THE BS KILLER DESK · investigation · 25 August 2026
China's Claude black market is real. The White House quote everyone's using isn't about it.
A viral post said China has a black market for Claude access, with the White House calling it industrial-scale. Real story, wrong join. We chased every primary source and found four separate incidents wearing one trenchcoat.
The Distillation Heist · Feb 2026
DeepSeek, MiniMax, and Moonshot AI allegedly farmed Claude for training data.
The Espionage Op · Nov 2025
State-linked hackers ran Claude Code as an autonomous pentest kit against ~30 targets.
The Transfer Stations · May 2026
Retail proxy resale to ordinary Chinese developers, paid in yuan, no card needed.
“The White House Called The Transfer Stations Industrial-Scale”
The April memo followed the February heist, two weeks before the transfer-station report existed.
“A Study Proved Fake Claude Sells You Fake Claude”
The 37%-versus-84% benchmark quoted everywhere is real. It's about a Gemini proxy.
THE CHECK
Three real crimes. Two fake joins.
Everything happening to Claude in China is worse than fine and better sourced than the post makes it sound. You don't need the extra glue. The real version already has three separate ways to go wrong.
Someone sent us a LinkedIn post this week that read like a thriller. China has a black market for Claude. It's not a hack, it's a supply chain. "Transfer stations." Money-mule logic, just moving tokens instead of cash. The White House called it industrial-scale. Recruited humans doing selfie verification for strangers, a trick lifted straight from the Worldcoin iris-scan trade.
Good post. Correctly alarmed. We went and read every source underneath it anyway, because that's the job, and here's the thing about the AI-crime beat in 2026: the individual facts are almost always true, and the sentence connecting them is almost always doing more work than it earned.
The verdict first, because you're busy: there are three real, independently confirmed China-and-Claude scandals running in parallel right now, and the post fuses two of them into one bigger, scarier single story using a quote that, when you check the date, could not have been describing what it's credited with describing. We also found the exact spot where a second wrong join happened, and traced a viral "we proved fake Claude sells you fake Claude" statistic back to a real academic paper that tested three AI companies. Anthropic was not one of them.
Four stories. One card. Read the dates before you read the outrage.
Story one: someone actually did point Claude at a break-in VERIFIED
In mid-September 2025, Anthropic's threat intelligence team caught a group it assessed, with high confidence, as Chinese state-sponsored, using Claude Code as the engine of a live espionage campaign. Not "asked an AI for hacking tips." Wired it up to Kali Linux, handed it real penetration-testing tools over MCP, and let it run reconnaissance, exploitation, credential theft, and lateral movement against roughly thirty organizations: large tech firms, banks, chemical manufacturers, government agencies.
The operators lied to the model to get it moving. Told it they worked for a legitimate security firm running defensive tests, then chopped the attack into small tasks with no full picture attached, so Claude never saw the whole crime, only its own slice. Anthropic's own writeup says the AI performed 80 to 90 percent of the campaign, with a human stepping in for four to six decisions per target. At points it fired off thousands of requests, multiple a second, a pace no team of humans could sustain.
A handful of the thirty break-ins worked. Anthropic disrupted the operation, published the postmortem on 13 November 2025, and this is now sitting in MITRE ATT&CK as a named campaign. This is real, it is bad, and it is a completely different animal from everything below it. Nobody bought a discount subscription to run this. Somebody weaponized the tool directly.
Story two: the actual heist behind “24,000 accounts, 16 million exchanges” VERIFIED
This is the number the LinkedIn post is really reaching for, and it's a real Anthropic disclosure, just attached to the wrong actors in the retelling. On 23 February 2026, Anthropic published its own numbers: DeepSeek, MiniMax, and Moonshot AI, three of China's frontier AI labs, had allegedly run what Anthropic called industrial-scale distillation campaigns against Claude. The tactic is old, the scale wasn't. Flood a commercial API with carefully built prompts, harvest every answer, train your own model to imitate the teacher for free.
The breakdown, straight from Anthropic: MiniMax drove the most traffic at over 13 million exchanges, reportedly pivoting to probe new capabilities within 24 hours of a fresh Claude release. Moonshot ran about 3.4 million, aimed at agentic reasoning and computer-use behavior. DeepSeek was the smallest of the three at roughly 150,000, concentrated on Claude's safety-tuned refusals, which is its own small horror story: reverse-engineering not the model's smarts, but its conscience. Total across all three: over 24,000 fraudulent accounts, over 16 million exchanges. Anthropic says one proxy network alone ran more than 20,000 accounts simultaneously.
Not a rumor. Anthropic's own words, on its own site, with its own dollar figure for what it's losing. DeepSeek, MiniMax, and Moonshot AI had not responded publicly to the allegation as of this writing.
