
Chinese developers are bypassing Anthropic's geoblocking through proxy networks called transfer stations, buying Claude tokens at a 70–90 percent discount.
The modular supply chain—spanning account brokers, phone verification platforms, and resellers—is hard to shut down; replacements launch within hours.
Newer identity checks already have AI-based workarounds, and the logs flowing through proxies may be monetized for model training, turning users into unpaid data producers.
What happened
Despite Anthropic's strict geoblocking, credit card checks, and biometric verification, Chinese developers are buying Claude tokens through "transfer stations"—API proxies hosted outside China that relay requests as if from legitimate locations and accept payments in yuan via WeChat or Alipay. According to Oxford researcher Zilan Qian's analysis, users pay about 10 percent of the official price, with some operators hitting discounts of 70 to 90 percent below list.
Why it matters
The proxy infrastructure enables large-scale model distillation (learning from Claude's outputs to train competing models faster). Anthropic has already detected distillation attacks by Deepseek, Moonshot, and MiniMax involving over 24,000 fake accounts and 16 million requests. More broadly, the modular supply chain—with separate actors handling account registration, phone verification, proxy hosting, and resale—is resilient to bans; when one provider is shut down, replacements can be deployed within hours. Newer identity checks (ID + live selfie) already have workarounds using AI-generated fake IDs and deepfake technology.
What to watch
The operators may be monetizing usage logs as their primary revenue stream. Qian notes that datasets with Claude Opus 4.6 reasoning outputs are already circulating on HuggingFace with unclear provenance, and Chinese developers indicate that token sales are just customer acquisition while real margins come from selling logs—though no proof yet exists that this is happening systematically. Additionally, the circumvention infrastructure feeds into broader criminal markets (fraud, spam, biometric data resale) beyond AI alone.
Ask the AI about this article →
Anthropic's access controls rank among the strictest of any major AI provider for China—phone checks, foreign credit card verification, billing address validation, and even ID verification with live selfies for select users. Yet none of these barriers have stopped a thriving underground market. The transfer station infrastructure succeeds precisely because it is modular: account brokers, SMS verification platforms, proxy operators, and downstream resellers each handle a single link in the supply chain. When Anthropic bans one provider, the others remain intact and can reconnect within hours. Newer identity checks, which the company introduced to tighten control, already have documented workarounds—AI services generate realistic fake IDs, and deepfake technology defeats biometric checks, with real people in low-income countries sometimes recruited to complete KYC verifications for under $30.
The pricing advantage flows from multiple sources: free credits, discounted enterprise and education plans, token-quota sharing, and most significantly, the ability to monetize the data streams flowing through proxies. Every request—prompt, response, tool call, and iteration—is visible to the proxy operator and potentially valuable for training or distillation. Datasets with Claude Opus 4.6 outputs already circulate on HuggingFace with unclear provenance, and Chinese developers indicate that token sales are merely customer acquisition; the real margins lie in selling logs. While Qian's analysis cannot confirm systematic log monetization or identify buyers, she argues that rock-bottom pricing becomes viable only with this additional revenue stream, making users both paying customers and unpaid data producers.
The broader implication cuts across policy and security. Access restrictions intended to prevent geopolitical technology transfer have created exactly the circumvention markets they sought to prevent. The same infrastructure that allows a developer in Beijing to buy cheap Claude tokens also enables a bad actor to reach frontier models without being traced—since Anthropic initially sees only the proxy's account and IP, not the end user. This weakens monitoring systems designed to detect coordinated abuse across accounts. Beyond AI, the circumvention ecosystem feeds criminal markets: biometric data collected for KYC workarounds is resold for financial fraud and deepfakes, and account farming operations support spam, phishing, and credit card fraud. Anthropic, OpenAI, and Google have begun coordinating against distillation, but industry opinion is divided; in late July 2026, 25 companies including Nvidia, Microsoft, and Meta warned against premature restrictions on distillation, arguing it is a normal business practice. With the US government unlikely to regulate distillation alone, AI labs are left to enforce their own terms against methods that are admittedly illegal yet still deliver the distillation data they fear most.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Israeli startup DataAgent Ltd
SK Hynix presented a custom HBM concept at SEMICON Taiwan 2026, where compute functions are placed in the base…

Taoyuan is positioning itself as a northern hub for AI data centers (AIDC), citing the Tatan area and an LNG c…

The U.S. Department of Defense announced on August 31 that it has deployed ChatGPT Mil, a customized version o…

Nvidia reported earnings that were both remarkable and boring, reflecting its focus on avoiding a consolidated…

Anthropic has agreed to a $35bn cloud-computing contract with Lambda, a Nvidia-backed cloud provider
