How users in China keep evading Anthropic's geographic restrictions to use Claude

🕒 Published on Zendoric: July 4, 2026 · 00:29
The WIRED article, by Zeyi Yang and Matt Burgess, documents how Anthropic maintains especially strict restrictions to block access to Claude from China —more aggressive than OpenAI's with ChatGPT—, including bans on accounts suspected of being controlled from Chinese territory.
The WIRED article, written by Zeyi Yang and Matt Burgess, documents how Anthropic maintains especially strict restrictions to prevent access to Claude from China —more aggressive than OpenAI's with ChatGPT—, including bans on accounts suspected of being controlled from Chinese territory. Despite this, a thriving underground ecosystem circumvents these barriers.
According to the report, this market includes the sale of Claude accounts on platforms such as Taobao and Xianyu, as well as on Telegram channels where ChatGPT Plus and Gemini Plus accounts are also traded. More recently, a phenomenon called 'transfer stations' or 'relay stations' has emerged: intermediaries who buy access to Anthropic's API outside China and redistribute tokens within the country, offering cheaper prices thanks to corporate discounts. The article even mentions that the well-known Chinese crypto entrepreneur Justin Sun opened his own 'transfer station' in May.
A revealing detail is that these practices have distorted the global statistics on Claude usage: Singapore, a country of just 6 million inhabitants, appears consistently among the countries with the highest relative adoption of Claude according to data published by Anthropic, probably because many Chinese users falsify their location or route traffic through it.
The text explains why there is so much demand despite the risk: according to Zilan Qian, a researcher at the Oxford China Policy Lab, Chinese models such as those from DeepSeek or Z.ai —although powerful in open source— lag between six and nine months behind U.S. models, especially in programming tasks. This explains why Chinese engineers and academics interviewed by WIRED prefer Claude Code or OpenAI Codex over domestic tools. Matt Sheehan, of the Carnegie Endowment for International Peace, points to a cultural asymmetry: Chinese technology policymakers have no qualms about adopting American ideas or products despite the geopolitical rivalry, whereas in the U.S. distrust of rival products tends to prevail.
The article places this phenomenon in the context of Anthropic's national security concerns: its CEO Dario Amodei repeatedly points to Chinese access to frontier models as a critical threat, and the company recently accused Alibaba of using Claude outputs to train rival models through a 'distillation' technique, something that, according to the text, had already happened before with other Chinese companies.
In April, Anthropic introduced identity verification through the company Persona (backed by Founders Fund), which requires uploading an official identity document. This has shifted the black market: Claude accounts that have already passed KYC verification are now sold on Telegram, in addition to open discussion of how to evade that control.
The report concludes with a reflection on the security risks generated by this parallel ecosystem: users are exposed to scams and to having their prompts and sensitive information collected and resold by the 'transfer station' intermediaries. Qian warns that those working in AI safety will have to think about how to monitor this unofficial infrastructure to prevent abuses, at a time when Anthropic continues to tighten controls while demand for access to its most advanced models from restricted markets persists.
🔗 Related on Zendoric


