Anthropic runs what are probably the strictest access controls of any major AI provider when it comes to China. The company checks phone numbers, foreign credit cards and billing addresses. It bans companies more than 50 percent owned, directly or indirectly, by entities based in unsupported regions. For select users it even requires ID verification with a live selfie.

Yet Chinese developers can still buy Claude tokens for about 10 percent of the official price. The findings come from a detailed analysis by Zilan Qian, a researcher at the Oxford China Policy Lab.

How "transfer stations" work

The method's name in the Chinese developer community is "transfer station" — API proxies hosted on servers outside China. The mechanism is simple: they accept requests, forward them as if they came from a legitimate location, and relay the response back.

From the user's side there is almost no friction. Payment happens in yuan through local payment apps. No VPN, no foreign credit card. Popular transfer stations are cataloged in community directories and ranked by price and availability.

How the price falls so far

A tenth of the price does not happen by itself. Operators push costs down two ways:

  • Exploiting free credits — promotional credits from mass-registered accounts feed the pool.
  • Swapping models — when a user requests an expensive model, the request may be quietly routed to a cheaper alternative.

The second point is also a reliability problem for the developer buying the service: you cannot be sure the model you paid for is the one that ran.

Who uses it

According to Qian, the customers likely include Chinese AI labs looking to distill Western models — learning from a stronger model's outputs to improve their own weaker ones faster.

But the user base goes well beyond that. Students, researchers, developers, tech employees, companies, app makers and hobbyists all use these services. Qian's point is that the proxy networks, mostly discussed as a security problem in the US, are actually part of a much broader commercial market for Claude access in China.

Why it is hard to shut down

Qian's analysis describes the transfer station as one actor in the middle of a modular supply chain. Upstream, account brokers mass-register accounts, SMS verification platforms provide foreign phone numbers, and reverse-engineering specialists study the company's detection methods.

What makes the structure hard to dismantle is precisely its modularity: cutting one link does not stop the chain, it just gets replaced.

Why it matters

The analysis's central warning is not about access but visibility. A provider's ability to monitor misuse depends on being able to see who is doing what. Requests arriving through a proxy sever that link: the provider sees activity on an account that looks legitimate, not the real user behind it.

That weakens the basic assumption underlying safety evaluations. When a company says it monitors misuse of its model, what it can monitor is limited to what appears in its own records.

A second consequence is more indirect: this supply chain also feeds criminal markets built around identity and payment fraud. The fake identities and numbers needed for mass account registration get sold for other purposes too.