How China’s gray market sells Claude tokens at a fraction of the price

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane August 23, 2026 5 min read
How China’s gray market sells Claude tokens at a fraction of the price

Chinese developers are buying access to Anthropic’s Claude model for roughly 10 percent of the official price. This happens through a gray market in China that bypasses strict access controls, credit card checks, and even biometric verification. The trade undermines Anthropic’s safety monitoring and fuels criminal activity around identity and payment fraud.

Transfer stations act as a backdoor

The mechanism relies on “transfer stations,” which are API proxies hosted on servers outside China. They accept requests, forward them as if they originated from a legitimate location, and relay the response back. Users pay in Chinese yuan via WeChat or Alipay. No VPN or foreign credit card is required. Popular services are listed in community directories and ranked by cost and availability.

Zilan Qian, a researcher at the Oxford China Policy Lab, notes that customers likely include Chinese AI labs aiming to distill Western models. These labs use outputs from stronger models to improve their own weaker versions faster.

The user base extends beyond labs. Students, researchers, developers, tech employees, companies, app makers, and hobbyists all use these services. Qian argues that proxy networks, often discussed as a security problem in the US, form part of a broader commercial market for Claude access in China.

A modular supply chain that is hard to shut down

Qian describes the transfer station as one actor in a modular supply chain. Upstream, account brokers mass-register Anthropic accounts and SMS verification platforms provide foreign phone numbers. Reverse-engineering specialists study Anthropic’s detection methods. Downstream, developers, companies, and resellers market access on Chinese e-commerce platforms like Taobao.

Most participants only run one or two links in the chain. This structure makes the system resilient. When one provider gets banned, the upstream account pools and downstream customers remain intact. A replacement can be spun up within hours.

Even newer identity checks that require users to verify their identity with an ID and a live selfie have workarounds. AI services can generate realistic fake IDs, while deepfake technology beats biometric checks. Where that falls short, real people in low-income countries are sometimes recruited for verifications in these KYC markets.

These claims rely partly on informal conversations and publicly available sources. As a precedent, Qian points to the black market around Worldcoin, whose identity system verifies users through iris scans. Scans from Cambodia and Kenya were traded for under $30.

Sellers hit prices 70 to 90 percent below list

Operators drive prices down through several methods. They farm Anthropic’s free $5 credit, exploit enterprise and education discounts, or split a single $200 Max plan across multiple users through token quotas. Accounts funded with stolen or fraudulently used credit cards may also flow into these pools, though the analysis cannot pin down their share.

Model swapping adds another layer. Since the proxy sits between the user and Anthropic, it can quietly reroute a request meant for Opus 4.7 to the cheaper Sonnet or even to Chinese models like Qwen. Researchers at Germany’s CISPA Helmholtz Center for Information Security examined 17 API proxies and found widespread model swapping.

One supposed “Gemini-2.5” endpoint scored just 37 percent on a medical benchmark instead of the official 83.82 percent. The Chinese community calls this practice “diluting.”

The biggest lever may be monetizing usage data. Every request that passes through a proxy is potentially visible to its operator, including prompts, responses, tool calls, and iterations. Coding agents can expose even more context from the codebase and workflow. These logs could contain valuable training or distillation data.

Datasets with Claude Opus 4.6 reasoning outputs and no clear provenance are already circulating on HuggingFace. Chinese developers warn that the token business is just customer acquisition and the real margin is in the logs. Qian stresses that there is no proof yet that transfer station operators are systematically collecting and selling this data, or who the buyers might be. Her argument is that rock-bottom prices could become viable through additional monetization of the logs. In that scenario, users would be paying customers and unpaid data producers at the same time.

Access restrictions create the markets they meant to prevent

Qian concludes that the implications go far beyond the US-China tech rivalry. The methods a geoblocked developer uses to get access are structurally identical to those a bad actor could use to reach frontier models without being traced. When a request comes through a proxy, Anthropic initially sees the proxy’s account and IP address, not the actual end user. That weakens monitoring systems like Clio, which are designed to detect coordinated abuse patterns across accounts and conversations, especially when activity is spread across many proxy accounts and broken into individually inconspicuous sub-requests.

The circumvention infrastructure also feeds criminal markets beyond AI. Biometric data collected for KYC workarounds could be resold for financial fraud or deepfakes. Account farming operations support spam, phishing, and credit card fraud. Qian points out that access restrictions have historically created profitable circumvention markets, from the Great Firewall to today’s transfer stations.

Anthropic, OpenAI, and Google fight distillation

This gray market infrastructure hurts Anthropic’s business because it has already been used in large-scale distillation attacks by Chinese AI companies. Anthropic, OpenAI, and Google recently began working together against unauthorized model copying by Chinese competitors.

Anthropic had previously uncovered large-scale distillation attacks by Deepseek, Moonshot, and MiniMax, in which more than 24,000 fake accounts generated over 16 million requests. The company cut off its services to firms under Chinese control and closed the subsidiary loophole. Alibaba banned its employees from using Claude Code after hidden code was found that could identify Chinese users.

But the industry is split on whether distillation is even a problem. Voices across the sector have started framing it as a normal business practice, driven by interests in strengthening open-weight models. Mark Zuckerberg called learning from anything observable, including distillation of competing models, a principle worth protecting. In late July 2026, 25 companies, including Nvidia, Microsoft, and Meta, warned against premature restrictions on distillation.

That pushback makes it unlikely the US government will step in with regulation over distillation alone, though it might act for cybersecurity reasons or simply to slow down China. Currently, the AI labs are left to protect themselves and enforce their own terms of service. But as Qian’s report shows, their safeguards are not good enough yet and can be defeated through admittedly illegal methods that still deliver distillation data.

What it means

For people making things, the immediate effect is access. Developers can run powerful models without needing foreign credit cards or passing strict identity checks. This lowers the barrier to entry significantly. However, the trade-off is privacy and data ownership. Every interaction passes through a third party who can log prompts and responses. Users effectively become data producers for the operators of these proxy services. The low cost comes with the risk that the data being used to train future models is stolen from the very people paying to use the current ones.

Scroll to Top