Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Black Market for Blocked Claude Thrives in China as Token Resellers Undercut Anthropic

China's black market for blocked access to Anthropic's Claude is growing fast, with thousands of "token resellers" selling API access at less than half the official price, Chosun Ilbo reported on Oct. 4, citing The Information. The resellers use overseas servers, stolen credit cards and USDT, and their accounts are reportedly tied to distillation training at Chinese firms including Moonshot AI and DeepSeek.

Published

A black market for access to Anthropic's Claude is thriving in China, where the AI model is officially blocked, according to an English-language report published by the Chosun Ilbo on Oct. 4. The article describes an underground trade built around "token resellers" who buy and sell access rather than software.

The Chosun report, citing U.S. tech outlet The Information, explains that tokens are the text fragments an AI reads and generates, roughly equivalent to words though not always aligned with single words. It frames the trade as a modern successor to the pirated software, games and movies that once circulated widely in China, only now the commodity is access rights to U.S. frontier AI models. The resellers are also bound up with illegal account trading and distillation attacks.

The scale is striking. In one office building in Beijing's Haidian District, six of 30 companies were found to be reselling AI access rights, and Chosun estimates the number of token resellers inside China at anywhere from several thousand to tens of thousands.

The mechanics rely on geography and identity laundering. Resellers set up servers in countries where Claude is permitted, gather large numbers of Claude accounts, and then sell API access to Chinese users at less than half the official price. By placing themselves between Anthropic and users, the accounts are effectively "laundered"; locally the practice is called "zhongzhuanzhan," or transfer station. The Information reported that resellers register accounts in bulk using email addresses acquired through past cryptocurrency businesses, while Tom's Hardware, cited by Chosun, says accounts are also funded with stolen credit cards, re-opened when cards are blocked, and paid for with the USDT stablecoin, with ads for "Claude token sales" circulated on GitHub and Telegram.

Anthropic never launched Claude in China, and in September of last year it suspended services for overseas organizations more than 50% owned directly or indirectly by entities from hostile countries, including China. Yet demand inside China remains high: academics and engineers at multiple Chinese tech companies reportedly prefer Claude for code generation and eagerly test each new version as it is released.

The black market is also tied to distillation, a technique in which a stronger "teacher model" trains a smaller or weaker "student model." Chosun reports that accounts obtained through the reseller market are used for distillation training by companies such as Moonshot AI and DeepSeek, which flood Claude with questions to quickly train their own models on the responses.

As Anthropic tightens restrictions, the workarounds have grown more sophisticated. Chinese tech firms establish paper companies in Southeast Asia, the Middle East and even the United States to sign enterprise agreements with Anthropic or Amazon Web Services, and leftover tokens from overseas startups are sometimes resold into China. A source from the tech industry told Chosun that because these processes occur outside China they are hard to trace, calling it a game of hide-and-seek between those blocking accounts and those using them without authorization.

Why it matters: The report shows that export-style restrictions on frontier AI are being met by a resilient gray market, raising questions about whether account-level and ownership-based controls can meaningfully contain access. For Anthropic, the phenomenon compounds two risks at once, revenue leakage and model distillation, while for U.S. policymakers it undercuts the assumption that blocking a model is the same as preventing its use.

Why it matters

The report underscores an enforcement gap in frontier-AI restrictions: account-level and ownership-based blocks are not stopping Chinese developers from reaching Claude, leaving Anthropic exposed to both revenue leakage and distillation.

AnthropicClaudeChina
Back to realtime news

Nearby Updates

All