Where the post's timeline breaks UNSUPPORTED
Here's the join that doesn't hold up, stated as plainly as we can manage. On 23 April 2026, the White House Office of Science and Technology Policy released a memo, NSTM-4, accusing unnamed foreign entities, primarily in China, of running what OSTP director Michael Kratsios called "deliberate, industrial-scale campaigns" using "tens of thousands of proxy accounts" and jailbreaking techniques. That's a real quote from a real federal policy memo, and it plainly follows on from Anthropic's February disclosure about DeepSeek, MiniMax, and Moonshot AI. The memo does not name a single company.
Now the retail "transfer station" story, the one with the WeChat payments and the recruited selfie-takers. That investigation, by Oxford China Policy Lab researcher Zilan Qian, ran in ChinaTalk on 5 May 2026. Twelve days after the White House memo. Her own piece does not claim the transfer stations she profiled are the same infrastructure DeepSeek, MiniMax, or Moonshot used, and it couldn't have been what Kratsios was describing in April, because it did not exist as a public document in April.
A quote about one scandal, stapled onto a different scandal that hadn't happened yet when the quote was said.
Are the two connected in reality? Plausibly, partially. Anthropic's own February post says the distillation labs reached Claude through "commercial proxy services," which is structurally the same move as a transfer station: route the request through a server that isn't you. Whether the specific storefronts Qian documented, the ones selling to individual developers on Taobao, are literally the same pipes the three big labs used is a claim nobody in any source we read is willing to make. We looked. It's not there. Call this one open, not resolved, and be suspicious of anyone who resolves it for you with more confidence than Anthropic itself has shown.
Story three: yes, you actually can buy Claude on Taobao VERIFIED
This part of the post holds up completely, and it deserves the space, because it's a genuinely strange piece of internet infrastructure. Qian's investigation documents "transfer stations," 中转站, API proxy services hosted outside China that take a request paid for in yuan through WeChat or Alipay, dress it up as if it came from somewhere Anthropic will serve, and hand back the answer. No VPN. No foreign card. No account in your own name. Tokens go for about 1 RMB per dollar of usage, a 70 to 90 percent discount off the sticker price.
Qian maps a three-layer supply chain. Upstream, brokers mass-register Anthropic accounts and SMS platforms rent out foreign phone numbers to pass verification. In the middle, the transfer-station operators run the actual proxy servers and handle the yuan payments. Downstream, individual developers and resellers repackage access and sell it on, openly, on GitHub, Taobao, and Telegram, with community-maintained leaderboards ranking the cheapest storefronts.
Anthropic tightened identity checks in response, up to photo ID and a live selfie for some accounts. The market's answer was not clever code. It was people. Operators recruit real humans in lower-income countries to sit for the selfie check on a stranger's behalf, the exact playbook already proven out in the Worldcoin iris-scan trade, where a scanned eye reportedly changes hands for under thirty dollars. Your face. Someone else's login. The post's comparison to a synthetic-identity mule isn't a stretch, it's a pretty precise description of what's happening.
And the price isn't really a discount. Every prompt and every answer that passes through a proxy sits, in full, on that proxy operator's server. Qian's sources describe reselling those logs as training data. You are not paying ten cents on the dollar for Claude. You're paying ten cents on the dollar plus your prompt history, and nobody asked whether that was the deal you thought you signed up for.
The second wrong join: a benchmark that never met Claude UNSUPPORTED
This is the one we're proudest of catching, because it's exactly the kind of thing our whole job exists to catch. Several outlets covering the transfer-station story cite a specific number: a proxy claiming to run a frontier model scored 37 percent on a medical benchmark, against 84 percent for the real API. It's presented, in multiple places, right next to the words "Claude Opus," as if it were proof that fake Claude tests worse than real Claude.
The number is real. It comes from "Real Money, Fake Models," a March 2026 paper out of Germany's CISPA Helmholtz Center for Information Security, which audited seventeen shadow API services and found 45.83 percent of them silently swapping the model they'd promised for a cheaper one. Genuinely good, rigorous work: they fingerprinted responses by tokenization quirks, knowledge cutoffs, and refusal patterns to catch the swap.
We read the paper. Not the summary, the paper. It tests three model families: OpenAI, Google's Gemini, and DeepSeek. The 37-versus-84 example is specifically a proxy claiming to run "Gemini-2.5." Claude and Anthropic do not appear in the study's scope at all. Somewhere between the arXiv preprint and a dozen tech blogs, someone welded a real Google-focused statistic onto a China-focused Claude story because the shape of the sentence fit, and everyone after that outlet just kept reusing it. This is, itself, a small distillation attack: someone extracted a number's authority without extracting its actual context, and the copy survived the transfer perfectly while the truth didn't.
To be fair to the underlying worry: Qian's own reporting, from direct investigation of the transfer-station marketplaces rather than a lab benchmark, does describe "model swapping," proxies rerouting a paid request for Opus to Sonnet, Haiku, or a domestic model like Qwen. That claim is credible and sourced. It just isn't the CISPA number. Nobody has yet run CISPA's fingerprinting method against Claude-branded shadow APIs specifically and published a score. If someone has, we didn't find it, and neither did anyone else quoting that 37 percent next to Claude's name.
