A growing gray market in China is allowing developers and other users to access Anthropic’s Claude AI models at 70% to 90% below official prices, despite Anthropic’s restrictions on access from China. The market relies on intermediary services known as “transfer stations” that route requests through overseas servers, effectively creating an unofficial supply chain for access to Claude.

The discounts, however, come with significant risks. An analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, found that these intermediary services can exploit free credits, enterprise and education discounts, shared subscriptions and potentially fraudulent payment methods. Some operators can also substitute cheaper AI models for the models customers believe they are purchasing, while the prompts and outputs passing through the proxies may become valuable data for the operators.

China’s Claude Gray Market At A Glance

ParticularDetails
AI providerAnthropic
AI serviceClaude
MarketChina
Access mechanismUnofficial API proxy/“transfer stations”
Reported discount70%-90% below official pricing
Potential effective priceAs low as about 10% of list price
Payment methodsRMB-based payments, including Chinese platforms
Overseas infrastructureUsed to route API requests
CustomersDevelopers, companies, students and other users
Main risksData exposure, model substitution, fraud and account shutdowns
Researcher citedZilan Qian, Oxford China Policy Lab
Official Anthropic accessRestricted in China

The market is not a single centralized operation. Instead, it is described as a modular network of account brokers, verification providers, proxy operators, resellers and end users.

How The Claude Transfer Station Market Works

The central players are known as transfer stations, or 中转站. These services act as intermediaries between Chinese users and overseas AI providers.

Instead of a Chinese developer connecting directly to Anthropic, the developer sends a request to the intermediary. The intermediary then forwards the request to Anthropic using an account or API access obtained through another route.

Chinese Developer
       ↓
Transfer Station
       ↓
Overseas Proxy Server
       ↓
Anthropic / Claude
       ↓
Response
       ↓
Transfer Station
       ↓
Chinese Developer

This structure allows users to access models that are officially unavailable to them while making it harder for the AI provider to identify the actual end user behind an individual request.

Why Claude Access Is Restricted In China

Anthropic has implemented strict access controls for users and organizations in unsupported regions.

According to The Decoder, the company checks factors including phone numbers, foreign payment cards and billing addresses. Certain users may also be asked to complete identity verification involving government identification and a live selfie. Companies that are more than 50% owned, directly or indirectly, by entities in unsupported regions can also face restrictions.

Anthropic’s Reported Access Controls

ControlPurpose
Phone-number checksVerify user identity/location
Foreign payment cardsRestrict unsupported-region payments
Billing-address checksEstablish geographic eligibility
ID verificationAdditional identity confirmation
Live selfieBiometric verification for selected users
Corporate ownership checksRestrict entities linked to unsupported regions

Despite these controls, the gray market has developed an alternative access infrastructure.

Claude Tokens Can Be Sold At 70%-90% Discounts

One of the most striking characteristics of the market is its pricing.

Operators can reportedly sell Claude access at 70% to 90% below official prices, according to Qian’s analysis. Some services effectively offer access at roughly one-tenth of the official price.

This pricing is possible because operators are not necessarily purchasing every token through standard retail API pricing.

Instead, they can combine several sources of low-cost or subsidized access.

How Gray-Market Operators Reduce Costs

MethodHow It Works
Free-credit farmingMultiple accounts collect promotional credits
Education discountsDiscounted access is resold
Enterprise discountsLower-cost access is divided among users
Subscription sharingOne paid plan is distributed across multiple customers
Payment abusePotentially fraudulent cards can fund accounts
Model substitutionCheaper models replace expensive ones
Data monetizationUser requests may become a source of value

The combination allows resellers to maintain a large gap between their selling price and their effective acquisition cost.

The “One Fish, Three Meals” Economics

The gray market’s economics can involve more than simply buying tokens cheaply and selling them at a markup.

The underlying business model can potentially generate value from three different sources:

Cheap / Subsidized AI Access
          ↓
   ┌──────┼────────┐
   ↓      ↓        ↓
Resale  Model    Data
Margin  Swapping Monetization
   │      │        │
   └──────┼────────┘
          ↓
     Gray-Market
       Revenue

The first source is the resale of discounted or fraudulently obtained capacity.

The second is the possibility of quietly routing requests to cheaper models.

The third—and potentially most valuable—is the information generated by users’ requests.

Model Substitution Creates A Major Trust Problem

A particularly concerning feature is model substitution.

A customer may believe they are paying for a high-end Claude model, but the intermediary controls the routing layer and can potentially send the request to a less expensive model.

The user may not immediately realize the difference.

Customer Requests
Premium Claude Model
        ↓
   Gray-Market Proxy
        ↓
 ┌──────┴────────┐
 ↓               ↓
Premium Model   Cheaper Model
Actually Used   Secretly Used

This means the user is not necessarily buying the model advertised by the reseller.

Researchers at Germany’s CISPA Helmholtz Center for Information Security examined 17 API proxies and found evidence of widespread model substitution, according to Qian’s analysis. One endpoint advertised as Gemini-2.5 reportedly produced a score of only 37% on a medical benchmark, compared with 83.82% for the official model.

Why Model Substitution Matters

ProblemImpact
User pays for premium modelHigher-than-necessary cost
Cheaper model is substitutedLower performance
Model identity becomes unclearBenchmark results become unreliable
Sensitive workloads use unknown modelsSecurity risk
Enterprise applications depend on proxyReliability concerns

For developers building products on top of these services, the problem can become especially serious because they may not know which model actually processed their data.

User Data Could Be More Valuable Than The Tokens

The most significant concern may not be the discounted access itself.

It is the data passing through the intermediary.

A transfer station necessarily sees the requests it forwards unless its architecture provides some form of end-to-end protection that prevents the operator from accessing the content.

That means the operator could potentially see:

  • Prompts
  • Model responses
  • Tool calls
  • Coding instructions
  • Codebase context
  • Iterative agent interactions
  • Business information

The Decoder reports that Qian considers usage data potentially one of the most valuable assets generated by the ecosystem.

Coding Agents Could Expose Even More Information

The data risk becomes larger when AI agents are involved.

A simple chatbot prompt might contain a short question.

A coding agent can send extensive information about a software repository, configuration files, errors, dependencies and development workflow.

Developer
   ↓
Coding Agent
   ↓
Repository Context
   ↓
Multiple AI Requests
   ↓
Transfer Station
   ↓
Claude / Other Model

A proxy operator could therefore potentially see far more than a user’s individual question.

For companies using AI coding tools, this could expose proprietary source code or internal development information.

Data Security Risks Of Gray-Market AI

Data TypePotential Risk
Personal informationPrivacy exposure
Source codeIntellectual-property theft
Business plansCompetitive intelligence
Customer dataConfidentiality breach
ResearchLoss of proprietary knowledge
AI promptsTraining/distillation value
Agent tracesExposure of workflows
API credentialsPotential security compromise

This is why the apparent cost savings can be misleading.

A developer might save 80% on AI inference while exposing information that is worth considerably more than the savings.

Identity Verification Is Also Being Bypassed

Anthropic’s newer identity-verification requirements have not eliminated the gray market.

According to Qian’s analysis, workarounds include fake identity documents, deepfake technology and, in some cases, recruiting real people in lower-income countries to complete verification processes.

These methods are part of a broader identity-verification gray market that has appeared around other technology services.

Anthropic KYC
     ↓
ID + Live Selfie
     ↓
Attempted Circumvention
     ↓
Fake Documents
OR
Deepfake Technology
OR
Third-Party Human Verification
     ↓
Unofficial Account

The existence of such infrastructure means stronger verification can raise the cost of unauthorized access without necessarily eliminating it.

A Modular Supply Chain Makes The Market Harder To Stop

One reason the ecosystem is difficult to shut down is that responsibility is divided among multiple participants.

An account broker may never interact directly with an end user.

A verification provider may only provide phone numbers.

A transfer station may only route API traffic.

