메뉴
BL
The Decoder • 34일 전

중국 암시장, 클로드 토큰을 정가 10%에 판매

IMP
7/10
핵심 요약

중국 개발자들이 해외 서버를 경유하는 API 프록시인 이른바 '중계소(전이 스테이션)'를 통해 Anthropic의 접근 제한을 우회하며 Claude 토큰을 정가의 약 10%에 구매하고 있습니다. 옥스퍼드 중국 정책 연구소의 분석에 따르면 이러한 모듈형 공급망은 지오블로킹을 무력화할 뿐 아니라 Anthropic의 오용 감시 능력을 약화시키고 신분·결제 사기 범죄 시장을 키울 수 있습니다.

번역된 본문

중국의 암시장은 Claude 토큰을 정가의 극히 일부 가격에 판매한다

핵심 요점

중국 개발자들이 Anthropic의 엄격한 접근 제한을 우회하며, 이른바 '중계소'를 통해 AI 모델 Claude의 토큰을 공식 가격의 약 10%에 구매하고 있다. 이 API 프록시들은 요청을 해외 서버를 경유해 전달한다. 운영자들은 무료 크레딧을 악용하고 비싼 모델을 몰래 저렴한 대안 모델로 바꿔치기하며 가격을 끌어내린다. 옥스퍼드 중국 정책 연구소 연구원 자일란 첸(Zilan Qian)의 분석에 따르면, 이러한 모듈형 공급망은 지오블로킹을 무력화할 뿐만 아니라 Anthropic의 오용 감시 능력을 약화시키고 신분·결제 사기 관련 범죄 시장을 부추길 수 있다.

지오블로킹, 신용카드 검증, 일부 사용자에 대한 생체 인증에도 불구하고, Anthropic의 AI 모델을 둘러싼 암시장이 중국에서 번창하고 있다. 이른바 '중계소'가 접근 제한과 AI 안전에 관한 기본 전제를 무너뜨리고 있다.

Anthropic은 중국 관련해서는 어느 주요 AI 제공업체보다도 엄격한 접근 통제를 운영한다. 회사는 전화번호, 해외 신용카드, 청구지 주소를 검사한다. 또한 중국처럼 지원되지 않는 지역에 있는 법인이 직간접적으로 50% 이상 소유한 기업을 차단한다. 선별된 사용자에게는 셀카를 통한 실시간 신분 인증까지 요구한다.

그럼에도 중국 개발자들은 공식 가격의 약 10%로 Claude 토큰을 구매할 수 있다고 옥스퍼드 중국 정책 연구소 연구원 자일란 첸이 ChinaTalk에 발표한 상세 분석에서 밝혔다.

'중계소'가 개발자에게 뒷문을 열어준다

비결은 중국 개발자 커뮤니티에서 '중계소'라고 부르는 것으로, 중국 밖의 서버에 호스팅된 API 프록시다. 이들은 API 요청을 받아 정상적인 위치에서 온 것처럼 전달하고, 응답을 다시 중계한다. 사용자는 위챗이나 알리페이를 통해 위안화로 결제한다. VPN도, 해외 신용카드도 필요 없다. 인기 있는 중계소들은 커뮤니티 디렉터리에 등재되어 가격과 가용성 기준으로 순위가 매겨진다.

첸에 따르면 고객에는 서방 모델을 증류하려는 중국 AI 연구소가 포함될 가능성이 높다. 증류란 더 강력한 모델의 출력으로부터 학습해 자신들의 약한 모델을 더 빠르게 개선하는 것을 말한다.

하지만 사용자층은 그보다 훨씬 넓다. 학생, 연구자, 개발자, 기술 기업 직원, 기업, 앱 개발자, 취미 사용자 모두 이 서비스를 이용한다. 첸은 미국에서 주로 보안 문제로 논의되는 이 프록시 네트워크가 실제로는 중국 내 Claude 접근을 위한 훨씬 광범위한 상업 시장의 일부라고 주장한다.

