How China's gray market sells Claude tokens at a fraction of the price
Key Points
- Chinese developers are bypassing Anthropic's strict access restrictions, buying tokens for the AI model Claude through so-called transfer stations at roughly ten percent of the official price.
- These API proxies route requests through overseas servers. Operators push prices down by exploiting free credits and secretly swapping expensive models for cheaper alternatives.
- According to an analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, this modular supply chain doesn't just undermine geoblocking. It also weakens Anthropic's ability to monitor misuse and can fuel criminal markets around identity and payment fraud.
Despite geoblocking, credit card checks, and even biometric verification for some users, a gray market for Anthropic's AI models is thriving in China. So-called "transfer stations" are undermining access restrictions and basic assumptions about AI safety.
Anthropic runs what are probably the strictest access controls of any major AI provider when it comes to China. The company checks phone numbers, foreign credit cards, and billing addresses. It bans companies that are more than 50 percent owned, directly or indirectly, by entities based in unsupported regions like China. For select users, it even requires ID verification with a live selfie. Yet Chinese developers can still buy Claude tokens for about 10 percent of the official price, according to a detailed analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, published by ChinaTalk.
"Transfer stations" give developers a backdoor
The trick is what the Chinese developer community calls "transfer stations," which are API proxies hosted on servers outside China. They accept API requests, forward them as if they came from a legitimate location, and relay the response back. Users pay in Chinese yuan through WeChat or Alipay. No VPN, no foreign credit card needed. Popular transfer stations are cataloged in community directories and ranked by price and availability.
According to Qian, the customers likely include Chinese AI labs looking to distill Western models, meaning they learn from a stronger model's outputs to improve their own weaker models faster.
But the user base goes well beyond that. Students, researchers, developers, tech employees, companies, app makers, and hobbyists all use the services. Qian argues that the proxy networks, which are mostly discussed as a security problem in the US, are actually part of a much broader commercial market for Claude access in China.
A modular supply chain that's hard to shut down
Qian's analysis describes the transfer station as one actor in the middle of a modular supply chain. Upstream, account brokers mass-register Anthropic accounts, SMS verification platforms provide foreign phone numbers, and reverse-engineering specialists study Anthropic's detection methods. Downstream, developers, companies, and resellers market access on Chinese e-commerce platforms like Taobao.
Most participants only run one or two links in the chain, which makes the system resilient. When one provider gets banned, the upstream account pools and downstream customers stay intact. A replacement can be spun up within hours.
Even Anthropic's newer KYC-style identity checks, which require select users to verify their identity with an ID and a live selfie, already have workarounds and dedicated infrastructure, according to Qian. AI services can generate realistic fake IDs, while deepfake technology is being used to beat biometric checks. Where that falls short, real people in low-income countries are sometimes recruited for verifications in these KYC markets, Qian says. These claims are based partly on informal conversations and publicly available sources. As a precedent, she points to the black market around Worldcoin, whose identity system verifies users through iris scans. Scans from Cambodia and Kenya were traded for under $30, according to Qian.
How sellers hit prices 70 to 90 percent below list
Operators drive prices down through a mix of methods. They farm Anthropic's free $5 credit, exploit enterprise and education discounts, or split a single $200 Max plan across multiple users through token quotas. Accounts funded with stolen or fraudulently used credit cards may also flow into these pools, though the analysis can't pin down how large their share is.
Model swapping adds another layer. Since the proxy sits between the user and Anthropic, it can quietly reroute a request meant for Opus 4.7 to the cheaper Sonnet or even to Chinese models like Qwen. Researchers at Germany's CISPA Helmholtz Center for Information Security examined 17 API proxies and found widespread model swapping, according to Qian. One supposed "Gemini-2.5" endpoint scored just 37 percent on a medical benchmark instead of the official 83.82 percent. The Chinese community calls this practice "diluting."
The biggest lever, according to Qian, may be monetizing usage data. Every request that passes through a proxy is potentially visible to its operator, including prompts, responses, tool calls, and iterations. Coding agents can expose even more context from the codebase and workflow. These logs could contain valuable training or distillation data.
Datasets with Claude Opus 4.6 reasoning outputs and no clear provenance are already circulating on HuggingFace. Chinese developers warn, according to the analysis, that the token business is just customer acquisition and the real margin is in the logs. Qian stresses that there's no proof yet that transfer station operators are systematically collecting and selling this data, or who the buyers might be. Her argument is that rock-bottom prices could become viable through additional monetization of the logs. In that scenario, users would be paying customers and unpaid data producers at the same time.
Access restrictions create the very markets they're meant to prevent
Qian concludes that the implications go far beyond the US-China tech rivalry. The methods a geoblocked developer uses to get access are structurally identical to those a bad actor could use to reach frontier models without being traced. When a request comes through a proxy, Anthropic initially sees the proxy's account and IP address, not the actual end user. That can also weaken monitoring systems like Clio, which are designed to detect coordinated abuse patterns across accounts and conversations, especially when activity is spread across many proxy accounts and broken into individually inconspicuous sub-requests.
The circumvention infrastructure also feeds criminal markets beyond AI, the analysis argues. Biometric data collected for KYC workarounds could be resold for financial fraud or deepfakes. Account farming operations support spam, phishing, and credit card fraud. Qian points out that access restrictions have historically created profitable circumvention markets, from the Great Firewall to today's transfer stations.
Anthropic, OpenAI, and Google have been fighting distillation for months
This gray market infrastructure hurts Anthropic's business because it has already been used in large-scale distillation attacks by Chinese AI companies. Anthropic, OpenAI, and Google recently began working together against unauthorized model copying by Chinese competitors.
Anthropic had previously uncovered large-scale distillation attacks by Deepseek, Moonshot, and MiniMax, in which more than 24,000 fake accounts generated over 16 million requests. The company cut off its services to firms under Chinese control and closed the subsidiary loophole. Alibaba banned its employees from using Claude Code after hidden code was found that could identify Chinese users.
But the industry is split on whether distillation is even a problem. Voices across the sector have started framing it as a normal business practice, driven by interests in strengthening open-weight models. Mark Zuckerberg called learning from anything observable, including distillation of competing models, a principle worth protecting. In late July 2026, 25 companies, including Nvidia, Microsoft, and Meta, warned against premature restrictions on distillation.
That pushback makes it unlikely the US government will step in with regulation over distillation alone, though it might act for cybersecurity reasons or simply to slow down China. Currently, the AI labs are left to protect themselves and enforce their own terms of service. But as Qian's report shows, their safeguards aren't good enough yet and can be defeated through admittedly illegal methods that still deliver distillation data.
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.