Policy

Chinese Proxies Bypass Anthropic to Sell Cheap Claude Tokens

Chinese developers are bypassing Anthropic's strict geoblocking to buy Claude tokens at a 90 percent discount, exposing critical gaps in AI safety and export controls.

The Decoder1 day agoPolicy
Image: The Decoder

An analysis by Oxford China Policy Lab researcher Zilan Qian reveals that Chinese developers are bypassing Anthropic's strict geoblocking to purchase Claude tokens for roughly 10 percent of the official price. This gray market relies on "transfer stations," which are API proxies hosted on servers outside China. These proxies route requests to make them appear legitimate, allowing users to pay in Chinese yuan via WeChat or Alipay without a VPN.

The modular supply chain involves upstream account brokers, SMS verification platforms, and downstream resellers on Taobao. To bypass Anthropic's biometric checks, operators use deepfakes, AI-generated fake IDs, or hire real people in low-income countries—similar to how Worldcoin iris scans in Cambodia and Kenya were traded for under $30. Providers drive prices 70 to 90 percent below list by farming Anthropic's free $5 credits, exploiting enterprise discounts, splitting $200 Max plans, or using stolen credit cards.

Operators also lower costs through "diluting," or quietly swapping expensive models like Opus 4.7 for cheaper options like Sonnet or Qwen. Researchers at Germany's CISPA Helmholtz Center for Information Security found that one supposed Gemini-2.5 proxy endpoint scored just 37 percent on a medical benchmark compared to the official 83.82 percent. Furthermore, operators monetize user logs. Datasets containing Claude Opus 4.6 reasoning outputs are already circulating on HuggingFace, suggesting that the real profit margin lies in harvesting developer prompts.

For AI practitioners, this gray market proves that geoblocking is easily evaded. It also compromises safety monitoring, as tools like Anthropic's Clio struggle to detect abuse when requests are fragmented across proxy accounts. This infrastructure has enabled massive distillation attacks, such as when Deepseek, Moonshot, and MiniMax used 24,000 fake accounts to generate 16 million requests. While companies like Nvidia, Microsoft, and Meta warned against restricting distillation in late July 2026, developers using cheap proxies risk exposing their proprietary code to third-party logging.

This is our own summary of reporting by The Decoder

More in Policy