AIToday
Large Language ModelsAI Business & IndustryAI Safety & AlignmentTHE DECODERPublished: Aug 23, 2026, 19:01 JST4 min read

China's gray market undercuts Claude at 90% discount via proxy networks

China's gray market undercuts Claude at 90% discount via proxy networks

Key takeaway

  • Chinese developers are bypassing Anthropic's geoblocking through proxy networks called transfer stations, buying Claude tokens at a 70–90 percent discount.

  • The modular supply chain—spanning account brokers, phone verification platforms, and resellers—is hard to shut down; replacements launch within hours.

  • Newer identity checks already have AI-based workarounds, and the logs flowing through proxies may be monetized for model training, turning users into unpaid data producers.

3 Key Points

  1. What happened

    Despite Anthropic's strict geoblocking, credit card checks, and biometric verification, Chinese developers are buying Claude tokens through "transfer stations"—API proxies hosted outside China that relay requests as if from legitimate locations and accept payments in yuan via WeChat or Alipay. According to Oxford researcher Zilan Qian's analysis, users pay about 10 percent of the official price, with some operators hitting discounts of 70 to 90 percent below list.

  2. Why it matters

    The proxy infrastructure enables large-scale model distillation (learning from Claude's outputs to train competing models faster). Anthropic has already detected distillation attacks by Deepseek, Moonshot, and MiniMax involving over 24,000 fake accounts and 16 million requests. More broadly, the modular supply chain—with separate actors handling account registration, phone verification, proxy hosting, and resale—is resilient to bans; when one provider is shut down, replacements can be deployed within hours. Newer identity checks (ID + live selfie) already have workarounds using AI-generated fake IDs and deepfake technology.

  3. What to watch

    The operators may be monetizing usage logs as their primary revenue stream. Qian notes that datasets with Claude Opus 4.6 reasoning outputs are already circulating on HuggingFace with unclear provenance, and Chinese developers indicate that token sales are just customer acquisition while real margins come from selling logs—though no proof yet exists that this is happening systematically. Additionally, the circumvention infrastructure feeds into broader criminal markets (fraud, spam, biometric data resale) beyond AI alone.

Ask the AI about this article →

Context & Analysis

Anthropic's access controls rank among the strictest of any major AI provider for China—phone checks, foreign credit card verification, billing address validation, and even ID verification with live selfies for select users. Yet none of these barriers have stopped a thriving underground market. The transfer station infrastructure succeeds precisely because it is modular: account brokers, SMS verification platforms, proxy operators, and downstream resellers each handle a single link in the supply chain. When Anthropic bans one provider, the others remain intact and can reconnect within hours. Newer identity checks, which the company introduced to tighten control, already have documented workarounds—AI services generate realistic fake IDs, and deepfake technology defeats biometric checks, with real people in low-income countries sometimes recruited to complete KYC verifications for under $30.

The pricing advantage flows from multiple sources: free credits, discounted enterprise and education plans, token-quota sharing, and most significantly, the ability to monetize the data streams flowing through proxies. Every request—prompt, response, tool call, and iteration—is visible to the proxy operator and potentially valuable for training or distillation. Datasets with Claude Opus 4.6 outputs already circulate on HuggingFace with unclear provenance, and Chinese developers indicate that token sales are merely customer acquisition; the real margins lie in selling logs. While Qian's analysis cannot confirm systematic log monetization or identify buyers, she argues that rock-bottom pricing becomes viable only with this additional revenue stream, making users both paying customers and unpaid data producers.

The broader implication cuts across policy and security. Access restrictions intended to prevent geopolitical technology transfer have created exactly the circumvention markets they sought to prevent. The same infrastructure that allows a developer in Beijing to buy cheap Claude tokens also enables a bad actor to reach frontier models without being traced—since Anthropic initially sees only the proxy's account and IP, not the end user. This weakens monitoring systems designed to detect coordinated abuse across accounts. Beyond AI, the circumvention ecosystem feeds criminal markets: biometric data collected for KYC workarounds is resold for financial fraud and deepfakes, and account farming operations support spam, phishing, and credit card fraud. Anthropic, OpenAI, and Google have begun coordinating against distillation, but industry opinion is divided; in late July 2026, 25 companies including Nvidia, Microsoft, and Meta warned against premature restrictions on distillation, arguing it is a normal business practice. With the US government unlikely to regulate distillation alone, AI labs are left to enforce their own terms against methods that are admittedly illegal yet still deliver the distillation data they fear most.

FAQ

How do transfer stations work and what do users pay?
Transfer stations are API proxies hosted outside China that accept requests, forward them as if from a legitimate location, and relay responses back. Users pay in Chinese yuan via WeChat or Alipay and receive Claude tokens at about 10 percent of the official price, with some operators offering discounts of 70 to 90 percent below list.
How do operators achieve such low prices?
Methods include farming Anthropic's free $5 credit, exploiting enterprise and education discounts, splitting a single $200 Max plan across multiple users via token quotas, and using model swapping to reroute requests from expensive models (Opus 4.7) to cheaper ones (Sonnet) or Chinese models like Qwen. The biggest potential lever is monetizing usage logs—every request through a proxy is visible to the operator, including prompts, responses, and tool calls, which could be valuable for training or distillation.
What distillation attacks has Anthropic already found?
Anthropic uncovered large-scale distillation attacks by Deepseek, Moonshot, and MiniMax in which more than 24,000 fake accounts generated over 16 million requests.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • DataAgent launches with $10M to auto-fix Kubernetes faultsSiliconANGLE AI · 1h ago
  • SK Hynix custom HBM boosts inference up to 5.15xDIGITIMES Asia · 1h ago
  • Nvidia Earnings: Boring by Design, Avoiding a Consolidated WorldStratechery (Ben Thompson) · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleSnowflake cuts AI costs with smart model routing, open models