2 min read

The Chinese Grey Market Selling Cheap Claude Access

The Chinese Grey Market Selling Cheap Claude Access

A gray market of API resellers, known in China as "transfer stations" (中转站), lets developers access Anthropic's models at as little as 10% of the official price, according to research from Oxford China Policy Lab's Zilan Qian. The White House and Anthropic have both characterized similar activity as coordinated distillation attacks, with an April 2026 White House memo warning of "industrial-scale" campaigns using tens of thousands of proxy accounts, and Anthropic separately reporting a single proxy network managing more than 20,000 fraudulent accounts. Qian's research argues both framings miss something important: underneath the handful of labs allegedly trying to copy frontier models sits a much larger, more mundane market of professors, students, developers, and hobbyists who just want cheaper access to tools they can't otherwise reach.

That distinction matters because it changes what problem anyone is trying to solve.

Every layer of access control has produced a matching layer of evasion

Qian's central point is a pattern familiar to anyone who's watched digital black markets evolve: geoblocking, phone verification, credit card requirements, and now biometric identity checks each get met with dedicated workaround infrastructure, in this case SMS verification farms and biometric harvesting operations built specifically to satisfy know-your-customer checks on someone else's behalf. That's a meaningfully different problem than "Chinese labs are copying our models." It means the people whose identities and phone numbers get used to pass verification are often not the ones actually using the access, and are frequently already vulnerable people caught in a supply chain they don't understand, according to Qian's analysis.

The scale is what makes this more than a curiosity. Anthropic's models are, per Qian's citation of prior reporting, genuinely popular among Chinese developers, and the proxy market exists because real demand for the product exceeds what official access channels allow at an affordable price. Blocking accounts and monitoring for fraud treats the symptom, since the underlying incentive, cheaper access to a product people want, doesn't disappear when one proxy network gets shut down.

Why this matters beyond the US-China frame

The transfer station economy is a case study in what account-based access controls can and can't actually verify. If proxy logs become a tradeable commodity, used for everything from model training data to targeted fraud, then a company's confidence about who is actually using its product, and for what, gets weaker even as its official verification requirements get stricter. That's a governance problem, not just a compliance one, and it applies to any platform layering identity checks onto access, not just frontier AI labs.

For companies building AI-dependent products or services, the lesson isn't about China specifically. It's that access control built purely on verification gates tends to create a market for defeating the gate, and the people actually harmed by that market are often the least visible part of it. Understanding where your own product sits in that dynamic is worth real attention before regulation forces the question.

If your team is trying to think through how AI governance and access trends actually affect your business, rather than just the headlines about them, that's the kind of analysis our growth strategy work is built to provide, and our AI marketing services team can help you navigate what's coming next.