A growing gray market in China is allowing developers and other users to access Anthropic’s Claude AI models at 70% to 90% below official prices, despite Anthropic’s restrictions on access from China. The market relies on intermediary services known as “transfer stations” that route requests through overseas servers, effectively creating an unofficial supply chain for access to Claude.
The discounts, however, come with significant risks. An analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, found that these intermediary services can exploit free credits, enterprise and education discounts, shared subscriptions and potentially fraudulent payment methods. Some operators can also substitute cheaper AI models for the models customers believe they are purchasing, while the prompts and outputs passing through the proxies may become valuable data for the operators.
China’s Claude Gray Market At A Glance
| Particular | Details |
|---|---|
| AI provider | Anthropic |
| AI service | Claude |
| Market | China |
| Access mechanism | Unofficial API proxy/“transfer stations” |
| Reported discount | 70%-90% below official pricing |
| Potential effective price | As low as about 10% of list price |
| Payment methods | RMB-based payments, including Chinese platforms |
| Overseas infrastructure | Used to route API requests |
| Customers | Developers, companies, students and other users |
| Main risks | Data exposure, model substitution, fraud and account shutdowns |
| Researcher cited | Zilan Qian, Oxford China Policy Lab |
| Official Anthropic access | Restricted in China |
The market is not a single centralized operation. Instead, it is described as a modular network of account brokers, verification providers, proxy operators, resellers and end users.
How The Claude Transfer Station Market Works
The central players are known as transfer stations, or 中转站. These services act as intermediaries between Chinese users and overseas AI providers.
Instead of a Chinese developer connecting directly to Anthropic, the developer sends a request to the intermediary. The intermediary then forwards the request to Anthropic using an account or API access obtained through another route.
Chinese Developer
↓
Transfer Station
↓
Overseas Proxy Server
↓
Anthropic / Claude
↓
Response
↓
Transfer Station
↓
Chinese Developer
This structure allows users to access models that are officially unavailable to them while making it harder for the AI provider to identify the actual end user behind an individual request.
Why Claude Access Is Restricted In China
Anthropic has implemented strict access controls for users and organizations in unsupported regions.
According to The Decoder, the company checks factors including phone numbers, foreign payment cards and billing addresses. Certain users may also be asked to complete identity verification involving government identification and a live selfie. Companies that are more than 50% owned, directly or indirectly, by entities in unsupported regions can also face restrictions.
Anthropic’s Reported Access Controls
| Control | Purpose |
|---|---|
| Phone-number checks | Verify user identity/location |
| Foreign payment cards | Restrict unsupported-region payments |
| Billing-address checks | Establish geographic eligibility |
| ID verification | Additional identity confirmation |
| Live selfie | Biometric verification for selected users |
| Corporate ownership checks | Restrict entities linked to unsupported regions |
Despite these controls, the gray market has developed an alternative access infrastructure.
Claude Tokens Can Be Sold At 70%-90% Discounts
One of the most striking characteristics of the market is its pricing.
Operators can reportedly sell Claude access at 70% to 90% below official prices, according to Qian’s analysis. Some services effectively offer access at roughly one-tenth of the official price.
This pricing is possible because operators are not necessarily purchasing every token through standard retail API pricing.
Instead, they can combine several sources of low-cost or subsidized access.
How Gray-Market Operators Reduce Costs
| Method | How It Works |
|---|---|
| Free-credit farming | Multiple accounts collect promotional credits |
| Education discounts | Discounted access is resold |
| Enterprise discounts | Lower-cost access is divided among users |
| Subscription sharing | One paid plan is distributed across multiple customers |
| Payment abuse | Potentially fraudulent cards can fund accounts |
| Model substitution | Cheaper models replace expensive ones |
| Data monetization | User requests may become a source of value |
The combination allows resellers to maintain a large gap between their selling price and their effective acquisition cost.
The “One Fish, Three Meals” Economics
The gray market’s economics can involve more than simply buying tokens cheaply and selling them at a markup.
