How China’s Token Resellers Create an Anthropic Gray Market

In Beijing’s Haidian District, a bustling hub for local universities and tech companies, six out of the roughly 30 tenants in one run-of-the-mill office building are all in the same business, according to one occupant of the building: selling Chinese customers access to Anthropic’s Claude and other models from U.S. AI companies.
They’re not supposed to do that. Anthropic doesn’t offer its services in China for national security reasons, but the demand for Claude tokens is off the charts. The company has been among the most vocal in accusing Chinese AI labs of extracting its models’ capabilities in what it has called an “industrial-scale, covert campaign” aided by fake or stolen accounts, credit cards and identities.
On the ground in China, though, the country’s leading AI labs aren’t getting access to Claude on their own. A cottage industry of mostly mom-and-pop token resellers like the ones housed in the Beijing building has mushroomed to cater to demand for U.S. models, according to interviews with several such resellers, along with executives and employees at multiple Chinese AI companies. One of the tenants in the Beijing building, who operates a token reselling business, estimates there are thousands, if not tens of thousands, of firms like his in China.
As a result, these little-known token resellers have come to play a key role in the rising popularity of open-weight models from Chinese AI companies like Moonshot AI and DeepSeek, which have made rapid technical progress in catching up to the quality of U.S. models. That progress has alarmed the Trump administration, which has accused Chinese AI labs of using a copycat technique called distillation on such a vast scale that it threatens U.S. interests.
Both Anthropic and OpenAI have also alleged that DeepSeek, Moonshot, Z.ai, Alibaba and other Chinese AI labs have distilled the U.S. companies’ models. On Wednesday, OpenAI said in a post that it detected a “coordinated model-distillation campaign” that involved individuals associated with Moonshot.
Distillation is a common technique used to train AI systems because it saves cost and time by building on the existing models. It entails using the outputs of one model to teach another to mimic its behavior. The U.S. frontier AI companies routinely distill their own models to produce smaller, more efficient versions, for example. But the proprietary nature of Anthropic’s and OpenAI’s models means that outsiders who distill them are violating their terms of service.
In a statement, an Anthropic spokesperson said: “We’ve long said that distillation attacks pose a serious threat to national security and undermine AI safety standards across the industry. That’s why we continue to speak openly about what we’re seeing and work closely with other labs, government, and partners on shared solutions.”
None of the Chinese model makers has responded to Anthropic’s or OpenAI’s allegations. Three of those model makers—Moonshot, Z.ai and Alibaba—declined to comment for this story. DeepSeek didn’t respond to a request for comment.
It’s hard to determine how much of the advancement of Chinese open-source models is due to distillation. U.S. authorities have argued that it is vital to their technical progress. “The sheer scale of these campaigns and their sophistication indicate that distillation is not a supplement to these companies’ AI model development, but the critical core of it,” stated a September report from the U.S. Cybersecurity and Infrastructure Security Agency.
Interviews with employees at half a dozen leading Chinese AI developers—all of whom declined to be named—confirm that the technique is widely used inside their companies.
For Chinese companies, U.S. export controls on advanced chips have made distillation a necessary evil. The lack of computing resources means they can’t afford the luxury of experimenting with different training runs the way their American peers can. But overreliance on distillation as a shortcut can bring about problems by relieving AI labs of the need to innovate.
“It’s like athletes doping. It can improve performance in the short run but also brings long-term harm,” said an investor in a leading Chinese AI model developer.
So far, though, distillation isn’t the only reason Chinese AI labs have made so much progress, their investors say, adding that resource constraints have encouraged inventiveness among those startups. DeepSeek’s R1 model, released in January 2025, achieved near-frontier capabilities but was trained on a fraction of the number of chips U.S. labs typically employ, and Moonshot’s Kimi K3, released in July, beat both OpenAI’s and Anthropic’s then-flagship models in a coding leaderboard.
Even some U.S. AI labs have begun to take inspiration from the designs of their Chinese counterparts: Thinking Machines Lab, co-founded last year by former OpenAI Chief Technology Officer Mira Murati, said its first model, Inkling, largely followed the architecture of a DeepSeek model released in late 2024. For a part of Inkling’s post-training process, Thinking Machines also used data generated by open-source models including Moonshot’s Kimi K2.5.
Distillation isn’t the only reason customers in China are clamoring for access to Anthropic and OpenAI models. Ordinary businesses in the country are eager to do so for the same productivity benefits that motivate U.S. companies to use the technology.
Token resellers also don’t just obtain access to U.S. models like Claude through stolen or fake accounts, as Anthropic has suggested. Many of the resellers have accumulated email addresses and identities from their previous work in crypto, e-commerce or other sectors, which they use to register Claude accounts. And they rely on methods of indirectly paying for the accounts using USDT, a popular stablecoin.
