A Claude gray market has grown up in Beijing, according to an October 2026 report from The Information. Its piece, titled "How China's Token Resellers Create an Anthropic Gray Market," describes intermediaries who accumulate identities and USDT-funded payment cards to open Claude accounts in bulk, then route access through proxies to developers in China, where Anthropic does not sell its service (The Information; Techmeme summary). The full article is paywalled, so the details below come from the headline summary and from secondary coverage of it, and are attributed accordingly.
This post stays at the policy and market level. It does not cover how to get around any restriction. The point is what the story shows about a regional access policy meeting strong demand.
Anthropic
DeepSeek
Moonshot AI
MiniMaxWhat The Information reported
Coverage of the report describes six of roughly 30 tenants in a single office building in Beijing's Haidian district selling access to Claude and other US models. They advertise openly on GitHub, Taobao and Telegram, and call themselves "transfer stations" (AI Weekly). A transfer station takes a prompt from a Chinese developer, forwards it to Claude through an overseas account, and is paid in RMB through WeChat or Alipay.
Reported prices run 70 to 90 percent below Anthropic's list prices, with one benchmark of 1 RMB per US dollar of API credit. The same coverage lists how supply is said to be sourced: bulk registration, free-credit farming, corporate discounts, accounts bought with stolen card details or USDT-funded cards, and $200 Max plans split across many users. Some sellers are also reported to substitute a cheaper Anthropic tier, or a domestic model such as Qwen, and label it as Claude (AI Weekly). These are reported practices, not findings Anthropic has confirmed for this market.
The service is not sold in China, so the demand does not disappear. It finds an intermediary.
Metir analysis
Anthropic's regional policy
Anthropic does not offer commercial access to Claude in China, a point it restated in its February 2026 report on distillation (Anthropic). The company tightened the rules on September 4, 2025. Entities more than 50 percent owned, directly or indirectly, by companies headquartered in unsupported regions, with China named as the example, were barred from its services regardless of where they operate. Anthropic's stated reasoning is that companies "subject to control from authoritarian regions like China face legal requirements that can compel them to share data, cooperate with intelligence services" (Anthropic).
That policy governs who may be a customer. It does not by itself stop an overseas account holder from passing prompts along to someone else, which is the gap a reseller occupies. Anthropic has pushed on the account side. In April 2026 it began rolling out identity verification for a few use cases, asking some users for a government-issued photo ID and sometimes a live selfie (Help Net Security). Reporting from July 2026 says Chinese users were still buying cheap access through proxy services after that change (WinBuzzer).

Resale, relays and distillation
Resale is not only a consumer story. In February 2026 Anthropic said DeepSeek, Moonshot AI and MiniMax created more than 24,000 fraudulent accounts and generated more than 16 million exchanges with Claude to extract capabilities for their own models. It said the labs relied on commercial proxy services it calls "hydra cluster" architectures, which spread traffic across fraudulent accounts (Anthropic). A reseller market and a distillation pipeline can share the same plumbing, even though a developer buying cheap tokens and a lab harvesting outputs have different aims. The AI Weekly summary of the new report says the Haidian market grew up around that enforcement anyway.
Our earlier post on the White House, Moonshot and distillation claims covers the political side of that dispute.
The user's risk
For buyers, the arrangement carries its own exposure. Routing through an intermediary exposes prompts, code context and model responses to the operator, not only to Anthropic. Researchers cited by WinBuzzer found up to 47.21 percent performance divergence among third-party services claiming to offer official models (WinBuzzer). Allegations that some operators log prompts and outputs to sell as training data are reported but, per IBTimes' reading of the evidence, remain unconfirmed (IBTimes). A model swap is also hard to detect from the outside, so a buyer paying for a frontier model may not be receiving one.
The export-control parallel
Export controls on chips and access controls on models face similar economics. Controlled capability is scarce on one side of a border and valuable on the other, so intermediaries appear. The chip version is physical: on October 1, 2026 the US Justice Department announced the arrest of a California business owner charged with smuggling more than $300 million of export-controlled servers to China through Malaysia and Singapore, using false paperwork and third-country shipments (DOJ). The model version is digital: an account opened elsewhere, with prompts relayed on. We looked at the hardware side in AI chip export controls, the cloud loophole and smuggling.
The difference matters for enforcement. A server can be seized and a shipment traced. An API account is an identity, a payment method and a stream of requests, so a provider's levers are verification, usage monitoring, and terms of service. Each lever adds friction, and friction raises the price of gray-market supply without necessarily removing it.
What to watch
- Verification scope. Anthropic's April 2026 identity checks cover only some use cases. Whether they widen is the clearest signal of how seriously the company treats account resale.
- Reseller pricing. Discounts of 70 to 90 percent suggest supply is cheap to obtain. A narrowing gap would indicate enforcement is biting.
- Domestic substitutes. Reports say Chinese developers value Claude for coding, so improving local models, such as the Qwen family, could shift demand over time (WinBuzzer).
- Provider coordination. Whether other US labs adopt similar ownership and identity rules will shape how much of this demand lands on any one provider.
The Information's reporting, as summarized, does not show a single dramatic breach. It shows a market: priced, advertised openly, and sustained by a policy that limits supply in one jurisdiction while demand remains. How the policy and the market adjust to each other is likely to be a recurring story as frontier models become more tightly regulated products.
Sources:
- The Information: How China's Token Resellers Create an Anthropic Gray Market (paywalled; headline and byline confirmed)
- Techmeme summary of The Information report, October 5, 2026
- AI Weekly: Beijing transfer stations resell Claude at 70-90% off
- Anthropic: Updating restrictions of sales to unsupported regions
- Anthropic: Detecting and preventing distillation attacks
- Help Net Security: Anthropic tests user trust with ID and selfie checks for Claude
- WinBuzzer: China's cheap Claude tokens and proxy markets
- IBTimes: Grey market for Claude AI tokens in China
- US Department of Justice: California man arrested for smuggling more than $300 million of export-controlled servers to China
Image credits
- Hero: Zhongguancun Street near Haidian Huangzhuang, Beijing, December 2020. Photo by N509FZ, Wikimedia Commons, licensed CC BY-SA 4.0. It is a general view of the district and does not depict any company named in this post.
- In-body: Haidian Huangzhuang blocks, December 2020. Photo by N509FZ, Wikimedia Commons, licensed CC BY-SA 4.0.