The underlying business model can potentially generate value from three different sources:
Cheap / Subsidized AI Access
↓
┌──────┼────────┐
↓ ↓ ↓
Resale Model Data
Margin Swapping Monetization
│ │ │
└──────┼────────┘
↓
Gray-Market
Revenue
The first source is the resale of discounted or fraudulently obtained capacity.
The second is the possibility of quietly routing requests to cheaper models.
The third—and potentially most valuable—is the information generated by users’ requests.
Model Substitution Creates A Major Trust Problem
A particularly concerning feature is model substitution.
A customer may believe they are paying for a high-end Claude model, but the intermediary controls the routing layer and can potentially send the request to a less expensive model.
The user may not immediately realize the difference.
Customer Requests
Premium Claude Model
↓
Gray-Market Proxy
↓
┌──────┴────────┐
↓ ↓
Premium Model Cheaper Model
Actually Used Secretly Used
This means the user is not necessarily buying the model advertised by the reseller.
Researchers at Germany’s CISPA Helmholtz Center for Information Security examined 17 API proxies and found evidence of widespread model substitution, according to Qian’s analysis. One endpoint advertised as Gemini-2.5 reportedly produced a score of only 37% on a medical benchmark, compared with 83.82% for the official model.
Why Model Substitution Matters
| Problem | Impact |
|---|---|
| User pays for premium model | Higher-than-necessary cost |
| Cheaper model is substituted | Lower performance |
| Model identity becomes unclear | Benchmark results become unreliable |
| Sensitive workloads use unknown models | Security risk |
| Enterprise applications depend on proxy | Reliability concerns |
For developers building products on top of these services, the problem can become especially serious because they may not know which model actually processed their data.
User Data Could Be More Valuable Than The Tokens
The most significant concern may not be the discounted access itself.
It is the data passing through the intermediary.
A transfer station necessarily sees the requests it forwards unless its architecture provides some form of end-to-end protection that prevents the operator from accessing the content.
That means the operator could potentially see:
- Prompts
- Model responses
- Tool calls
- Coding instructions
- Codebase context
- Iterative agent interactions
- Business information
The Decoder reports that Qian considers usage data potentially one of the most valuable assets generated by the ecosystem.
Coding Agents Could Expose Even More Information
The data risk becomes larger when AI agents are involved.
A simple chatbot prompt might contain a short question.
A coding agent can send extensive information about a software repository, configuration files, errors, dependencies and development workflow.
Developer
↓
Coding Agent
↓
Repository Context
↓
Multiple AI Requests
↓
Transfer Station
↓
Claude / Other Model
A proxy operator could therefore potentially see far more than a user’s individual question.
For companies using AI coding tools, this could expose proprietary source code or internal development information.
Data Security Risks Of Gray-Market AI
| Data Type | Potential Risk |
|---|---|
| Personal information | Privacy exposure |
| Source code | Intellectual-property theft |
| Business plans | Competitive intelligence |
| Customer data | Confidentiality breach |
| Research | Loss of proprietary knowledge |
| AI prompts | Training/distillation value |
| Agent traces | Exposure of workflows |
| API credentials | Potential security compromise |
This is why the apparent cost savings can be misleading.
A developer might save 80% on AI inference while exposing information that is worth considerably more than the savings.
Identity Verification Is Also Being Bypassed
Anthropic’s newer identity-verification requirements have not eliminated the gray market.
According to Qian’s analysis, workarounds include fake identity documents, deepfake technology and, in some cases, recruiting real people in lower-income countries to complete verification processes.
These methods are part of a broader identity-verification gray market that has appeared around other technology services.
Anthropic KYC
↓
ID + Live Selfie
↓
Attempted Circumvention
↓
Fake Documents
OR
Deepfake Technology
OR
Third-Party Human Verification
↓
Unofficial Account
The existence of such infrastructure means stronger verification can raise the cost of unauthorized access without necessarily eliminating it.
A Modular Supply Chain Makes The Market Harder To Stop
One reason the ecosystem is difficult to shut down is that responsibility is divided among multiple participants.
An account broker may never interact directly with an end user.
A verification provider may only provide phone numbers.
A transfer station may only route API traffic.
A reseller may only market the service.
