惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
D
Docker
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
博客园 - 【当耐特】
C
Check Point Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

WIRED

‘Avatar: Aang, The Last Airbender’ Leaked Online. Some Fans Say Paramount Deserves the Fallout NASA Wants to Put Nuclear Reactors on the Moon AI Could Democratize One of Tech's Most Valuable Resources Microsoft Surface PCs Are Getting Big Price Hikes, and the Cheaper Models Are Going Away Why Amazon Is Buying Globalstar—and What It Means for Your iPhone The US Government Will Ask Data Centers How Much Power They Use MAGA Is Starting to Look Beyond Trump Allbirds Is Pivoting to AI Compute. Sure, Why Not Best Smart Smoke Detector (and Why You Still Need a Dumb One) 12 Best Standing Desks of 2026, Tested and Reviewed Best Wi-Fi Routers of 2026 for Working, Gaming, and Streaming Best GoPro Camera (2026): Compact, Budget, Accessories The Caves That Could Help Us Find, or Become, Aliens AI Slop Is Making the Internet Fake-Happy The Deepfake Nudes Crisis in Schools Is Much Worse Than You Thought In the Wake of Anthropic’s Mythos, OpenAI Has a New Cybersecurity Model—and Strategy Telegram Is Still Hosting a Sanctioned $21 Billion Crypto Scammer Black Market The FCC Has a Fast Lane for Complaints About Trump’s Media Critics Top iRestore Deals for Hair Growth and LED Therapy Devices Meta Is Warned That Facial Recognition Glasses Will Arm Sexual Predators You Should Be More Freaked Out by Shingles BYD’s Fastest-Charging Car in the World Is Astonishing—in Good and Bad Ways The 4 Best Water Filter Pitchers (2026): PFAS, Microplastics The Internet's Most Powerful Archiving Tool Is in Peril The Dumbest Hack of the Year Exposed a Very Real Problem AI Agents Are Coming for Your Dating Life ‘The Audacity’ Is the Broligarchy Takedown You Were Waiting For Why Is It So Hard to Fix an Electric Bike? (2026) Best 2-in-1 Laptops (2026): Microsoft, Lenovo, and the iPad There’s a Secret Ingredient to Making Luxury Ice at Home
How People in China Keep Outsmarting Anthropic’s Geolocat...
Zeyi Yang,Matt Burgess · 2026-06-27 · via WIRED

Anthropic goes to great lengths to prevent people in China from using its AI models, but in practice, its safeguards have often failed. Over the past year, startups, researchers, and tech enthusiasts across the country have developed increasingly sophisticated workarounds to access Claude. Many of them consider it the world’s most capable AI assistant, making the extra effort to obtain it worthwhile.

Anthropic goes to great lengths to prevent people in China from using its AI models, but in practice, its safeguards have often failed. Over the past year, startups, researchers, and tech enthusiasts across the country have developed increasingly sophisticated workarounds to access Claude. Many of them consider it the world’s most capable AI assistant, making the extra effort to obtain it worthwhile.

In early June, Anthropic publicly released Fable 5, a safeguarded version of its most powerful AI model to date, Mythos. Chinese social media immediately lit up with posts from people sharing their impressions after trying it out. (Anthropic revoked access to the model worldwide a few days later in response to export controls imposed by the Trump administration).

Chinese people generally can access other Western AI tools, such as OpenAI’s ChatGPT, by using virtual private networks, foreign phone numbers, and international payment methods to create and maintain their accounts. But Anthropic has arguably taken more aggressive steps, such as banning accounts that it suspects are owned and controlled by people located in China. On Chinese social media, users frequently report that they have been suspended from Claude without warning, despite taking those precautions.

The cat-and-mouse game has fueled a thriving underground economy for Claude access in China. Accounts are sold on Chinese ecommerce platforms like Taobao and through illicit marketplaces on Telegram. More recently, a cottage industry of “transfer stations” has also emerged. These services act as intermediaries, purchasing access to Anthropic’s API outside China and then redistributing Claude API tokens to users inside the country. The set up is designed to give startups and other professional users more stable and reliable access to AI assistant.

Michael Aciman, a spokesperson for Anthropic, says that the company uses a range of evolving detection systems, including identity verification, to enforce its policies against unauthorized access to Claude. He added that Anthropic has also worked to detect and disrupt proxy networks used to provide access to the chatbot in China.

Despite all of the difficulties Chinese people are forced to overcome to use Claude, there remain many loyal fans of Anthropic in the country. It’s especially popular among programmers. Even though Chinese companies like DeepSeek and Z.ai have some of the most capable open-source large language models on the market, third-party tests still show that they lag behind leading closed models like Claude. During a recent reporting trip to China, WIRED spoke to academics and engineers at multiple tech companies who said that they preferred using Claude over Chinese models to generate code, and are eager to try out each new model that Anthropic releases.

Zilan Qian, a research associate at the Oxford China Policy Lab, looked into the black market for reselling Western AI tokens to Chinese users. He noted that Chinese software developers say they overwhelmingly prefer using tools like Claude Code and OpenAI’s Codex compared to tools from domestic companies. “Analysis shows that Chinese models are still six to nine months behind the US models, and for specific things like coding and developing, you can obviously tell the gap,” Qian says.