차단하기 어려운 모듈형 공급망

첸의 분석은 중계소를 모듈형 공급망의 중간에 위치한 하나의 행위자로 설명한다. 상류에서는 계정 브로커가 Anthropic 계정을 대량으로 등록하고, SMS 인증 플랫폼이 해외 전화번호를 제공하며, 리버스 엔지니어링 전문가들이 Anthropic의 탐지 방법을 연구한다. 하류에서는 개발자, 기업, 리셀러가 타오바오 같은 중국 전자상거래 플랫폼에서 접근 권한을 판매한다.

대부분의 참여자는 공급망에서 한두 개 고리만 담당하기 때문에 시스템이 회복력을 갖는다. 한 제공자가 차단되더라도 상류의 계정 풀과 하류의 고객은 그대로 유지되며, 몇 시간 안에 대체품이 만들어질 수 있다. 첸에 따르면 선별된 사용자에게 신분증과 실시간 셀카로 신원을 확인하도록 하는 Anthropic의 최신 KYC 방식 신원 검증조차 이미 우회 방법과 전용 인프라가 존재한다. AI 서비스는 사실적인 가짜 신분증을 생성할 수 있고, 딥페이크 기술이 생체 인증을 통과하는 데 사용되고 있다. 그것으로도 부족한 경우 저소득 국가의 실제 사람들이 이러한 KYC 시장의 인증 작업에 동원되기도 한다고 첸은 말한다. 이러한 주장은 비공식 대화와 공개된 자료에 부분적으로 기반한 것이다. 선례로서 그녀는 월드코인(Worldcoin)을 둘러싼 암시장을 언급하는데, 그 신원 인증 시장이 AI 시대에도 유사한 방식으로 재현될 수 있음을 시사한다.

