
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

New Delhi, Oct 5 (IANS) An underground market for access to Anthropic’s AI model Claude has rapidly expanded in China, with brokers reselling account tokens to domestic users even as the service is officially blocked in the country, a new report has said.
Summary
The report from South Korea-based The Chosun said the trade relies on “token resellers” who set up servers overseas where Claude is permitted and then gather numerous accounts. Further, they sell access to Chinese users, including scholars and engineers as they prefer Claude over domestic models for code generation and eagerly test new versions. “Token resellers use bulk email addresses acquired through past cryptocurrency ventures to successfully register Claude accounts,” the report cited US IT outlet The Information as saying.
As many as 6 out of 30 companies in an office building in Haidian District, Beijing, are engaged in “AI access reselling,” while tens of thousands of such entities are reported to exist nationwide. As US platforms tighten controls, resellers have adopted more sophisticated circumvention tactics, such as creating shell companies in Southeast Asia, the Middle East and the United States to sign enterprise agreements with Anthropic or Amazon Web Services. “These processes occur outside China, making tracking difficult.
It’s a game of hide-and-seek between those blocking accounts and those misusing them,” the report said. Illegally obtained accounts are reportedly used for “distillation learning” by Chinese firms. In March 2026, US firm Anthropic accused three Chinese unicorns including DeepSeek of having illegally extracted capabilities from its Claude model to advance their own systems.
The modus-operandi of the alleged theft involved creation of around 24,000 fraudulent accounts to train Chinese models using over 16 million exchanges with Claude.
KazaSec's take
AI-related security incidents are a genuinely new category, prompt injection, model manipulation, and data leakage through an LLM integration don't map cleanly onto traditional application security testing, and are worth assessing deliberately rather than assuming existing controls already cover them.
Coverage details
We've archived 499 other articles touching the same topic (technology, ai model, underground market) , see the full security news archive.
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.