A network of API intermediaries allows developers in China to access Anthropic models for a fraction of the official price, despite geographic blocks and identification requirements. The workings of this market were detailed by researcher Zilan Qian of the Oxford China Policy Lab in an article published on ChinaTalk on May 5.

Known in China as “transfer stations” (中转站), these services act as intermediaries between users and artificial intelligence providers. Instead of connecting directly to Anthropic's infrastructure, the client sends requests to the operator, which forwards the requests using its own accounts and servers.

The model created a market that combines access to blocked services, reduced prices, and a chain of specialized suppliers. At the same time, it transfers to opaque intermediaries data that may include prompts, responses, code, and other information entered by users.

Market grew in parallel with the blocks

Anthropic does not officially offer its services in mainland China and maintains various mechanisms to restrict access in unsupported regions.

In addition to requirements related to phone, payment, and location, the company expanded in September 2025 its restrictions for organizations controlled by companies based in unsupported countries. In April 2026, it also began requiring identity verification for certain users through an official document and a live selfie.

Even so, intermediaries continued offering Claude and tools like Claude Code to Chinese clients.

According to the survey, some of these services advertise consumption of Anthropic models at prices equivalent to only a small fraction of official rates. In certain offers analyzed, the cost ends up being between 70% and 90% below the amounts charged directly by the provider.

A chain with different suppliers

Operators do not rely on a single structure.

At the top of the chain are account suppliers, verification services, payment infrastructure, and networks used to maintain connections outside China. In the center are the platforms that receive user requests, manage payments, and distribute traffic among different accounts.

On the other side are individual developers, companies, app creators, and resellers who buy capacity from these platforms and may resell it again.

This division makes the ecosystem more resilient. The suspension of a service or set of accounts does not necessarily eliminate suppliers, customers, or other intermediaries capable of replacing it.

Low price increases risk for users

The discount offered by these platforms does not always represent merely a low-margin operation.

Because the intermediary controls the connection, the user may not be able to confirm that they received exactly the model they contracted for. The article cites research and reports about services that advertise more expensive models but may route certain requests to lower-cost alternatives.

A study mentioned in the survey evaluated 17 API proxies and found significant differences between the performance of intermediated services and official APIs in some tests.

There is also a risk related to privacy.

Everything that goes through the intermediary can technically be logged on its servers. In AI programming tools, this can include source code, repository context, commands, model responses, and information about internal projects.

Chinese communities cited by Qian say that such records can be reused as data for model training or traded by third parties. The survey itself, however, stresses that there is no evidence that this collection and trading occurs systematically among the operators.

Proxies reduce visibility for providers

The phenomenon also creates a problem for security systems developed by the AI labs themselves.

When thousands of users go through intermediaries, the provider may see the proxy’s account or infrastructure, not necessarily the person who originated each request. This makes it difficult to associate specific behaviors with real users and reduces the effect of measures based solely on account suspension.

The situation affects mechanisms that rely on analyzing patterns across accounts and conversations to identify coordinated activities. If different operators and credentials are used along the chain, part of these signals can be fragmented before reaching the model provider.

The scenario drew increased attention in 2026. In a memo released on April 23, the White House stated that Chinese entities used networks with tens of thousands of intermediary accounts in distillation campaigns against American models. Anthropic had also reported in February an operation involving more than 20,000 fraudulent accounts managed by a single proxy network.

The market described by Qian, however, goes beyond labs involved in model development. It also serves students, researchers, technology professionals, independent developers, and other users interested in accessing foreign models or reducing usage costs.

The result is a parallel economy that exposes a limitation of controls based solely on location, identity, and account: new barriers can increase the cost of access, but they also create economic incentives for intermediaries to try to circumvent them.

More from Radar