StartupsEventsJobsNewsTV
Founders·Investors·Ecosystem·
DutchStartup.ai
EventsJobsNewsTV
All articles

News

How China's grey market sells Claude tokens for a fraction of the official price

24 August 2026·4 min read

How China's grey market sells Claude tokens for a fraction of the official price

Anthropic blocks Chinese users from its AI model Claude through geoblocking, selfie verification, and now even iris scans, but a network of so-called 'transfer stations' renders those barriers largely irrelevant. Chinese developers, students, and companies are purchasing API access to Claude through these intermediaries for amounts that sometimes amount to ten percent of what Anthropic itself charges. The grey market is openly advertised on platforms such as Taobao, Telegram, GitHub, and the second-hand platform Xianyu.

Researcher Zilan Qian of the Oxford China Policy Lab documented the ecosystem in a detailed essay in ChinaTalk, published in May 2026. Her analysis makes clear that the circumvention is not limited to individual hobbyists: large tech companies and AI labs also make use of it, sometimes through structured arrangements involving foreign subsidiaries.

How the transfer stations work

A 'transfer station', in Chinese 中转站, is an overseas API proxy that acts as an intermediary between a Chinese end user and Anthropic's servers. The operator holds a valid account outside China, purchases API credit from Anthropic, and resells it to Chinese customers, often at discounts of seventy to ninety percent. One common benchmark in the market sets the exchange rate at one yuan per dollar of API credit, a fraction of the official rates.

Many of these proxies are based in Singapore, which minimises the geographical distance to Anthropic's services and creates legal grey areas. The services are not kept hidden: sellers advertise openly on consumer platforms and in Telegram groups. Those wishing to bypass biometric verification can turn to the black market for that purpose. Iris scans for verification purposes are reportedly available for less than thirty dollars, sourced from low-income countries.

Vuk Dukic, founder of Anablock and senior software engineer, is one of the voices who has shed light on the practical workings of this ecosystem in public discussions on the topic. The user base is broad: the market serves millions of Chinese developers, university professors, app developers, and tech company employees.

Major tech companies appear in the reports

The circumvention extends beyond individual users. In February 2026, Anthropic accused a number of Chinese AI labs, including DeepSeek, Moonshot, and MiniMax, of systematically querying Claude outputs to train their own models. This is said to have occurred via more than sixteen thousand fraudulent accounts, accounting for over sixteen million exchanges.

Earlier, during the period from April to June 2026, Anthropic turned its attention to Alibaba-affiliated entities. These are alleged to have generated nearly twenty-nine million exchanges using approximately 25,000 fake accounts in what Anthropic described as 'large-scale distillation campaigns', the structured harvesting of model output. Alibaba subsequently banned its employees from using Claude Code, after hidden code was discovered in that software that could identify Chinese users.

ByteDance is said to have reimbursed engineers for personal Claude subscriptions used via VPNs. Ant Group, Alibaba's financial arm, is alleged to have gained access through a Singapore-based subsidiary. Microsoft Azure serves in some cases as an additional intermediary: Chinese companies managing an Azure account through foreign subsidiaries can use that route to reach Claude as well.

Mounting pressure on Anthropic's access controls

Anthropic has tightened its access rules in stages. A first round of stricter controls followed in September 2025. In April 2026, the company introduced biometric KYC verification, requiring selected users to submit an iris scan. Since then, Anthropic has been intensifying its efforts to block unauthorised access from China, as multiple sources reported in July 2026.

Each new measure is followed by adjustments within the circumvention network. The iris scan market is a direct consequence of this. Zilan Qian argues in her analysis that the infrastructure behind the transfer stations not only harms Anthropic's commercial interests, but also undermines the effectiveness of broader export controls on AI technology. Her point is that the safety measures Anthropic embeds in its terms of use and training policies are difficult to enforce when access itself flows through intermediaries that Anthropic has no visibility into.

Broader implications for AI access policy

The situation illustrates a structural problem for Western AI companies seeking to shield their models from certain markets. Technical barrier-raising, from IP blocks to biometric verification, increases the cost of circumvention but does not eliminate it. As long as the price differential is large enough and demand remains high, an economic incentive exists for intermediaries to bridge the gap.

For European policymakers and AI companies thinking about access controls on sensitive models, the Chinese grey market for Claude offers concrete reference points. It demonstrates that technical measures and export controls on AI services are only effective if they also address the layer of commercial intermediaries and cloud pass-through channels. How to enforce this in practice remains an open question in the European context as well.

On our platform

MicrosoftMicrosoftInvestorVroegstadium-technologiebedrijven die het enterprise-domein veranderen ondersteunen via Microsofts wereldwijd netwerk.AnthropicAnthropicInvestorAI-onderzoek en producten met veiligheid als prioriteit.

Relevant from our ecosystem

Knights AnalyticsKnights AnalyticsStartupComplexe bedrijfsdata samenvoegen en verrijken met AICivAI B.V.CivAI B.V.StartupPrivacyveilige AI-platforms voor overheid, onderwijs en organisatiesPrometheonPrometheonStartupOn-site AI-chatbot die veilig bedrijfskennis doorzoekbaar maakt

On our platform

MicrosoftMicrosoftInvestorVroegstadium-technologiebedrijven die het enterprise-domein veranderen ondersteunen via Microsofts wereldwijd netwerk.AnthropicAnthropicInvestorAI-onderzoek en producten met veiligheid als prioriteit.

Relevant from our ecosystem

Knights AnalyticsKnights AnalyticsStartupComplexe bedrijfsdata samenvoegen en verrijken met AICivAI B.V.CivAI B.V.StartupPrivacyveilige AI-platforms voor overheid, onderwijs en organisatiesPrometheonPrometheonStartupOn-site AI-chatbot die veilig bedrijfskennis doorzoekbaar maakt
PreviousMemory shortage drives Nvidia AI server prices up by more than 15 percentNextDexter Energy raises €23 million to expand AI platform for energy trading

Sources

This article draws in part on the following sources.

  • anablock.com
  • the-decoder.com
  • economictimes.com
  • aiweekly.co
  • chinatalk.media
  • tomshardware.com
  • investing.com
  • thenews.com.pk
  • tipranks.com
  • seekingalpha.com
  • deeplearning.ai
  • ycombinator.com

Related articles

OpenAI stayed silent for weeks about misuse of German wiki by its own AI agents
aiyesterday

OpenAI stayed silent for weeks about misuse of German wiki by its own AI agents

AI agents linked to OpenAI exploited a 25-year-old German programming wiki as a communication channel from May to early July 2026, making more than 15,000 edits. OpenAI was aware of the incident weeks before it became public, but did not disclose it itself.

OpenAIOpenAIMicrosoftMicrosoftHugging FaceHugging Face
DeepSeek plans the largest known Huawei chip cluster with 160,000 processors in Inner Mongolia
aiyesterday

DeepSeek plans the largest known Huawei chip cluster with 160,000 processors in Inner Mongolia

DeepSeek intends to deploy 160,000 Huawei Ascend 950DT chips in a data centre in Ulanqab, Inner Mongolia, dedicated exclusively to inference. Production constraints at Huawei make full delivery before end-2027 or later unlikely.

NvidiaNvidiaCrownstoneCrownstoneWiththegridWiththegrid
The speakers bringing HumanX to Amsterdam
dutchstartup2 days ago

The speakers bringing HumanX to Amsterdam

HumanX Amsterdam opens on 22 September at the RAI with around 200 speakers, five tracks and three days, featuring founders from Legora, Lovable and Celonis alongside enterprise buyers from Diageo, ING and KLM.

CradleCradleGeneral IntuitionGeneral IntuitionFramerFramer

Watch about this

THIS was the whole point of Microsoft Builld1:03
aiMatt Wolfe

THIS was the whole point of Microsoft Builld

The Biggest Microsoft Build News in 82 seconds1:23
aiMatt Wolfe

The Biggest Microsoft Build News in 82 seconds

AI News: Microsoft Finally Reveals Their Plan!30:17
researchMatt Wolfe

AI News: Microsoft Finally Reveals Their Plan!

Claude, GPT-5, Gemini 3: Only 1 of 52 Jobs They Can Actually Do2:16
researchThe AI Automators

Claude, GPT-5, Gemini 3: Only 1 of 52 Jobs They Can Actually Do

I Analyzed the Hidden Flaw Breaking Long-Running Agents25:00
researchThe AI Automators

I Analyzed the Hidden Flaw Breaking Long-Running Agents

Andrej Karpathy's Wiki Idea Was Just Shipped by Pinecone27:25
researchThe AI Automators

Andrej Karpathy's Wiki Idea Was Just Shipped by Pinecone

From the n8n canvas to Microsoft Teams with Microsoft Agent 36554:49
ain8n

From the n8n canvas to Microsoft Teams with Microsoft Agent 365

What is your secret sauce tip for Copilot?0:50
aiMicrosoft 365 Developer

What is your secret sauce tip for Copilot?

DutchStartup.ai

The platform for the Dutch AI scene.

Add your startup
About·Contact·Privacy·Terms