Claude API in China: Beijing resellers sell access at 70 to 90% off, and export controls have no answer
Six of about 30 tenants in one Beijing building resell Anthropic's Claude at 70 to 90% below list, The Information reported. The chip controls stop at the border; access to the models trained on those chips does not.
By Yash Malviya
Published

Claude API in China: a Beijing office building full of resellers shows how export controls on chips leak at the model layer. The Information reported this week, per secondary summaries we could read because the original is paywalled, that six of roughly 30 tenants in one Haidian building resell Anthropic's Claude, advertising on GitHub, Taobao and Telegram at prices 70 to 90% below Anthropic's own. Anthropic does not sell to mainland China. The resellers do not care.
The business is not new, and that is the point. Anthropic's own February 23, 2026 disclosure said distillation labs used "commercial proxy services which resell access to Claude and other frontier AI models at scale." Eight months and one identity-check regime later, the proxies are still openly renting desks.
What the reporting says
The Chinese developer term is "transfer station": a proxy that takes a prompt from a developer in China, forwards it through an overseas Anthropic account, and collects payment in yuan through WeChat or Alipay. A May 5, 2026 analysis by Zilan Qian of the Oxford China Policy Lab, published on ChinaTalk, put a typical price at 1 RMB per $1 of API credit.
The Information's October reporting, as summarized by AI Weekly and Newsquawk, adds the physical detail: ordinary offices in a Beijing tech district, not a darknet. We could not read the article itself, so every figure below that traces to it is labeled as reported second-hand.
- Price: 70 to 90% below official rates, per Qian and the secondary summaries of The Information.
- Supply: farmed free credits, corporate and education discounts, $200 Max plans split across many users, and in some cases accounts bought with stolen cards, per Qian.
- Substitution: buyers may receive a cheaper Claude tier or a domestic model relabeled as Claude, per Qian.
How the discount is possible
Qian describes three revenue streams from one account: the markup, the model swap, and the data. The third matters most for the race. Her point is that every prompt, response and tool call passes through the proxy operator's server, so the operator holds a full record of what the customer built. Whether those logs are actually resold as training data is, by her own account, not systematically verified.
“labs use commercial proxy services which resell access to Claude and other frontier AI models at scale.”
Anthropic's February post gives the scale of the organized version. It named DeepSeek, Moonshot AI and MiniMax, and said they generated over 16 million exchanges through about 24,000 fraudulent accounts. It said one proxy network managed more than 20,000 accounts at once. Anthropic described this as "hydra cluster" traffic: spread across many accounts so that banning one does not stop the flow.

Why this is a compute story
Washington's chip controls aim to slow how fast Chinese labs can train frontier systems. Anthropic's post made the link itself, writing that "Distillation attacks undermine those controls by allowing foreign labs...to close the competitive advantage that export controls are designed to preserve." If a lab cannot buy the best accelerators, it can still buy the outputs of models trained on them, and train a cheaper student.
That sits next to a chip-side picture that is also leaky. We have covered the Nvidia smuggling indictment, and an open Chinese model that trails the US frontier by about four months. The gap on one public benchmark has also narrowed: AI Weekly's October 5 digest reports DeepSeek's V4.1 Flash at 81.1 on LiveBench against 83.4 for Anthropic's top model. We have not verified that leaderboard ourselves, and a single score proves little. Still, a shrinking gap is what you would expect if chips are scarce but outputs are cheap.
What Anthropic has done, and what it has not
Anthropic has escalated. In September 2025 it barred entities more than 50% owned by companies headquartered in unsupported regions. From April 2026 it began requiring some users to verify with a government photo ID and a live selfie, according to the sources we read. Qian reports that the verification layer already has a cottage industry around it, including AI-generated fake IDs and recruited people in low-income countries who pass the checks for a fee.
Each control raised the price of evasion without ending it. Qian's analysis argues the transfer-station supply chain will outlast any single measure, and the October reporting, as summarized, says bans pushed buyers toward more opaque workarounds. We found no on-record Anthropic comment on the October reporting, and no US agency statement on resellers specifically. There is no new rule here, only a documented gap.
“Distillation attacks therefore reinforce the rationale for export controls.”
The policy problem
Chip controls have a clear legal hook: a shipment crosses a border and needs a license. Model access has a thinner one. Reselling an API seat through a foreign subsidiary sits in a legal gray zone, as one summary of the reporting puts it, while knowingly evading sanctions carries direct liability. Nobody has tested where a Beijing proxy sits between the two, and a US lab cannot enforce Chinese law against a tenant in Haidian.
Three things would change the picture, and none has happened as of October 6, 2026: a government rule that reaches model access like it reaches chips, a lab-side technical fix that survives rented identities, or evidence that proxy logs became a meaningful share of a Chinese training set. Without the third, the strongest claim in circulation, that this market feeds distillation, stays a plausible mechanism rather than a measured one.
Our take
The story is real but smaller than the headline price cut suggests. Cheap access to Claude in China is established by a named researcher and now by a major trade outlet, and Anthropic itself says proxies are part of the distillation problem. What is not established is how much of Chinese frontier progress depends on it. Treat export controls as a stack: chips, cloud access and model access, with the third layer currently the leakiest and the least governed. Watch for a Commerce or Congress move on model access, and for any lab publishing numbers on how much proxy traffic it still sees after identity checks.
Frequently asked questions
How are Chinese developers getting the Claude API despite Anthropic's restrictions?
Through resellers called transfer stations. They take a developer's prompt in China, forward it through an overseas Anthropic account, and take payment in yuan via WeChat or Alipay. Supply comes from farmed free credits, discounts, split $200 Max plans and, per researcher Zilan Qian, sometimes stolen cards.
How much cheaper is Claude through Chinese resellers?
Qian's May 5, 2026 analysis puts transfer-station prices 70 to 90% below official rates, around 1 RMB per $1 of API credit. Secondary summaries of The Information's October reporting repeat the range. The original Information article is paywalled.
Can a buyer be sure the model is really Claude?
No. Qian reports model substitution: a buyer paying for a premium model may get a cheaper Claude tier or a domestic Chinese model relabeled as Claude.
Is this market feeding Chinese model distillation?
Anthropic said in February 2026 that labs use commercial proxy services in distillation campaigns, including about 24,000 fraudulent accounts and over 16 million exchanges. Whether proxy logs are resold as training data is plausible but not systematically verified, per Qian.
What has Anthropic done about it?
It barred entities majority-owned by firms in unsupported regions in September 2025 and began photo ID and live selfie checks for some users in April 2026. Reporting says the market adapted. We found no on-record Anthropic comment on the October story.
Do US export controls cover reselling AI model access?
Chip controls rest on licenses for shipments. Model access is thinner: one summary says reselling through foreign subsidiaries is a legal gray zone, while knowing sanctions evasion carries direct liability. We found no new US rule on resellers as of October 6, 2026.
Sources
What each one is, and whose it is.
- 1
Detecting and preventing distillation attacks, Anthropic (February 22, 2026)
Vendor announcement - 2
How to buy cheap Claude tokens in China, ChinaTalk (Zilan Qian, Oxford China Policy Lab) (May 4, 2026)
OtherIndependent of the vendor - 3
How China's Token Resellers Create an Anthropic Gray Market (paywalled; headline and byline only read), The Information (October 1, 2026)
Press reportIndependent of the vendor - 4
Beijing 'Transfer Stations' Resell Claude at 70-90% Off, AI Weekly (October 4, 2026)
Press reportIndependent of the vendor - 5
Gray market of token resellers in China, reports The Information, Newsquawk (October 1, 2026)
Press reportIndependent of the vendor