Claude AI underground market booms in China as token resellers bypass ban

Share:
Audio Loading voice…
Claude AI underground market booms in China as token resellers bypass ban

Synopsis

An underground ecosystem of token resellers is giving Chinese engineers and scholars access to Anthropic's Claude — despite an official block — through shell companies, bulk accounts, and overseas servers. With Anthropic already accusing DeepSeek and two other Chinese unicorns of distillation theft via 24,000 fake accounts, the story exposes a significant gap in how frontier AI access can be enforced across borders.

Key Takeaways

An underground market for Anthropic's Claude AI has rapidly expanded in China , with token resellers bypassing the official service block.
As many as 6 of 30 companies in one Haidian District, Beijing office building are reportedly engaged in AI access reselling; tens of thousands of such entities reportedly exist nationwide.
Resellers use shell companies in Southeast Asia , the Middle East , and the US to sign enterprise agreements with Anthropic or Amazon Web Services.
In March 2026 , Anthropic accused three Chinese unicorns including DeepSeek of using approximately 24,000 fraudulent accounts and over 16 million Claude exchanges to train their own models.
Anthropic has warned that AI systems built via distillation may lack safety guardrails and could be used for cyberattacks or biological weapons development.

An underground market for Anthropic's AI model Claude has rapidly expanded inside China, with brokers reselling account tokens to domestic users even as the service remains officially blocked in the country, according to a new report. The trade, which reportedly involves tens of thousands of entities nationwide, has grown sophisticated enough to evade platform-level controls.

How the Token Reseller Network Operates

According to the report from South Korea-based outlet The Chosun, which cited US technology publication The Information, the scheme relies on 'token resellers' who set up servers in overseas territories where Claude is permitted and then aggregate large numbers of accounts. These accounts are then sold as access passes to Chinese users.

'Token resellers use bulk email addresses acquired through past cryptocurrency ventures to successfully register Claude accounts,' the report noted. Buyers reportedly include scholars and engineers who prefer Claude over domestic AI models, particularly for code generation tasks, and who eagerly test each new model version as it is released.

Scale and Reach Inside China

The scale of the operation points to significant domestic demand. As many as 6 out of 30 companies in a single office building in Haidian District, Beijing — a technology hub — are reportedly engaged in 'AI access reselling.' Nationwide, tens of thousands of such entities are said to exist, according to the report.

Circumvention Tactics Growing More Sophisticated

As US platforms tighten enforcement, resellers have reportedly adopted more elaborate workarounds. These include creating shell companies in Southeast Asia, the Middle East, and the United States to sign enterprise agreements directly with Anthropic or Amazon Web Services.

'These processes occur outside China, making tracking difficult. It's a game of hide-and-seek between those blocking accounts and those misusing them,' the report said.

The Distillation Threat: Allegations Against Chinese AI Firms

Beyond access reselling, illegally obtained accounts are reportedly being used for 'distillation learning' — a technique by which capabilities of a frontier model are extracted to train a rival system. In March 2026, Anthropic accused three Chinese unicorns, including DeepSeek, of having allegedly extracted capabilities from Claude to advance their own AI systems.

The alleged modus operandi involved the creation of approximately 24,000 fraudulent accounts and over 16 million exchanges with Claude to train Chinese models. Anthropic has warned that AI systems built this way may lack the safety guardrails embedded in frontier models, and could potentially be weaponised for cyberattacks and biological weapons development.

What This Means Going Forward

The expanding black market underscores the tension between US efforts to restrict frontier AI access and the persistent demand for those tools among Chinese researchers and developers. With enforcement proving difficult across jurisdictions, the episode raises broader questions about how AI developers can protect model integrity — and whether enterprise-level access agreements are themselves a vulnerability in the containment strategy.

Point of View

Then the containment architecture has a gaping enterprise-tier hole. The distillation allegations against DeepSeek are particularly consequential — if capabilities can be cloned through 16 million synthetic exchanges, export-control logic applied to hardware may not extend meaningfully to model outputs. Washington and US AI developers will need to rethink enforcement at the application layer, not just the chip layer.
NationPress
5 Oct 2026

Frequently Asked Questions

What is the underground market for Claude AI in China?
It is a network of token resellers who set up overseas servers, aggregate Claude accounts using bulk email addresses, and sell access to Chinese users — circumventing China's official block on the service. Tens of thousands of such entities reportedly operate nationwide.
How do resellers avoid detection by Anthropic and US platforms?
Resellers have reportedly evolved from simple account sharing to creating shell companies in Southeast Asia, the Middle East, and the United States to sign legitimate enterprise agreements with Anthropic or Amazon Web Services, making account-level tracking significantly harder.
What is distillation learning and why is it a concern?
Distillation learning involves using exchanges with a frontier AI model to train a separate, rival model — effectively extracting capabilities without authorisation. Anthropic alleged in March 2026 that three Chinese unicorns, including DeepSeek, used around 24,000 fraudulent accounts and over 16 million Claude exchanges to do exactly this.
Why do Chinese engineers prefer Claude over domestic AI models?
According to the report, Chinese scholars and engineers prefer Claude particularly for code generation tasks and actively seek access to each new version as it is released, viewing it as superior to available domestic alternatives for technical work.
What risks does Anthropic say distillation-trained models pose?
Anthropic has warned that AI models built through distillation of its systems may lack the safety guardrails it implements, and could potentially be used for harmful purposes including cyberattacks and biological weapons development.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 2 months ago
  4. 2 months ago
  5. 2 months ago
  6. 3 months ago
  7. 3 months ago
  8. 6 months ago
Google Prefer NP
On Google