A reseller may only market the service.

Gray-Market Supply Chain

ParticipantRole
Account brokersRegister and supply accounts
SMS providersSupply foreign phone numbers
Verification servicesHelp complete identity checks
Proxy operatorsRoute AI requests
ResellersSell access to users
End usersConsume AI capacity
Data buyersPotentially monetize collected information

This modular structure makes enforcement more difficult because shutting down one component does not necessarily eliminate the entire market.

Chinese E-Commerce Platforms Are Part Of The Distribution Network

The market is not necessarily hidden entirely in obscure corners of the internet.

The Decoder reports that Claude access is marketed through Chinese online marketplaces such as Taobao, while other services and discussions can appear on GitHub and messaging platforms.

This creates a relatively accessible distribution network for users seeking discounted AI access.

Where Gray-Market Access Can Be Promoted

GitHub
   +
Taobao
   +
Telegram
   +
Developer Communities
   ↓
Transfer Stations
   ↓
Chinese AI Users

The public-facing nature of some of these services highlights the scale of demand for access to foreign AI models.

The Gray Market Is Not Limited To Claude

The broader gray market extends beyond Anthropic.

Security researchers have identified similar services offering discounted access to multiple frontier AI systems, including Claude, GPT and Gemini. Okta researchers recently reported discovering services advertising discounted or “unlimited” access through fraudulent registrations and abused cloud credits.

This suggests that the underlying economic model is broader than one company’s restrictions.

AI Models Targeted By Gray-Market Services

AI ProviderPotential Gray-Market Issue
AnthropicClaude access proxies
OpenAIAccount and token resale
GoogleModel access proxies
Other providersDiscounted or unauthorized API access

Where official access is expensive or restricted, intermediaries can have a strong incentive to create alternative channels.

Geoblocking Can Create An Arbitrage Market

The situation illustrates a broader economic principle.

When there is strong demand for a product but official access is restricted or expensive, intermediaries may attempt to arbitrage the difference.

High Demand
     +
Restricted Supply
     +
Large Price Difference
     ↓
Arbitrage Opportunity
     ↓
Gray Market

The gray market does not necessarily eliminate the demand.

Instead, it changes how the demand is satisfied.

In this case, the result is a network that can undermine both access controls and safety monitoring.

Anthropic May Lose Visibility Into End Users

When a user connects directly to Anthropic, the company can associate activity with its own account and infrastructure.

A proxy changes that relationship.

Anthropic may see the intermediary’s account and IP address rather than the actual individual using the service.

Direct Access

User
 ↓
Anthropic
 ↓
User Identity Visible


Proxy Access

User
 ↓
Transfer Station
 ↓
Anthropic
 ↓
Proxy Identity Visible

The Decoder reports that this can make it more difficult for Anthropic to identify misuse and understand who is actually making requests.

The Safety Implications Go Beyond China

The issue is not simply whether Chinese developers can access Claude.

The same architecture can potentially be used by malicious actors attempting to hide their identities while accessing powerful AI systems.

Qian’s analysis argues that methods used to bypass geographic restrictions can resemble the infrastructure that a malicious actor might use to reach frontier models without being easily traced.

Why AI Providers Care

RiskPotential Consequence
Proxy accountsUser identity obscured
Multiple accountsHarder abuse detection
Model substitutionLoss of control over model identity
Data harvestingPrivacy and security concerns
Fraudulent paymentsFinancial losses
Automated agentsLarger-scale misuse
Cross-border proxiesHarder enforcement

The gray market therefore creates a challenge for both commercial access control and AI safety.

AI Pricing Is Becoming An Important Competitive Factor

The emergence of gray-market AI services also highlights the importance of pricing.

If the gap between official pricing and unofficial pricing becomes extremely large, users have greater incentives to seek alternatives.

The reported 70%-90% discounts demonstrate how significant that gap can become.

