Skip to main content

Share story

AI Security

Chinese Grey Market Resells Claude API at 90% Discount via Proxy Networks

Anthropic Claude Image: primary
Oxford China Policy Lab researcher Zilan Qian found that proxy networks known as "transfer stations" operate openly on platforms including GitHub, Taobao, and Telegram. These networks sustain rock-bottom pricing through a combination of stolen credentials, model substitution, and harvesting users' prompts and outputs for resale as AI training data. The findings give credence to warnings issued in recent weeks by both the White House and Anthropic. The White House accused Chinese entities in late April of running "industrial-scale" distillation campaigns against U.S. frontier models using tens of thousands of proxy accounts. Anthropic disclosed similar activity in February, identifying roughly 24,000 fraudulent accounts linked to Chinese labs, including DeepSeek, Moonshot AI, and MiniMax. Qian's research describes a modular supply chain where most participants handle only one or two links. Upstream operators bulk-register Anthropic accounts by farming free API credits, exploiting corporate discounts, or subdividing $200 Max subscription plans across dozens of users. Some accounts enter the pool at zero cost, purchased with stolen credit card details. To defeat Anthropic's newest identity verification requirements, which now include photo ID and live selfie checks for some users, the supply chain has recruited real people in lower-income countries to complete verification in person. The Worldcoin biometric black market, where iris scans harvested in Cambodia and Kenya were sold for under $30, provided a template for this approach. German researchers at the CISPA Helmholtz Center for Information Security audited 17 of these proxy services and found widespread model substitution. Proxy access marketed as "Gemini-2.5" scored just 37% on a medical benchmark where the official API scored nearly 84%. Users requesting Claude Opus may instead receive responses from cheaper models such as Sonnet, Haiku, or even domestic Chinese alternatives like Qwen, with the output fraudulently relabeled. The proxy operators also collect every prompt and response that passes through their servers. For coding agents, that means complete reasoning chains, repository context, and human-verified outputs. Several Chinese developers told Qian that the access markup is essentially customer acquisition, and that harvesting those logs is the actual business. Proxy-harvested reasoning data is valuable for distillation because reasoning outputs can be systematically captured and used to train competing models. But potential security exposure extends beyond model training because coding agents routinely pass contextual repo data, API structures, and authentication logic through to the model. Samsung encountered a version of this problem in 2023 when its fab engineers pasted proprietary source code into ChatGPT, inadvertently disclosing confidential semiconductor manufacturing data to OpenAI's servers. Anthropic blocked Chinese-controlled entities from Claude access in September and has since added progressively stricter verification, but Qian's research suggests each new control has generated a corresponding evasion market rather than reducing overall unauthorized access.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Tom's Hardware and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital Infrastructure
Capital Infrastructure

Morphotonics raises €40 million for optics manufacturing and data-center push

Dutch manufacturing startup Morphotonics has raised €40 million in an extended round backed by investors including 3M Ventures, Innovation Industries, Invest-NL and the European Investment Bank. The company makes machines that sta...

Capital AI
Capital AI

Spott raises €18.3 million to expand recruitment software

Leuven-based Spott has raised €18.3 million ($21 million) in a Series A led by Balderton Capital, with Base10 Partners, Y Combinator and Fortino participating. The recruitment-software company plans to use the funding for expansio...

AI
AI

Tencent launches preview of Hy Image 3.5 model

Tencent launched a preview of Hy Image 3.5, its latest image-generation model. The release gives users access to a new Tencent system for creating images during the company's competition with Alibaba and ByteDance. Tencent said i...

Products
Products

Apple Music plans 600-capacity London concert and broadcast venue

Apple Music plans to open a 600-capacity concert hall beneath Apple's European headquarters at Battersea Power Station in the coming weeks. The venue will sell tickets for one-off performances by established and emerging artists, ...