How China's Gray Market Sells Claude Tokens at a Fraction of the Price
Chinese developers bypass Anthropic's strict geoblocking and KYC measures through "transfer stations" — API proxies hosted overseas — purchasing Claude tokens at roughly 10% of the official price A modular supply chain spans account brokers, SMS verification platforms, reverse-engineering specialists, transfer station operators, and downstream resellers on platforms like Taobao, making the system highly resilient to takedowns Operators undercut prices by farming free credits, exploiting discount
Analysis
TL;DR
- Chinese developers bypass Anthropic's strict geoblocking and KYC measures through "transfer stations" — API proxies hosted overseas — purchasing Claude tokens at roughly 10% of the official price
- A modular supply chain spans account brokers, SMS verification platforms, reverse-engineering specialists, transfer station operators, and downstream resellers on platforms like Taobao, making the system highly resilient to takedowns
- Operators undercut prices by farming free credits, exploiting discounts, splitting accounts across users, and potentially using fraudulently obtained payment methods
- Widespread "model swapping" (called "diluting") reroutes requests from expensive models like Opus to cheaper alternatives like Sonnet or Chinese models such as Qwen, with one fake "Gemini-2.5" endpoint scoring only 37% versus the official 83.82% on medical benchmarks
- The most significant revenue lever may be monetizing usage data — prompts, responses, and tool calls passing through proxies could yield valuable training/distillation datasets, turning users into unpaid data producers
Why It Matters
This gray market exposes critical vulnerabilities in AI access controls that the industry has treated as sufficient, demonstrating that even Anthropic's most rigorous verification — including biometric checks — can be circumvented at scale. For AI practitioners and providers, it raises urgent questions about data security, model provenance, and the unintended consequence of creating black markets that fuel broader cybercrime ecosystems including identity fraud and payment fraud.
Technical Details
- Transfer station architecture: API proxies hosted on servers outside China accept requests in Chinese yuan via WeChat/Alipay, forward them through legitimate accounts, and relay responses back — eliminating the need for VPNs or foreign credit cards
- Modular supply chain: Upstream actors include account brokers mass-registering Anthropic accounts, SMS verification platforms providing foreign numbers, and reverse-engineering specialists studying detection methods; downstream resellers market access on Taobao, with most participants running only one or two links
- KYC circumvention: AI-generated fake IDs and deepfake technology bypass biometric selfie checks; in some cases, real people in low-income countries are recruited for verifications, echoing the Worldcoin iris-scan black market where scans from Cambodia and Kenya traded for under $30
- Model swapping ("diluting"): Proxies silently reroute requests to cheaper models; CISPA Helmholtz Center researchers examined 17 API proxies and found widespread swapping, with one endpoint claiming to be "Gemini-2.5" performing at less than half the official benchmark score
- Data monetization hypothesis: Every request through a proxy exposes prompts, responses, tool calls, and iterations; coding agents can leak additional codebase context, and unprovenanced Claude Opus 4.6 reasoning datasets are already circulating on HuggingFace
Industry Insight
AI providers must treat access control as an arms race rather than a one-time implementation — geoblocking, payment verification, and even biometric KYC are surmountable when economic incentives are high enough, requiring continuous investment in detection infrastructure and adaptive countermeasures. The "diluting" practice reveals that proxy operators can silently degrade service quality, meaning users may believe they're accessing premium models while receiving inferior outputs — a trust and transparency problem that could erode confidence in API-based AI ecosystems if left unaddressed. The data monetization angle represents a emerging threat vector: rock-bottom pricing may be a customer acquisition strategy where the real profit comes from harvesting usage logs, turning developers into unwitting data suppliers and raising significant IP and privacy concerns that providers should proactively address through monitoring and terms enforcement.
Disclaimer: The above content is generated by AI and is for reference only.