Chinese developers are paying roughly 10% of Anthropic's official price for Claude API access through underground "transfer stations" that route requests through overseas servers. A new analysis by Oxford China Policy Lab researcher Zilan Qian, published by ChinaTalk, maps out a modular supply chain that defeats Anthropic's industry-leading access controls, from phone number checks to live-selfie verification.

The gray market doesn't just undercut pricing. It strips Anthropic of visibility into who uses its models and how, creating blind spots for misuse detection and feeding adjacent criminal markets in identity fraud.
What are transfer stations and how do they work?
Claude Code for 2% of the price — inside the grey market
Transfer stations are API proxies hosted on servers outside China. A developer in Shanghai sends a request to the proxy; the proxy forwards it to Anthropic's API as if the request originated from a legitimate location, then relays the response back. Payment happens in Chinese yuan via WeChat or Alipay. No VPN required, no foreign credit card needed.
Popular transfer stations are cataloged in community directories, ranked by price and model availability. The user base is broad: students, researchers, enterprise developers, app makers, hobbyists, and, according to Qian, likely Chinese AI labs running distillation, learning from Claude's outputs to train their own models faster.
Why Anthropic's controls aren't enough
Anthropic runs stricter access controls than any major AI provider when it comes to China. The company verifies phone numbers, requires foreign credit cards and billing addresses, and bans companies more than 50% owned by entities in unsupported regions. For select users, it demands ID verification with a live selfie.
None of this stops the gray market. Qian's analysis describes a modular supply chain with specialized operators at each link. Upstream, account brokers mass-register Anthropic accounts. SMS verification platforms supply foreign phone numbers. Reverse-engineering specialists study and defeat Anthropic's detection methods. Downstream, developers and resellers market access on Chinese e-commerce platforms like Taobao.
Most participants run only one or two links in the chain. When Anthropic bans a batch of accounts, the upstream pools and downstream customers stay intact. A replacement proxy can spin up within hours.
Deepfakes and recruited humans defeat KYC
Even Anthropic's newer KYC-style identity checks already have workarounds. AI services generate realistic fake IDs. Deepfake technology beats the live-selfie biometric checks. Where that fails, real people in low-income countries are recruited to perform verifications.
Qian points to Worldcoin's identity system as precedent. Despite verifying users through iris scans, a black market emerged where scans from Cambodia and Kenya traded for under $30. The infrastructure that defeats one verification system transfers easily to another.
Recent coverage of Anthropic's Claude capabilities and security positioning
How operators hit 70-90% discounts
The steep discounts come from stacking multiple tactics. Operators farm Anthropic's free $5 credit across thousands of accounts. They exploit enterprise and education discounts. They split a single $200 Max plan across multiple users through token quotas. Accounts funded with stolen or fraudulently obtained credit cards may also flow into these pools, though Qian's analysis can't determine their share.
Model swapping adds another margin. Since the proxy sits between user and API, it can quietly reroute a request meant for the expensive Opus 4.7 model to the cheaper Sonnet, or even to Chinese models like Qwen. Researchers at Germany's CISPA Helmholtz Center for Information Security examined 17 API proxies and found widespread model swapping. One endpoint claiming to be "Gemini-2.5" scored just 37% on a medical benchmark where the real model scores 83.82%.
The Chinese developer community has a term for getting a weaker model than you paid for. But the fraud cuts both ways: some users knowingly accept model swaps to get cheaper access, while others pay premium prices believing they're getting premium models.
Logicity's Take
This isn't primarily a security story. It's an economics story. Anthropic's pricing assumes access control. When that control fails, the entire pricing model breaks. For AI product teams building on Claude, the gray market creates an uneven playing field: competitors in China can access the same models at 10% of the cost, then ship products that undercut you globally. The fix isn't better geoblocking. It's probably model-level watermarking and output fingerprinting that works regardless of how the request arrives.
What this breaks beyond pricing
The deeper problem is visibility. Anthropic's terms of service prohibit using Claude to generate CSAM, bioweapons instructions, or election disinformation. Enforcement depends on knowing who's using the API and monitoring for policy violations.
When requests arrive through a proxy, Anthropic sees only the proxy's credentials. The actual user is invisible. Usage patterns that might trigger red flags get aggregated and obscured. The company loses its ability to shut down specific bad actors because it can't identify them.
The gray market also fuels adjacent criminal infrastructure. The same fake ID services, deepfake providers, and verification-for-hire networks that defeat Anthropic's KYC checks serve other purposes: bank fraud, identity theft, circumventing sanctions. Every new AI provider that implements similar controls creates new demand for these services, which then get better and cheaper.
“This modular supply chain doesn't just undermine geoblocking. It also weakens Anthropic's ability to monitor misuse and can fuel criminal markets around identity and payment fraud.”
— Zilan Qian, Oxford China Policy Lab, in ChinaTalk analysis
For AI labs, the implications are uncomfortable. The industry's standard approach to responsible deployment, restricting access through account controls and monitoring usage for violations, assumes the lab knows who it's serving. Gray markets eliminate that assumption. A more robust approach might require embedding detection capabilities into the model outputs themselves, making misuse traceable regardless of how the user gained access.
The alternative is accepting that access controls are theater: useful for compliance documentation, ineffective against motivated bypass.
Need Help Implementing This?
If you're building AI products and need to understand your model provider's actual security posture, or you're evaluating whether to build on closed APIs versus open-weight alternatives, reach out to the Logicity team for guidance.
Source: The Decoder / Tomislav Bezmalinović
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in AI & Machine Learning
Bezos AI Lab Gets $10B: What Project Prometheus Means
Jeff Bezos is closing a $10 billion funding round for Project Prometheus, an AI lab focused on physics-based AI for manufacturing and engineering. With a $38 billion valuation and backing from JPMorgan and BlackRock, this signals a major shift in enterprise AI investment toward industrial applications.

Kimi K2.6 Open-Weight AI: 300 Agents at a Fraction of the Cost
Moonshot AI's Kimi K2.6 matches GPT-5.4 and Claude Opus 4.6 on coding benchmarks while running 300 parallel agents. For businesses locked into expensive API contracts, this open-weight model could slash AI infrastructure costs while delivering enterprise-grade automation.