Gray-Market Supply Chain
| Participant | Role |
|---|---|
| Account brokers | Register and supply accounts |
| SMS providers | Supply foreign phone numbers |
| Verification services | Help complete identity checks |
| Proxy operators | Route AI requests |
| Resellers | Sell access to users |
| End users | Consume AI capacity |
| Data buyers | Potentially monetize collected information |
This modular structure makes enforcement more difficult because shutting down one component does not necessarily eliminate the entire market.
Chinese E-Commerce Platforms Are Part Of The Distribution Network
The market is not necessarily hidden entirely in obscure corners of the internet.
The Decoder reports that Claude access is marketed through Chinese online marketplaces such as Taobao, while other services and discussions can appear on GitHub and messaging platforms.
This creates a relatively accessible distribution network for users seeking discounted AI access.
Where Gray-Market Access Can Be Promoted
GitHub
+
Taobao
+
Telegram
+
Developer Communities
↓
Transfer Stations
↓
Chinese AI Users
The public-facing nature of some of these services highlights the scale of demand for access to foreign AI models.
The Gray Market Is Not Limited To Claude
The broader gray market extends beyond Anthropic.
Security researchers have identified similar services offering discounted access to multiple frontier AI systems, including Claude, GPT and Gemini. Okta researchers recently reported discovering services advertising discounted or “unlimited” access through fraudulent registrations and abused cloud credits.
This suggests that the underlying economic model is broader than one company’s restrictions.
AI Models Targeted By Gray-Market Services
| AI Provider | Potential Gray-Market Issue |
|---|---|
| Anthropic | Claude access proxies |
| OpenAI | Account and token resale |
| Model access proxies | |
| Other providers | Discounted or unauthorized API access |
Where official access is expensive or restricted, intermediaries can have a strong incentive to create alternative channels.
Geoblocking Can Create An Arbitrage Market
The situation illustrates a broader economic principle.
When there is strong demand for a product but official access is restricted or expensive, intermediaries may attempt to arbitrage the difference.
High Demand
+
Restricted Supply
+
Large Price Difference
↓
Arbitrage Opportunity
↓
Gray Market
The gray market does not necessarily eliminate the demand.
Instead, it changes how the demand is satisfied.
In this case, the result is a network that can undermine both access controls and safety monitoring.
Anthropic May Lose Visibility Into End Users
When a user connects directly to Anthropic, the company can associate activity with its own account and infrastructure.
A proxy changes that relationship.
Anthropic may see the intermediary’s account and IP address rather than the actual individual using the service.
Direct Access
User
↓
Anthropic
↓
User Identity Visible
Proxy Access
User
↓
Transfer Station
↓
Anthropic
↓
Proxy Identity Visible
The Decoder reports that this can make it more difficult for Anthropic to identify misuse and understand who is actually making requests.
The Safety Implications Go Beyond China
The issue is not simply whether Chinese developers can access Claude.
The same architecture can potentially be used by malicious actors attempting to hide their identities while accessing powerful AI systems.
Qian’s analysis argues that methods used to bypass geographic restrictions can resemble the infrastructure that a malicious actor might use to reach frontier models without being easily traced.
Why AI Providers Care
| Risk | Potential Consequence |
|---|---|
| Proxy accounts | User identity obscured |
| Multiple accounts | Harder abuse detection |
| Model substitution | Loss of control over model identity |
| Data harvesting | Privacy and security concerns |
| Fraudulent payments | Financial losses |
| Automated agents | Larger-scale misuse |
| Cross-border proxies | Harder enforcement |
The gray market therefore creates a challenge for both commercial access control and AI safety.
AI Pricing Is Becoming An Important Competitive Factor
The emergence of gray-market AI services also highlights the importance of pricing.
If the gap between official pricing and unofficial pricing becomes extremely large, users have greater incentives to seek alternatives.
The reported 70%-90% discounts demonstrate how significant that gap can become.
