Claude AI underground market booms in China as token resellers bypass ban
Synopsis
Key Takeaways
An underground market for Anthropic's AI model Claude has rapidly expanded inside China, with brokers reselling account tokens to domestic users even as the service remains officially blocked in the country, according to a new report. The trade, which reportedly involves tens of thousands of entities nationwide, has grown sophisticated enough to evade platform-level controls.
How the Token Reseller Network Operates
According to the report from South Korea-based outlet The Chosun, which cited US technology publication The Information, the scheme relies on 'token resellers' who set up servers in overseas territories where Claude is permitted and then aggregate large numbers of accounts. These accounts are then sold as access passes to Chinese users.
'Token resellers use bulk email addresses acquired through past cryptocurrency ventures to successfully register Claude accounts,' the report noted. Buyers reportedly include scholars and engineers who prefer Claude over domestic AI models, particularly for code generation tasks, and who eagerly test each new model version as it is released.
Scale and Reach Inside China
The scale of the operation points to significant domestic demand. As many as 6 out of 30 companies in a single office building in Haidian District, Beijing — a technology hub — are reportedly engaged in 'AI access reselling.' Nationwide, tens of thousands of such entities are said to exist, according to the report.
Circumvention Tactics Growing More Sophisticated
As US platforms tighten enforcement, resellers have reportedly adopted more elaborate workarounds. These include creating shell companies in Southeast Asia, the Middle East, and the United States to sign enterprise agreements directly with Anthropic or Amazon Web Services.
'These processes occur outside China, making tracking difficult. It's a game of hide-and-seek between those blocking accounts and those misusing them,' the report said.
The Distillation Threat: Allegations Against Chinese AI Firms
Beyond access reselling, illegally obtained accounts are reportedly being used for 'distillation learning' — a technique by which capabilities of a frontier model are extracted to train a rival system. In March 2026, Anthropic accused three Chinese unicorns, including DeepSeek, of having allegedly extracted capabilities from Claude to advance their own AI systems.
The alleged modus operandi involved the creation of approximately 24,000 fraudulent accounts and over 16 million exchanges with Claude to train Chinese models. Anthropic has warned that AI systems built this way may lack the safety guardrails embedded in frontier models, and could potentially be weaponised for cyberattacks and biological weapons development.
What This Means Going Forward
The expanding black market underscores the tension between US efforts to restrict frontier AI access and the persistent demand for those tools among Chinese researchers and developers. With enforcement proving difficult across jurisdictions, the episode raises broader questions about how AI developers can protect model integrity — and whether enterprise-level access agreements are themselves a vulnerability in the containment strategy.