원문 보기
원문 보기 (영어)
How China's gray market sells Claude tokens at a fraction of the price Tomislav Bezmalinović Aug 23, 2026 Nano Banana Pro prompted by THE DECODER Key Points Chinese developers are bypassing Anthropic's strict access restrictions, buying tokens for the AI model Claude through so-called transfer stations at roughly ten percent of the official price. These API proxies route requests through overseas servers. Operators push prices down by exploiting free credits and secretly swapping expensive models for cheaper alternatives. According to an analysis by Zilan Qian, a researcher at the Oxford China Policy Lab, this modular supply chain doesn't just undermine geoblocking. It also weakens Anthropic's ability to monitor misuse and can fuel criminal markets around identity and payment fraud. Ask about this article… Search Despite geoblocking, credit card checks, and even biometric verification for some users, a gray market for Anthropic's AI models is thriving in China. So-called "transfer stations" are undermining access restrictions and basic assumptions about AI safety. Anthropic runs what are probably the strictest access controls of any major AI provider when it comes to China. The company checks phone numbers, foreign credit cards, and billing addresses. It bans companies that are more than 50 percent owned, directly or indirectly, by entities based in unsupported regions like China. For select users, it even requires ID verification with a live selfie. Yet Chinese developers can still buy Claude tokens for about 10 percent of the official price, according to a detailed analysis by Zilan Qian, a researcher at the Oxford China Policy Lab , published by ChinaTalk. "Transfer stations" give developers a backdoor The trick is what the Chinese developer community calls "transfer stations," which are API proxies hosted on servers outside China. They accept API requests, forward them as if they came from a legitimate location, and relay the response back. Users pay in Chinese yuan through WeChat or Alipay. No VPN, no foreign credit card needed. Popular transfer stations are cataloged in community directories and ranked by price and availability. Ad According to Qian, the customers likely include Chinese AI labs looking to distill Western models , meaning they learn from a stronger model's outputs to improve their own weaker models faster. Ad But the user base goes well beyond that. Students, researchers, developers, tech employees, companies, app makers, and hobbyists all use the services. Qian argues that the proxy networks, which are mostly discussed as a security problem in the US, are actually part of a much broader commercial market for Claude access in China. A modular supply chain that's hard to shut down Qian's analysis describes the transfer station as one actor in the middle of a modular supply chain. Upstream, account brokers mass-register Anthropic accounts, SMS verification platforms provide foreign phone numbers, and reverse-engineering specialists study Anthropic's detection methods. Downstream, developers, companies, and resellers market access on Chinese e-commerce platforms like Taobao. Ad Most participants only run one or two links in the chain, which makes the system resilient. When one provider gets banned, the upstream account pools and downstream customers stay intact. A replacement can be spun up within hours. Even Anthropic's newer KYC-style identity checks, which require select users to verify their identity with an ID and a live selfie, already have workarounds and dedicated infrastructure, according to Qian. AI services can generate realistic fake IDs, while deepfake technology is being used to beat biometric checks. Where that falls short, real people in low-income countries are sometimes recruited for verifications in these KYC markets, Qian says. These claims are based partly on informal conversations and publicly available sources. As a precedent, she points to the black market around Worldcoin, whose identity system verifies users through iris scans. Scans from Cambodia and Kenya were traded for under $30, according to Qian. Ad How sellers hit prices 70 to 90 percent below list Operators drive prices down through a mix of methods. They farm Anthropic's free $5 credit, exploit enterprise and education discounts, or split a single $200 Max plan across multiple users through token quotas. Accounts funded with stolen or fraudulently used credit cards may also flow into these pools, though the analysis can't pin down how large their share is. Ad Model swapping adds another layer. Since the proxy sits between the user and Anthropic, it can quietly reroute a request meant for Opus 4.7 to the cheaper Sonnet or even to Chinese models like Qwen. Researchers at Germany's CISPA Helmholtz Center for Information Security examined 17 API proxies and found widespread model swapping, according to Qian. One supposed "Gemini-2.5" endpoint scored just 37 percent on a medical benchmark instead of the official 83.82 percent. The Chinese community calls this practice "diluting." The biggest lever, according to Qian, may be monetizing usage data. Every request that passes through a proxy is potentially visible to its operator, including prompts, responses, tool calls, and iterations. Coding agents can expose even more context from the codebase and workflow. These logs could contain valuable training or distillation data. Datasets with Claude Opus 4.6 reasoning outputs and no clear provenance are already circulating on HuggingFace. Chinese developers warn, according to the analysis, that the token business is just customer acquisition and the real margin is in the logs. Qian stresses that there's no proof yet that transfer station operators are systematically collecting and selling this data, or who the buyers might be. Her argument is that rock-bottom prices could become viable through additional monetization of the logs. In that scenario, users would be paying customers and unpaid data producers at the same time. Access restrictions create the very markets they're meant to prevent Qian concludes that the implications go far beyond the US-China tech rivalry . The methods a geoblocked developer uses to get access are structurally identical to those a bad actor could use to reach frontier models without being traced. When a request comes through a proxy, Anthropic initially sees the proxy's account and IP address, not the actual end user. That can also weaken monitoring systems like Clio, which are designed to detect coordinated abuse patterns across accounts and conversations, especially when activity is spread across many proxy accounts and broken into individually inconspicuous sub-requests. The circumvention infrastructure also feeds criminal markets beyond AI, the analysis argues. Biometric data collected for KYC workarounds could be resold for financial fraud or deepfakes. Account farming operations support spam, phishing, and credit card fraud. Qian points out that access restrictions have historically created profitable circumvention markets, from the Great Firewall to today's transfer stations. Anthropic, OpenAI, and Google have been fighting distillation for months This gray market infrastructure hurts Anthropic's business because it has already been used in large-scale distillation attacks by Chinese AI companies. Anthropic, OpenAI, and Google recently began working together against unauthorized model copying by Chinese competitors . Anthropic had previously uncovered large-scale distillation attacks by Deepseek, Moonshot, and MiniMax, in which more than 24,000 fake accounts generated over 16 million requests. The company cut off its services to firms under Chinese control and closed the subsidiary loophole. Alibaba banned its employees from using Claude Code after hidden code was found that could identify Chinese users. But the industry is split on whether distillation is even a problem. Voices across the sector have started framing it as a