“For both Chinese AI policymakers and technical people, they have much less of a problem drawing on and using American ideas or products, regardless of the geopolitical or ideological rivalry,” says Matt Sheehan, a senior fellow at the Carnegie Endowment for International Peace, where he researches AI policy and China. “It’s Americans who tend to think an idea or a product is tainted just because it comes from their rival,” he says.

Dario Amodei, Anthropic’s cofounder and CEO, often explicitly singles out Chinese access to frontier models as a critical threat to US national security. Just this week, Anthropic accused Alibaba of using Claude outputs to train the Chinese company’s rival models, a technique known as “distillation.” Anthropic has also claimed other Chinese companies have done the same thing in the past. For this and other national security reasons, Anthropic does not offer commercial access to Claude in China, or to subsidiaries of Chinese companies located outside of the country.

Still, people continue to find workarounds. For casual users, that might mean sticking to classic tactics like turning on a VPN and using a consistent proxy location, creating the illusion that they are always connecting to Claude from the same place instead of bouncing around the world. Less technical users can go on Chinese ecommerce platforms like Taobao and Xianyu to buy Claude accounts that have already been set up. Anthropic often still bans them after a while, but for people who only want to briefly test Claude or ask occasional questions, the loss is manageable.

Similar marketplaces have popped up on Telegram over the last few years, says Hieu Minh Ngo, a reformed criminal hacker turned cybercrime investigator at the Vietnamese scam-fighting nonprofit ChongLuaDao. On websites and Telegram channels Ngo and other researchers shared with WIRED, users market what they claim to be Claude Pro and Claude Max accounts, alongside others for ChatGPT Plus and Gemini Plus. These underground Chinese-language marketplaces particularly focus on selling “pro” accounts, which allow greater numbers of prompts to be sent, Ngo says.

The frenzy over OpenClaw in China earlier this year also fueled demand for AI agents, Qian says. Because these tools perform more complex tasks, they consume far more tokens than a typical chatbot session. For heavy users, especially developers who need a constant stream of prompts and responses, finding affordable, reliable access to tools like Claude and Codex quickly became a necessity.

That’s when transfer stations, also called relay stations, came in. Set up with servers in an Anthropic-supported country, they work as middlemen between Chinese users and Anthropic. Instead of logging into Claude directly, a user sends prompts to a locally-accessible website, which forwards the request to Claude through individual accounts or API keys. The response from the model is then passed back to the user. To the user, it can feel the same as chatting with Claude, just on a different platform. To make it more appealing to heavy users, transfer stations often charge a cheaper price than Claude’s own API access since they can get enterprise discounts from Anthropic and other licensed distributors.

Today, the demand has spurred Chinese-language websites and GitHub pages listing dozens of transfer stations and comparing a variety of models and token prices. Even the infamous Chinese crypto billionaire Justin Sun joined the game and opened his own transfer station in May.

The sheer number of Chinese users accessing Anthropic through proxy connections may have distorted the picture of who’s using Claude worldwide. Singapore, with its prominence in international business and dominant use of the Chinese language, often becomes the prime target for Chinese users to fake their geographic locations or route through transfer station traffic. Anthropic’s published data says that Singapore, a country of merely 6 million people, is often among the top countries in the world by Claude adoption relative to population size (the United States still uses Claude far more than any other country, according to the data).

Anthropic has continued tightening its restrictions to keep people in China and other restricted countries out. In April, the company rolled out identity verification for some Claude users. The process is handled by Persona, a third-party company backed by the venture capital fund Founders Fund, which requires users to upload a government-issued photo ID, such as a passport, driver’s license, or national identity card before they can log into Claude. IDs from unsupported countries won’t count. And if an account fails to pass the verification test, it could be banned.

The requirement, which some Chinese users have compared to the Know Your Customer (KYC) identity verification required by financial institutions, shifted the workaround market away from Claude accounts and APIs and toward fake identities. Over the past couple of months, Ngo says he has seen Chinese-language Telegram channels begin advertising Claude accounts that have already passed the identification checks. “They are talking about how to bypass KYC, where to buy the Claude KYC so they can use it,” Ngo says.

Perhaps it’s time to acknowledge that, no matter how strictly Anthropic enforces its geographical restrictions, as long as models are still released to the general public, savvy users in China and other unsupported countries will likely continue to find ways to keep using Claude. And the black markets are always ready to provide non-technical users with turnkey solutions.

But the unfortunate result is that by accessing Claude through more and more unsanctioned tools, users are also exposing themselves to more security risks. Not only can they be scammed by sellers on Telegram, the sensitive information and prompts they send through transfer stations could end up being packaged and sold by the intermediary company to unscrupulous buyers. All of these added wrinkles will pose new challenges for AI safety. “People who are working on AI safety need to think, if this transfer station infrastructure remains, how are you going to monitor bad actors and prevent them from doing bad things?” Qian says.

Additional reporting by Will Knight.


This is an edition of Zeyi Yang and Louise Matsakis Made in China newsletter. Read previous newsletters here.