China’s Claude token resellers operate as intermediaries: rather than getting commercial access directly from Anthropic, customers buy access through a third party that routes their requests through accounts and cloud infrastructure. Anthropic says some such networks use fraudulent accounts and replace them when they are blocked. That describes the company’s account of the system—not an independent audit of every reseller or a verified map of the market’s businesses and economics.
What a “token reseller” does
In this context, a token reseller sells access to Claude through a proxy or other intermediary service. The customer sends a prompt to the reseller’s interface or API; the reseller forwards the request through infrastructure it controls or has access to, then returns a response. The customer is buying a route to a model, not necessarily an Anthropic account or a direct contract with Anthropic.
Anthropic’s February 2026 account describes commercial proxy networks that distribute requests across accounts on Anthropic’s API and third-party cloud platforms. It characterizes some as “hydra cluster” systems: when accounts are blocked, replacements can be brought into service. Anthropic says one network had more than 20,000 fraudulent accounts active at once and that its traffic could be mixed with ordinary customer requests. Those are Anthropic’s descriptions and figures, not independently verified market-wide totals.
Why direct access is restricted
Anthropic said on September 4, 2025 that it was extending restrictions to organizations controlled by entities in unsupported jurisdictions, regardless of where those organizations operate. Its stated threshold is more than 50% direct or indirect ownership by companies headquartered in unsupported regions. The company cited legal, regulatory, and security risks.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Anthropic has also said it does not currently offer commercial Claude access in China, including to subsidiaries of Chinese companies located abroad. The company’s live supported-regions terms describe commercial API availability and reserve the right to withhold products from entities whose majority direct or indirect ownership is attributable to nations outside the listed regions. Supported regions and terms can change, so organizations should check Anthropic’s current policy rather than rely on an old list or assume that an overseas address alone establishes eligibility.
What Anthropic says the networks are used for
Anthropic reported that it attributed three campaigns using IP correlations, request metadata, infrastructure signals and, in some cases, corroboration from industry partners. It said the campaigns targeted capabilities including reasoning, coding, tool use and agentic behavior. The company’s reported exchange counts were:
Rank #2
| Organization Anthropic named | Exchanges Anthropic reported |
|---|---|
| DeepSeek | More than 150,000 |
| Moonshot AI | More than 3.4 million |
| MiniMax | More than 13 million |
These are Anthropic’s 2026 figures and attributions; the available reporting does not independently verify the counts. They describe the campaigns Anthropic identified, not the total activity of every reseller, every Chinese AI company or every customer using a proxy. Anthropic has described the activity as distillation—using a model’s outputs to help develop or improve another model—but the reported exchange totals alone do not establish what a particular reseller or buyer did with any given response.
Why a proxy can expose customers to risk
A third-party route introduces another party between a customer and the model provider. Unless the reseller’s practices are independently established, a customer may not know which model answered, who can see prompts and outputs, how long logs are retained, or how credentials are protected. A low advertised price does not establish that the service is delivering Claude or explain how customer data is handled.
Rank #3
Model substitution
Anthropic’s September 2026 report describes a fraudulent reseller operation that advertised cheap Claude access but silently routed customers to a different model. A response that appears plausible is not proof that it came from Claude. For consequential work, model identity and the actual service endpoint matter.
Credential theft and account misuse
In the same report, Anthropic says the operation installed software to harvest credentials. It warns that stolen API keys and session tokens can be resold or used to run someone else’s workloads; activity using a stolen credential can also appear to come from its owner. Treat AI service keys and connected integrations as production credentials: restrict access, avoid placing secrets into an unverified client or proxy, and revoke exposed credentials promptly.
Rank #4
Data handling and accountability
When prompts pass through a reseller, the reseller may be able to observe or retain them, depending on how the service is built. The available evidence does not establish the retention, access controls or security practices of resellers generally. Do not send sensitive business or personal information through a proxy unless you can verify who operates it, what data it collects, how it is protected, and what contractual terms apply.
How to distinguish an authorized route from a gray-market proxy
Anthropic says organizations can create a Claude Console account, with API use subject to its Commercial Terms. Direct availability and eligibility depend on Anthropic’s current supported-region and ownership policies. A service that claims to bypass those restrictions is not made authorized merely because it works or accepts payment.
Recommended Free Tools
Best Value
- Check eligibility: Confirm that the organization and its ownership structure qualify under Anthropic’s current regional policy.
- Verify the provider: Establish whether the account and endpoint are provided by Anthropic or an authorized cloud provider, or by an unrelated intermediary.
- Verify the model: Ask how the service identifies the model actually answering requests and how that identity can be checked.
- Review data and credentials: Determine whether prompts, outputs, logs, API keys or session tokens are collected, stored, shared or used for other purposes.
- Assess responsibility: Check what terms govern access, security incidents, support, billing and data deletion—and who is accountable if something goes wrong.
Anthropic’s warning is direct: “AI access should be purchased only through authorized channels.” That is the company’s position; the practical point for a buyer is that a proxy can add model-identity, data-handling and credential risks on top of the underlying eligibility question.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What remains unverified about the market
The Information has published an article with the exact headline “How China’s Token Resellers Create an Anthropic Gray Market,” by Jing Yang, Juro Osawa and Qianer Liu, but its article body is subscription-locked in the accessible version. The material available here does not establish the operators, business economics, pricing or market size described in that article. Anthropic’s public accounts explain the access mechanism and report specific investigations; they do not, by themselves, verify every detail of the wider reseller market.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

