In China offered access to Claude at a 90% discount, and the collected data were used for training AI models

In China offered access to Claude at a 90% discount, and the collected data were used for training AI models

550 software

Chinese “gray” proxy‑service market sells access to Claude at a tenth of the official price

A study by Oxford China Policy Lab staffer Zilan Qian showed how Chinese developers resell access to Anthropic’s AI model Claude. They use stolen accounts, swap models and sell queries and responses to users for a small fee.

How the scheme works
Stage What participants do Account registration At the top level they mass‑create accounts on Anthropic for free credits (about $5). Resale of limits Unused tokens from other accounts are sold, and corporate/educational discounts are shared. Subscription fragmentation Claude Max ($200) is split among dozens of users by limiting tokens per hour. Payment data theft Accounts are paid with stolen bank cards and end up in a “free” pool. Verification bypass Middlemen go to Africa/Latin America, hire people to pass personal verification (example: Worldcoin iris scans for <$30).

Model swapping
German researchers from CISPA Helmholtz Center examined 17 proxy services and found that the claimed model often does not match the actual one.

* Example: “Gemini‑2.5” scored 37 % on a medical test, while the official Claude Opus API achieved nearly 84 %.
* A user expecting answers from Claude Opus may receive responses from cheaper models (Sonnet, Haiku) or Chinese AI.

Recording and selling data
Proxy operators keep all queries and responses.

Chinese developers claim that markup is needed to attract customers, but real profit comes from data collection:

* On HuggingFace there are already datasets of Claude Opus 4.6 reasoning from unknown sources – valuable for training competing models.
* Users themselves create training material, and proxy servers provide a stream of data with little effort.

Additional risks
* Transfer of closed source code – AI agents can receive fragments of source code, API structure, and authentication logic. If traffic passes through an unverified proxy, the company sends internal data to a third‑party server without protection obligations.
* Example Samsung – in 2023 engineers at the company sent source code to ChatGPT, revealing confidential semiconductor manufacturing details.

Anthropic and White House reaction
Organization Action Anthropic In September blocked access to Claude for Chinese entities; tightened user verification. White House At the end of April accused Chinese structures of “industrial‑scale distillation,” training their own AI models on Claude’s answers via tens of thousands of proxy accounts.

However, Qian’s study shows that each new measure only spawned a new circumvention market, not stopping illegal access.

Key takeaway:
Chinese proxy services use a combination of stolen accounts, model swapping and data collection to profit. Despite Anthropic’s and the U.S. government’s efforts, they continue to bypass restrictions, creating a resilient “gray” ecosystem around Claude.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment