China's gray market sells Claude tokens at a tenth of the list price
Anthropic runs what are probably the strictest access controls of any major AI provider when it comes to China — phone and billing checks, bans on majority-Chinese-owned firms, and even live-selfie ID verification for some users. Yet Chinese developers can still buy Claude tokens for roughly 10 percent of the official price. A detailed analysis by Zilan Qian, a researcher at the Oxford China Policy Lab and published by ChinaTalk, maps the thriving gray market of "transfer stations" that routes around every layer of the wall.
Chinese developers buy Claude tokens through "transfer stations" for about a tenth of list price, quietly defeating Anthropic's geoblocking and identity checks. These API proxies sit on overseas servers, accept requests from developers and forward them as if they came from a legitimate location, with payment settled in yuan through WeChat or Alipay. No VPN, no foreign card, no selfie. Qian argues the network is far more than a security nuisance — it is a modular supply chain in which account brokers mass-register Anthropic accounts, SMS platforms supply foreign numbers, and specialists reverse-engineer Anthropic's detection. When one link is banned, a replacement comes up within hours, and customers range from students and hobbyists to companies and AI labs looking to distill a stronger Western model's outputs.
Sellers hit those rock-bottom prices several ways: farming free credits, splitting a single $200 Max plan across users, and quietly swapping an expensive model like Opus for cheaper alternatives or even Qwen — a practice the community calls "diluting." The biggest margin, Qian contends, may be in the usage data every request leaves behind, since prompts, responses, and tool calls pass through the proxy unencrypted to its operator. That claim is unproven, but it would turn each user into both a paying customer and an unpaid data producer.
The stakes go well beyond price arbitrage: this circumvention weakens both export controls and Anthropic's own safety monitoring. When a request arrives proxied, Anthropic sees the proxy's account and IP rather than the end user, which can blunt systems designed to catch coordinated abuse spread across many accounts. Qian notes the methods a geoblocked developer uses are structurally identical to what a bad actor would use to reach frontier models untraced. The infrastructure also feeds criminal markets — biometric data collected for KYC workarounds can be resold for fraud, and account farming supports spam and phishing.
That matters because Anthropic, OpenAI, and Google have spent months fighting unauthorized distillation. Anthropic previously accused DeepSeek, Moonshot, and MiniMax of running more than 24,000 fake accounts to generate over 16 million requests against Claude. But the industry is split on whether distillation is even a problem — 25 companies including Nvidia, Microsoft, and Meta have warned against premature restrictions. That split makes US regulation over distillation alone unlikely, leaving the labs to enforce their own terms of service. As Qian's report shows, those safeguards are not holding up.
If access restrictions mostly create their own black markets, is distilling a stronger model from the outside any worse than training on everyone else's data? Tell us in the comments.
Sources: ChinaTalk — How to Buy Cheap Claude Tokens in China · The Decoder