2026-thewizard0fbsod-quirky-chinese-i2p
findings extracted from this paper
-
The suspected Chinese surveillance nodes are hosted in data centers that explicitly prohibit 'circumvention services' (proxy/VPN services) in their terms of service, yet the nodes operate safely for extended periods. This suggests the operators benefit from either state-sanctioned access or ISP-level protection from ToS enforcement, consistent with a government or contractor intelligence-collection operation.
-
A community scan of the I2P network database (netDb) in July 2026 identified a cluster of suspicious router nodes uniformly running I2P version 0.9.66 (three versions behind the current 0.9.69), all hosted in Chinese domestic data centers rather than residential broadband. The nodes exhibit anomalous uniformity in their router capabilities (Caps) configuration and self-reported versions, a pattern inconsistent with organic user deployments.
-
The suspicious Chinese I2P nodes rotate their IP addresses regularly and simultaneously as a coordinated group, and some of the observed IPs have prior history of malicious behavior (SSH brute-forcing, remote exploitation) in threat-intelligence databases. Simultaneous coordinated IP rotation distinguishes state-run infrastructure from organic users and is a fingerprint of centrally managed probe fleets.
-
The author released a netDb scanner tool that reads the local I2Pd network database, identifies routers hosted on Chinese IP ranges, and exports results as IP lists for firewall rules. The tool supports filtering by country (--cn-only), JSON export, and IP-list export, enabling operators to block suspected surveillance nodes at the OS firewall layer before any I2P connection is made.