AI News AI资讯 6h ago Updated 1h ago 更新于 1小时前 46

How China's Gray Market Sells Claude Tokens at a Fraction of the Price 中国灰色市场以极低价格出售Claude令牌

Chinese developers bypass Anthropic's strict geoblocking and KYC measures through "transfer stations" — API proxies hosted overseas — purchasing Claude tokens at roughly 10% of the official price A modular supply chain spans account brokers, SMS verification platforms, reverse-engineering specialists, transfer station operators, and downstream resellers on platforms like Taobao, making the system highly resilient to takedowns Operators undercut prices by farming free credits, exploiting discount 中国灰色市场通过"中转站"API代理以官方价格约10%出售Claude tokens,系统性绕过Anthropic的严格访问限制 模块化供应链结构使系统具有高度韧性,单一节点被封禁后数小时内即可恢复运营 运营商通过免费积分、折扣、信用卡欺诈及模型替换等手段大幅降低成本,德国CISPA检测发现17个代理中普遍存在模型替换 中转站可窃取用户提示词、响应等数据,用户同时成为付费客户和免费数据生产者 该灰色市场不仅削弱地理封锁,还助长身份和支付欺诈等犯罪市场

68
Hot 热度
65
Quality 质量
62
Impact 影响力

Analysis 深度分析

TL;DR

  • Chinese developers bypass Anthropic's strict geoblocking and KYC measures through "transfer stations" — API proxies hosted overseas — purchasing Claude tokens at roughly 10% of the official price
  • A modular supply chain spans account brokers, SMS verification platforms, reverse-engineering specialists, transfer station operators, and downstream resellers on platforms like Taobao, making the system highly resilient to takedowns
  • Operators undercut prices by farming free credits, exploiting discounts, splitting accounts across users, and potentially using fraudulently obtained payment methods
  • Widespread "model swapping" (called "diluting") reroutes requests from expensive models like Opus to cheaper alternatives like Sonnet or Chinese models such as Qwen, with one fake "Gemini-2.5" endpoint scoring only 37% versus the official 83.82% on medical benchmarks
  • The most significant revenue lever may be monetizing usage data — prompts, responses, and tool calls passing through proxies could yield valuable training/distillation datasets, turning users into unpaid data producers

Why It Matters

This gray market exposes critical vulnerabilities in AI access controls that the industry has treated as sufficient, demonstrating that even Anthropic's most rigorous verification — including biometric checks — can be circumvented at scale. For AI practitioners and providers, it raises urgent questions about data security, model provenance, and the unintended consequence of creating black markets that fuel broader cybercrime ecosystems including identity fraud and payment fraud.

Technical Details

  • Transfer station architecture: API proxies hosted on servers outside China accept requests in Chinese yuan via WeChat/Alipay, forward them through legitimate accounts, and relay responses back — eliminating the need for VPNs or foreign credit cards
  • Modular supply chain: Upstream actors include account brokers mass-registering Anthropic accounts, SMS verification platforms providing foreign numbers, and reverse-engineering specialists studying detection methods; downstream resellers market access on Taobao, with most participants running only one or two links
  • KYC circumvention: AI-generated fake IDs and deepfake technology bypass biometric selfie checks; in some cases, real people in low-income countries are recruited for verifications, echoing the Worldcoin iris-scan black market where scans from Cambodia and Kenya traded for under $30
  • Model swapping ("diluting"): Proxies silently reroute requests to cheaper models; CISPA Helmholtz Center researchers examined 17 API proxies and found widespread swapping, with one endpoint claiming to be "Gemini-2.5" performing at less than half the official benchmark score
  • Data monetization hypothesis: Every request through a proxy exposes prompts, responses, tool calls, and iterations; coding agents can leak additional codebase context, and unprovenanced Claude Opus 4.6 reasoning datasets are already circulating on HuggingFace

Industry Insight

AI providers must treat access control as an arms race rather than a one-time implementation — geoblocking, payment verification, and even biometric KYC are surmountable when economic incentives are high enough, requiring continuous investment in detection infrastructure and adaptive countermeasures. The "diluting" practice reveals that proxy operators can silently degrade service quality, meaning users may believe they're accessing premium models while receiving inferior outputs — a trust and transparency problem that could erode confidence in API-based AI ecosystems if left unaddressed. The data monetization angle represents a emerging threat vector: rock-bottom pricing may be a customer acquisition strategy where the real profit comes from harvesting usage logs, turning developers into unwitting data suppliers and raising significant IP and privacy concerns that providers should proactively address through monitoring and terms enforcement.

TL;DR

  • 中国灰色市场通过"中转站"API代理以官方价格约10%出售Claude tokens,系统性绕过Anthropic的严格访问限制
  • 模块化供应链结构使系统具有高度韧性,单一节点被封禁后数小时内即可恢复运营
  • 运营商通过免费积分、折扣、信用卡欺诈及模型替换等手段大幅降低成本,德国CISPA检测发现17个代理中普遍存在模型替换
  • 中转站可窃取用户提示词、响应等数据,用户同时成为付费客户和免费数据生产者
  • 该灰色市场不仅削弱地理封锁,还助长身份和支付欺诈等犯罪市场

为什么值得看

这篇文章揭示了AI服务访问控制与地缘政治限制之间的现实差距,对AI从业者和政策制定者具有重要参考价值。它展示了技术限制如何被商业利益驱动的黑市生态所绕过,同时也暴露了AI安全监控的盲区。

技术解析

  • 中转站架构:API代理服务器托管在中国境外,接收API请求后转发至Anthropic官方服务,再返回响应给用户。用户通过微信或支付宝以人民币支付,无需VPN或外国信用卡。
  • 模块化供应链:上游包括账户中介批量注册Anthropic账户、短信验证平台提供外国号码、逆向工程专家研究检测机制;下游则是开发者、企业和转售商在淘宝等电商平台销售访问权限。
  • 模型替换技术:代理服务器可静默将请求路由至更便宜的模型(如Sonnet或国产模型Qwen),德国CISPA研究所检测发现17个API代理中普遍存在此行为,某声称"Gemini-2.5"的端点医疗基准测试得分仅37%而非官方的83.82%。
  • 数据收集与变现:每个请求的提示词、响应、工具调用和迭代过程都可能被代理运营商捕获,编码代理可暴露更多代码库和工作流上下文,形成潜在的数据资产。
  • KYC绕过技术:AI生成逼真假身份证、深度伪造技术绕过生物识别验证,部分情况下从低收入国家招募真人进行身份验证。

行业启示

  • AI提供商的访问控制措施(地理封锁、KYC验证、生物识别)面临系统性挑战,需要重新评估安全架构的有效性并考虑更全面的威胁模型。
  • 灰色市场催生了新的商业模式,数据变现可能比API销售本身更具利润空间,这改变了AI服务的价值链条和竞争格局。
  • 政策制定者和AI企业应关注跨境AI服务监管漏洞,同时平衡安全控制与全球开发者社区的合理需求,避免过度限制导致市场转向地下。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude Security 安全 Policy 政策 Regulation 监管 Closed Source 闭源