While Anthropic has described the sources of unauthorized access to its models in shadowy terms, token resellers often openly advertise their services. Chinese social media sites teem with posts advertising Claude tokens for sale. A post on GitHub, the popular open-source repository platform, lists token reselling services in Chinese, while another page ranks multiple token services by price. Transactions are often negotiated through messaging apps such as Telegram, which is blocked in China.
For their part, token resellers say their industry is becoming overcrowded as more entrants swarm into the category, lured by profits. They say the business reached new heights early this year due to a frenzy in China over OpenClaw, an open-source AI agent platform that drastically increased demand from startups and AI enthusiasts alike for U.S. models. The overcrowding has forced some token resellers to lower their profit margins.
At the same time, Anthropic is constantly catching on to the tricks token resellers employ to get Claude accounts, which has forced Chinese AI labs to come up with other ways of satisfying their thirst for tokens—for example, by opening shell companies that obtain Claude accounts in countries where Anthropic does business.
‘It’s like athletes doping. It can improve performance in the short run but also brings long-term harm.’
The booming demand for Claude in China has led to a flourishing supply chain that undergirds the country’s AI token economy.
In some cases, token resellers rely on other companies to secure email addresses they can use to sign up accounts that pass know-your-customer checks by Claude and its authorized distributors such as Amazon Web Services. Some firms help set up payments to top up prepaid cards when Chinese customers burn through the funds on them. Chinese labs also expect the resellers to provide round-the-clock customer service in case Anthropic bans their Claude accounts because of suspicious activity.
On a technical level, Chinese token resellers operate in a fashion similar to companies like OpenRouter, a popular service that aggregates access to a variety of models from different providers, allowing customers to switch seamlessly between them. The Chinese resellers set up a server that pools many registered individual Claude accounts. That server, typically located outside China to bypass Anthropic’s geographic restrictions, is known as a reverse proxy and acts as an intermediary between Claude and end users.
In its September report, CISA described token resellers as participants in a “gray market of proxies known as ‘transfer stations’” that allow Chinese AI labs to “bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability.”
There are privacy downsides to buying tokens this way. While tech-savvy AI labs usually have mechanisms in place to ensure data doesn’t go through external servers run by the token resellers, the same can’t be said for smaller or individual developers. Token resellers can see the data these clients are sending to AI models, and some of the more unscrupulous ones attempt to profit by selling that customer data to model developers, according to some resellers.
One Shanghai-based token reseller said he has acquired Claude accounts in several ways. The reseller said he and associates have pools of email addresses registered when they previously worked in the crypto field and have used them to successfully sign up for Claude accounts.
The reseller also applies for individual accounts directly with Anthropic, as well as through coding platforms such as Cursor and Kira, which also offer access to Claude. He typically signs up for a popular Anthropic subscription, Claude Code Max 20x, which costs $200 a month. He pays for Claude accounts using payment cards funded by USDT.
On occasion, Anthropic will ban his accounts if it detects unusual activity, such as heavier than normal usage. In those situations, he’ll request a refund, but such instances are becoming more rare as Anthropic steps up its efforts to weed out suspicious accounts.
Indeed, Anthropic’s intensification of its crackdown on what it calls “illicit” access to Claude from China has created a never-ending cat-and-mouse game. The Shanghai reseller said Anthropic will sometimes ban payment cards he uses en masse overnight, sending him and his team scrambling for access to new cards. Recently, Anthropic has also started requesting ID verification for some accounts when users log in, a move seen in China as another attempt to detect and ban users from the country.
Some token resellers hold out hope that Anthropic’s crackdown won’t be so far-reaching that it puts them out of business, if only because wiping them out would deprive it of a meaningful revenue source. “I have customers that can consume $10 million worth of Claude Code Max accounts a month,” the Shanghai token reseller said. “That’s more than $100 million a year.”
Chinese AI labs are using other methods to get access to Claude, which are becoming more attractive as Anthropic clamps down on token reselling. One of them involves setting up overseas shell companies to purchase enterprise plans from Anthropic, distributors like AWS or other companies that have enterprise Claude subscriptions.
The labs can register the shell companies anywhere Anthropic offers its services, from Southeast Asia to the Middle East or even the U.S., obscuring their connections to China, according to some token resellers and several employees at Chinese model developers who have used the method.
In some cases, AI startups in those countries that are existing customers of Anthropic or AWS resell unused tokens from their enterprise plans to AI labs in China, the employees said. This method, which Anthropic has not mentioned in its previous distillation allegations, is difficult for the company to trace because the entire process runs outside China.
In the past, Chinese authorities, for their part, mostly turned a blind eye to the local labs’ use of American AI models like Claude. But that could be changing.
In September, Anthropic released its most extensive report yet on how Chinese models were distilling Claude and what it’s doing to stop them. The report alleged that several Chinese companies, including DeepSeek and Moonshot, had been routing sensitive user data such as police surveillance video footage to Claude models. Soon, though, the revelations prompted China’s internet regulator to launch a probe into the companies.