A report from the think tank ChinaTalk details an informal ecosystem that lets developers in mainland China reach US-built large language models (LLMs) at deeply discounted rates, despite those models being officially restricted or unavailable locally.
What is happening?
The network comprises many types of intermediaries: account farms that acquire large numbers of AI accounts; verification platforms that provide phone numbers to pass sign-up checks; token resellers trading unused quotas; identity brokers creating fake credentials; model routers; payment processors; and proxy servers that accept developers’ API calls and relay them through accounts that appear legitimate.
According to the report, this system gives access to models not officially offered in mainland China, including OpenAI ChatGPT, Anthropic Claude, Google Gemini and Midjourney. The report says some arrangements allow Chinese developers to buy Anthropic Claude tokens for as little as 10 percent of the typical market price.
How the market operates
To keep costs down, operators use a mix of practices that range from legal but exploitative to outright illicit. Techniques include aggregating Anthropic’s free API credits, reselling unused account quotas, exploiting educational or corporate discounts, and splitting subscription plans among multiple users. Some actors rely on accounts created with stolen or fraudulent credit cards, which breaches terms of service and may be illegal.
Requests routed through proxies may be downgraded: when a user selects a higher-tier model, their call can be served by a cheaper, lower-performing model instead. The German CISPA Helmholtz Center for Information Security found that proxy access to a labeled “Gemini-2.5” achieved only 37 percent on the MedQA multiple-choice medical question benchmark, compared with 83.82 percent when accessed via Google’s API.
Data harvesting and downstream risks
Proxy services frequently log users’ requests and sell those logs. API calls are valuable training data for new models, and outputs from proprietary models can be used to train other models to replicate them. Parts of the network may also violate providers’ terms of service, exploit people who supply biometric data, or misrepresent products being sold.
Allegations and policy responses
This gray market has been implicated in claims that Chinese developers of open-source models routinely train on or otherwise extract outputs from proprietary US models. In February, Anthropic accused three Chinese AI labs — DeepSeek, Moonshot, and MiniMax — of systematically extracting Claude’s outputs to improve their own models. Anthropic reported detecting over 16 million exchanges from 24,000 fraudulent accounts and warned that “illicitly distilled” models may lack necessary safeguards and pose national security risks.
Reactions were mixed: some critics argued Anthropic’s objections were hypocritical given widespread model training on copyrighted material and fair-use arguments; others suggested Anthropic sought to protect its competitive edge and to encourage tighter US regulation of Chinese AI firms.
In April, the White House issued a memo acknowledging industrial-scale distillation as an adversarial threat and reiterated the administration’s intent to work with the private sector to develop defenses and hold foreign actors accountable.
Why this matters
The ChinaTalk report relies largely on interviews and circumstantial evidence; some of its claims have not been independently verified. Nonetheless, it highlights how access limits intended to manage AI distribution can create incentives for parallel markets that undermine economic and governance models. Developers using proxies may not receive the models they expect, and their prompts, code and agent traces may be logged and repurposed without their control. AI companies may be undercompensated and lack visibility into use of their services, while models trained on cheaply obtained outputs can evade original safety guardrails.
Conclusion
The report sketches a shadow ecosystem that offers inexpensive access to well-known LLMs but carries significant legal, security and ethical risks. While openness and knowledge-sharing are valuable, using fraudulent or deceptive means to access proprietary models is problematic. Businesses that aim to offer access to closed US models should address rights and safeguards with model providers through legitimate channels.