Official Market Vs Gray Market

FactorOfficial AccessGray Market
PricingList priceUp to 90% lower
IdentityVerifiedOften unclear
Model identityKnownMay be substituted
Data handlingProvider policiesProxy operator controls
ReliabilityOfficial infrastructureDepends on reseller
ComplianceFormal termsPotentially unauthorized
Account stabilityHigherCan disappear suddenly

The low price therefore comes with a very different risk profile.

Cheap AI Tokens May Not Be Cheap

For developers, the most important lesson is that the sticker price of AI inference does not capture the total cost.

A gray-market provider could save a developer money on tokens while exposing sensitive information, delivering an inferior model or unexpectedly terminating access.

For enterprise users, those risks could easily outweigh the financial savings.

Lower Token Price
       ↓
Potential Savings
       +
Data Exposure
       +
Model Substitution
       +
Reliability Risk
       +
Compliance Risk
       ↓
Potentially Higher
Total Cost

This makes the economics of gray-market AI considerably more complicated than a simple price comparison.

The Market Could Also Affect AI Model Distillation

The large amount of AI usage flowing through intermediaries could potentially create another source of value: model-training and distillation data.

A proxy operator potentially has access to large quantities of prompts, responses and interaction traces.

If those datasets are collected and reused, they could provide information about how frontier models solve different problems.

The Decoder reports that Qian identifies this as a potential economic incentive for operators.

Potential Value Of Collected AI Data

DataPotential Value
PromptsReveals user problems
ResponsesShows model behavior
Reasoning tracesPotential training/distillation value
Coding tasksValuable software examples
Tool callsReveals agent workflows
Iterative interactionsShows how problems are solved

The exact scale of such monetization is difficult to establish from publicly available evidence, but the potential incentive exists.

The Broader AI Industry Faces A New Access Problem

The gray-market phenomenon suggests that geographic restrictions alone may not be sufficient to control access to powerful AI models.

As AI becomes more valuable, users have stronger incentives to find alternative access routes.

That creates a continuing contest between:

AI providers improving access controls

and

intermediaries finding new ways around them.

Provider Restrictions
        ↓
New Circumvention Method
        ↓
Provider Detection
        ↓
Stronger Restrictions
        ↓
New Circumvention Method
        ↓
Gray-Market Evolution

This could become an ongoing feature of the global AI market.

The Bigger Picture

China’s gray market for Claude illustrates how difficult it can be to enforce geographic restrictions on highly sought-after AI models. Anthropic has introduced increasingly strict controls, including payment checks, billing verification and identity checks, yet intermediary networks known as transfer stations have created alternative channels through overseas proxy infrastructure. These services reportedly sell access at discounts of 70% to 90%, attracting developers and other users who cannot or do not want to access Claude through official channels.

The bigger concern is that the gray market can undermine more than pricing and geographic controls. Proxy operators may potentially see prompts, responses and coding-agent context, while model substitution means customers cannot always be certain which AI system is processing their requests. Researchers have also identified risks involving fraudulent accounts, stolen payment methods and the potential monetization of usage data.

The phenomenon also highlights a difficult trade-off for AI companies. Stronger access restrictions can protect models and reduce unauthorized usage, but when demand remains high, restrictions can create incentives for intermediaries to build alternative supply chains. Those supply chains can be harder for providers to monitor and may create greater privacy and safety risks than official access.

Looking Ahead

The gray market for Claude and other frontier AI models is likely to remain a moving target as providers strengthen identity verification, payment controls and abuse detection. Intermediaries have already demonstrated that they can combine account farming, discounted subscriptions, proxy infrastructure and other techniques to create cheaper access channels. As AI agents become more widely used, the amount and sensitivity of information passing through such intermediaries could also increase significantly.

For businesses and developers, the reported discounts therefore come with a major warning: cheap AI access can carry an invisible data cost. Users may not know where their prompts are going, which model is actually processing them or how their information is being stored and reused. The challenge for Anthropic and other AI providers will be to balance geographic and security restrictions with mechanisms that preserve trust, privacy and safety. The growth of China’s transfer-station economy suggests that simply blocking access may not be enough when demand for frontier AI remains strong

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.