
Anyone in China without official access to Claude does not actually have to go without it. A thriving grey market of so-called transfer stations sells access to Anthropic’s models at a fraction of the list price. An investigation by Oxford researcher Zilan Qian for the newsletter ChinaTalk lays out for the first time in detail how this infrastructure works, who profits from it, and what risks it creates that reach far beyond Anthropic’s export controls.
Key takeaways
- Transfer stations are API proxies hosted abroad, often in Singapore, that forward requests to Claude and take payment in yuan through WeChat or Alipay.
- Access there can cost as little as ten percent of the official price, a discount of 70 to 90 percent.
- They bypass geoblocking, credit card checks, and, since April 2026, Anthropic’s biometric ID and selfie verification.
- Some providers quietly swap expensive models like Opus for cheaper ones like Sonnet or Qwen without users noticing.
- The real danger, according to Qian, lies not in the price but in the logged prompts, which get resold as training data.
How a transfer station actually works
The principle is simple, which is exactly why it is hard to stop. An operator registers a Claude account abroad, often using free starter credit, stolen credit card details, or discounts meant for businesses and schools. Chinese users then send their requests not to Anthropic directly but to the transfer station’s proxy server, which forwards them under the borrowed identity and relays the answer back. Payment is convenient, in yuan, with no VPN or foreign credit card required. Qian’s research describes a three-tier supply chain that has grown around this: upstream, account brokers and fake SMS verification providers; in the middle, the transfer stations themselves; downstream, developers and resellers who advertise openly on Taobao. According to netzpalaver.de, security researchers at Okta found more than half a dozen such offerings in underground forums alone, with names like “Poison Claude” and “Ecomagent.”
ID, selfie, credit card: how the checks get bypassed
Anthropic has repeatedly tightened access controls for unsupported regions over the past year. Sales restrictions for China arrived in September 2025, followed in April 2026 by biometric identity verification through the provider Persona, which requires users to upload an ID and a live selfie. The grey market adapted instead of giving up. Specialized farms with real phone numbers handle SMS verification, while AI-generated fakes and deepfake technology cover the biometric checks, and where that is not enough, operators pay real people in lower-income countries in Africa and Latin America to hand over their faces for verification. Anthropic’s own invisible watermarking meant to flag AI-generated text shows the same pattern: communities build workaround tools around every new safeguard almost as fast as it ships. On top of that, some grey-market providers cut costs further by swapping models: customers who pay for Opus sometimes get answers from a cheaper model like Sonnet or China’s Qwen instead, without being told, something that shows up in noticeably lower benchmark scores.
Who ends up paying the price
The low price comes with a catch many users only understand too late. Because all traffic runs through the transfer station’s servers, operators log every prompt, every response, and every tool call. Qian sums it up by noting that the real margin no longer lies in cheap access itself but in the value of those logs as training and distillation material for competing models. Anthropic has already gone public with exactly this kind of large-scale, unauthorized distillation once before: in an earlier incident, actors linked to Chinese labs including Deepseek, Moonshot, and MiniMax used roughly 24,000 fake accounts to send more than 16 million requests, harvesting Claude’s answers to train their own systems. For individual developers, using a transfer station also carries a real fraud risk: accounts get suspended without warning, paid-for models get swapped quietly, and anyone who handed over biometric data for a fake verification often has no idea where that footage ends up.
What this means
The case illustrates a pattern that extends well beyond Anthropic and beyond China. Geoblocking and export controls are meant to govern access to powerful AI models along national borders. In practice, they generate exactly the kind of grey-zone infrastructure that ends up harder to control than the access it was meant to restrict in the first place: credit card fraud, traded face scans, and unauthorized model distillation are difficult to separate from the original question of who is officially allowed to use Claude. For Anthropic, this likely has two consequences going forward. First, technical verification alone will not be enough as long as every new hurdle can be commercially bypassed within weeks. Second, the harder question becomes how a company that makes privacy promises should be judged when a meaningful share of its actual users route through infrastructure it neither sees nor controls.
