SecurityAug 23, 2026, 7:48 AM

China's proxy network sells Claude AI tokens cheap

TickrWire Editorial Desk·Aug 23, 2026, 7:48 AM·3 min read AI-assisted, human-reviewed

Reported by The Decoder: How China's gray market sells Claude tokens at a fraction of the price. Analysis and context written by TickrWire.

30-second summary

Anthropic's Claude tokens are being sold in China at roughly ten percent of the official price through overseas API proxies called transfer stations, according to Oxford researcher Zilan Qian.

TickrWire
China's proxy network sells Claude AI tokens cheap
Key takeaways
  • Anthropic's Claude tokens are sold in China for about 10% of the official price via overseas proxy services called transfer stations.
  • Transfer stations bypass geoblocking, credit‑card checks, and even selfie‑based KYC by routing API calls through foreign servers and accepting yuan payments.
  • The proxy ecosystem logs user interactions, creating a potential source of training data and raising privacy and security concerns.
  • Model swapping and data harvesting through these proxies could facilitate large‑scale distillation attacks on Anthropic's models.
  • The modular supply chain can quickly reconstitute after shutdowns, making enforcement of export controls challenging.
Full story

Anthropic has built one of the toughest access regimes for its Claude models, blocking Chinese IPs, demanding foreign credit cards, and even requiring live‑selfie verification for some accounts. Despite these barriers, a thriving underground market has emerged that lets Chinese developers obtain Claude tokens for about ten percent of the advertised price. The phenomenon was detailed in a recent analysis by Zilan Qian of the Oxford China Policy Lab, which traced the flow of tokens from overseas proxy operators to end users inside China.

The core of the operation consists of "transfer stations" – servers located outside China that act as middlemen for API calls. A user in China sends a request to the proxy, which forwards it to Anthropic as if it originated from an approved location, then returns the response. Payments are made in yuan via popular platforms such as WeChat and Alipay, eliminating the need for VPNs or foreign credit cards. Catalogues of these stations are shared in community directories, where they are ranked by price and reliability, and the cheapest offerings can be as low as one‑tenth of the standard rate.

Anthropic’s defensive measures include phone‑number verification, foreign billing address checks, and bans on entities with more than half ownership from restricted regions. For a subset of users, the company also enforces KYC procedures that require a government ID and a live selfie. The analysis notes that even these biometric checks are being sidestepped: synthetic IDs, deep‑fake videos, and recruited individuals in low‑income countries are used to satisfy the requirements, echoing earlier black‑market activity around Worldcoin’s iris‑scan system.

The Chinese circumvention infrastructure mirrors earlier illicit supply chains that have surrounded other AI services. Account brokers mass‑register Anthropic accounts, SMS verification services supply foreign numbers, and reverse‑engineering groups study detection methods. Downstream, the tokens are marketed on Chinese e‑commerce sites like Taobao. Researchers at Germany’s CISPA Helmholtz Center observed that many proxies also perform "model swapping," redirecting requests intended for the high‑end Opus 4.7 model to cheaper alternatives such as Sonnet or even domestic models like Qwen, a practice the community calls "diluting."

These workarounds create several risks. Every request that passes through a proxy can be logged, exposing prompts, responses, tool calls, and code snippets to the operator. Such data could be harvested for training or model‑distillation purposes, a concern highlighted by the presence of Claude‑generated datasets on HuggingFace with unclear provenance. The analysis also flags the potential for biometric data collected during KYC workarounds to be sold for fraud or deep‑fake creation, and notes that stolen or fraudulently used credit cards may fund some of the token pools, though the exact scale is unknown.

Anthropic has already reported large‑scale distillation attacks by Chinese firms such as Deepseek, Moonshot, and MiniMax, which generated millions of requests through fake accounts. The company responded by cutting off services to entities under Chinese control and shutting a subsidiary loophole. However, the gray‑market channels described by Qian undermine these safeguards, allowing continued access and data extraction. Industry voices are divided on whether distillation is a legitimate research practice or a security threat; recent statements from major AI players argue against premature restrictions, suggesting that regulation may focus more on cybersecurity than on model copying.

Looking ahead, the persistence of transfer stations suggests that any future policy or technical countermeasure must address the modular nature of the supply chain. Because each participant typically runs only one or two links, the network can reconfigure within hours when a node is blocked. Observers will be watching for tighter enforcement from Anthropic, possible collaboration with other AI firms, and any governmental actions aimed at curbing the flow of AI capabilities across borders. The situation underscores how geoblocking, even when combined with biometric KYC, can be circumvented at scale, raising broader questions about the effectiveness of current AI export‑control strategies.

Why this matters
Developers

Access to cheap Claude tokens enables rapid model distillation and experimentation that would otherwise be blocked.

Businesses

Companies can acquire advanced AI capabilities at a fraction of cost, but risk violating terms and exposing proprietary data.

Investors

The gray market signals revenue leakage for Anthropic and highlights security gaps that could affect valuation.

Students

Students gain affordable AI tools, yet may inadvertently participate in illicit data collection.

Everyone

The workarounds illustrate how technical restrictions can be sidestepped, raising broader policy and safety questions.

Glossary
transfer station
An overseas server that proxies API requests to bypass geographic restrictions.
distillation
A technique where outputs from a larger model are used to train a smaller one.
KYC
Know‑Your‑Customer procedures that verify a user’s identity, often with documents and biometric data.

AI bias estimate: The source emphasizes security risks and economic impact, potentially overstating the scale of data harvesting without independent verification. (Automated estimate, not a definitive judgement.)

Sources · 1
Read next
More stories
An AI boss fired its first employee but only after humans reminded it of its own rulesAI Tools

An AI boss fired its first employee but only after humans reminded it of its own rules

An AI agent running a San Francisco store fired an employee only after humans reminded it of its own termination rules, highlighting gaps in long-term memory and leniency in AI management.

AI could make scientists do more work less well, not less work better, study arguesAI Research

AI could make scientists do more work less well, not less work better, study argues

A theoretical economics study argues that language models might make scientific research shallower because time saved on routine tasks encourages academics to start more projects rather than improve existing ones.

Vercel Introduces ‘Is Agentic’, a Free Agent-Readiness Scoring Tool That Audits Public Websites Using Ora’s 100+ ChecksAI Tools

Vercel Introduces ‘Is Agentic’, a Free Agent-Readiness Scoring Tool That Audits Public Websites Using Ora’s 100+ Checks

Vercel and Ora launch Is Agentic, a free tool that scores how easily AI agents can discover, access, understand, and use a website using over 100 checks across four layers.

Harvard’s $699 startup bootcamp offers AI avatars of its instructorsBusiness

Harvard’s $699 startup bootcamp offers AI avatars of its instructors

Harvard Business School’s eight‑week Foundry bootcamp now includes AI avatars from HeyGen that give feedback on practice pitches and board meetings, at a price of $699.

OpenAI says California should strengthen its AI safety bill

OpenAI says California should strengthen its AI safety bill

OpenAI now supports strengthening California Senate Bill 53, a measure it previously resisted, citing recent security breaches and the need for stricter frontier model monitoring.

Decoding AI’s Open-Source Course Maps Three Ways to Run an Agent Loop and the Provider Economics Behind EachAI Tools

Decoding AI’s Open-Source Course Maps Three Ways to Run an Agent Loop and the Provider Economics Behind Each

Paul Iusztin s Decoding AI course explores three distinct agent loop execution modes and analyzes how infrastructure choices dictate inference costs.