actors use proxy servers called transfer stations to hide the origin of traffic to frontier AI models, enabling model distillation attacks and abuse of stolen AI subscription credentials. The firm initially identified 10,867 such servers running the open-source relay platforms Claude Relay Service (CRS) and its successor sub2api, and now estimates more than 80,000 proxies in total. Investigations by Okta Threat Intelligence and Gambit Security found stolen Anthropic session tokens, Gemini, OpenAI and other API keys in infostealer data and in a reselling gateway.
Related items
- InfoQuoting The New York TimesSame vendor · Simon Willison's Weblog
- InfoAnthropic’s AI gave Philadelphia police a fake tip about an unsolved homicideSame vendor · The Verge (AI)
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- Info‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest dropSame vendor · The Verge (AI)