Official Market Vs Gray Market
| Factor | Official Access | Gray Market |
|---|---|---|
| Pricing | List price | Up to 90% lower |
| Identity | Verified | Often unclear |
| Model identity | Known | May be substituted |
| Data handling | Provider policies | Proxy operator controls |
| Reliability | Official infrastructure | Depends on reseller |
| Compliance | Formal terms | Potentially unauthorized |
| Account stability | Higher | Can disappear suddenly |
The low price therefore comes with a very different risk profile.
Cheap AI Tokens May Not Be Cheap
For developers, the most important lesson is that the sticker price of AI inference does not capture the total cost.
A gray-market provider could save a developer money on tokens while exposing sensitive information, delivering an inferior model or unexpectedly terminating access.
For enterprise users, those risks could easily outweigh the financial savings.
Lower Token Price
↓
Potential Savings
+
Data Exposure
+
Model Substitution
+
Reliability Risk
+
Compliance Risk
↓
Potentially Higher
Total Cost
This makes the economics of gray-market AI considerably more complicated than a simple price comparison.
The Market Could Also Affect AI Model Distillation
The large amount of AI usage flowing through intermediaries could potentially create another source of value: model-training and distillation data.
A proxy operator potentially has access to large quantities of prompts, responses and interaction traces.
If those datasets are collected and reused, they could provide information about how frontier models solve different problems.
The Decoder reports that Qian identifies this as a potential economic incentive for operators.
Potential Value Of Collected AI Data
| Data | Potential Value |
|---|---|
| Prompts | Reveals user problems |
| Responses | Shows model behavior |
| Reasoning traces | Potential training/distillation value |
| Coding tasks | Valuable software examples |
| Tool calls | Reveals agent workflows |
| Iterative interactions | Shows how problems are solved |
The exact scale of such monetization is difficult to establish from publicly available evidence, but the potential incentive exists.
The Broader AI Industry Faces A New Access Problem
The gray-market phenomenon suggests that geographic restrictions alone may not be sufficient to control access to powerful AI models.
As AI becomes more valuable, users have stronger incentives to find alternative access routes.
That creates a continuing contest between:
AI providers improving access controls
and
intermediaries finding new ways around them.
Provider Restrictions
↓
New Circumvention Method
↓
Provider Detection
↓
Stronger Restrictions
↓
New Circumvention Method
↓
Gray-Market Evolution
This could become an ongoing feature of the global AI market.
The Bigger Picture
China’s gray market for Claude illustrates how difficult it can be to enforce geographic restrictions on highly sought-after AI models. Anthropic has introduced increasingly strict controls, including payment checks, billing verification and identity checks, yet intermediary networks known as transfer stations have created alternative channels through overseas proxy infrastructure. These services reportedly sell access at discounts of 70% to 90%, attracting developers and other users who cannot or do not want to access Claude through official channels.
The bigger concern is that the gray market can undermine more than pricing and geographic controls. Proxy operators may potentially see prompts, responses and coding-agent context, while model substitution means customers cannot always be certain which AI system is processing their requests. Researchers have also identified risks involving fraudulent accounts, stolen payment methods and the potential monetization of usage data.
The phenomenon also highlights a difficult trade-off for AI companies. Stronger access restrictions can protect models and reduce unauthorized usage, but when demand remains high, restrictions can create incentives for intermediaries to build alternative supply chains. Those supply chains can be harder for providers to monitor and may create greater privacy and safety risks than official access.
Looking Ahead
The gray market for Claude and other frontier AI models is likely to remain a moving target as providers strengthen identity verification, payment controls and abuse detection. Intermediaries have already demonstrated that they can combine account farming, discounted subscriptions, proxy infrastructure and other techniques to create cheaper access channels. As AI agents become more widely used, the amount and sensitivity of information passing through such intermediaries could also increase significantly.
For businesses and developers, the reported discounts therefore come with a major warning: cheap AI access can carry an invisible data cost. Users may not know where their prompts are going, which model is actually processing them or how their information is being stored and reused. The challenge for Anthropic and other AI providers will be to balance geographic and security restrictions with mechanisms that preserve trust, privacy and safety. The growth of China’s transfer-station economy suggests that simply blocking access may not be enough when demand for frontier AI remains strong
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