Why this keeps happening
Simple enough to fit on a napkin. Anthropic does not sell to China. On 4 September 2025 it updated its terms to bar any entity more than 50 percent owned, anywhere in its ownership chain, by a company headquartered in an unsupported region, China named explicitly, citing the risk that a Chinese-controlled firm could be legally compelled to hand data to state intelligence services. Anthropic itself estimates this costs it "low hundreds of millions" in annual revenue. That's the supply side: zero, officially.
Demand didn't go anywhere. Chinese developers still want frontier reasoning and coding capability, individual and enterprise. Three of China's own AI labs want something even more specific: Claude's outputs, at industrial volume, to train a domestic competitor without the multi-billion-dollar training run. Zero official supply against real demand from two very different customer types is exactly the condition that manufactures a black market, and the 70-to-90-percent discount isn't marketing, it's the market clearing price once you subtract legality, and apparently subtract most of your privacy too.
How you actually stop it, and Anthropic's own honest answer
Anthropic's public playbook has four parts, in its own words: detection through behavioral fingerprinting that spots distillation-shaped traffic and coordinated multi-account activity; tighter access controls on the programs most commonly abused for fraud, meaning education, research, and startup discount tiers; response shaping, meaning product and model changes that make a stolen answer less useful for training a copycat while staying useful for a real user; and intelligence sharing with other AI labs, cloud providers, and government, largely through the Frontier Model Forum, the same channel OpenAI and Google now use to compare notes on the exact same attackers.
Then Anthropic says the quiet part out loud, in its own blog post: "no company can solve this alone." That's not false modesty. Every new identity check has produced a matching workaround inside weeks, not months. Photo ID and live selfies produced a market for stand-in humans within the same reporting cycle. This is the same shape as chip-smuggling enforcement, and Anthropic knows it, because Anthropic is also the company that told the world Chinese smugglers were hiding GPUs in "prosthetic baby bumps" and shipping crates "alongside live lobsters," a claim Nvidia publicly dismissed as a "tall tale." Worth knowing before you fully outsource your threat model to any one company's press release: Anthropic has a direct financial and competitive interest in tighter China restrictions, on chips and on its own API. That doesn't make its distillation numbers wrong, we checked, they hold. It does mean the loudest voice describing the danger is not a neutral referee, and that's true of basically everyone in this story, including us.
The honest ceiling on "how you stop it": you don't, cleanly, with verification alone. You raise the cost of evasion faster than the market can absorb it, you share intelligence fast enough that a proxy network gets burned before it scales to 20,000 accounts, and you accept that this is now a permanent cat-and-mouse cost of running a frontier model, the same way card fraud is a permanent cost of running a bank.
What this means if you run an organization, not a LinkedIn feed
Two completely different audiences need to hear two completely different warnings here, and most coverage of this story mashes them together the same way the original post did.
If you are tempted to buy cheap API access from anyone other than Anthropic, Amazon Bedrock, Google Vertex, or another Anthropic-listed reseller, because a transfer station is quoting a price 80 percent below list: every prompt you send, every document you paste in, every bit of your own customer's data that touches that call, sits unencrypted on a stranger's proxy server, in a jurisdiction with no contract obligating them to protect it, and there's a real chance you're not even talking to the model you paid for. That's not a compliance nitpick. That's handing your company's confidential data to an unvetted third party for a discount, which is the exact sentence that ends careers when a breach gets investigated.
If you are a large tech company, a bank, a chemical manufacturer, or a government agency: the relevant story isn't the discount marketplace, it's Story One. A state-linked group has already demonstrated it can run 80 to 90 percent of an intrusion through an AI agent with minimal supervision, at a request rate no human team can match. Your existing defenses were built assuming an attacker on human time. Assume they aren't anymore. Anomaly detection tuned for human-paced reconnaissance will miss a machine doing the same job at ten times the speed.
Different threats. Different defenses. One is a procurement risk. The other is a threat-model rewrite. The post that started this collapsed both into one villain, and that's the last thing worth saying about it: the real story didn't need the embellishment. It was already bad enough on its own, in three separate ways, each with its own paper trail.
THE CHECK
China does not have official Claude access, and China obviously has Claude access anyway, through three separate, independently documented routes: a state-linked espionage operation, an industrial-scale distillation campaign by three named labs, and a retail gray market selling discount tokens for your data. All three are real and all three are worse than a vibes-based LinkedIn post can convey. What isn't real: the White House describing the retail market specifically, and a Google-focused benchmark study standing in as proof about Claude. HOLDS: three scandals, independently sourced. DOESN'T HOLD: the two joins stitching them into one bigger story than the facts support.