Anthropic uses a layered technical enforcement system:
The Financial Times reported in July 2026 that Ant Group (an affiliate of Alibaba) has been accessing Anthropic's tools such as Claude Code through unauthorized workarounds — including providing employees with corporate Claude accounts linked to its Singapore-based entity FMI.
ByteDance implemented an internal reimbursement scheme that allowed engineers to use personal accounts to access Claude via VPNs, then get reimbursed by the company, bypassing corporate-level restrictions FI.
A thriving gray market has emerged in China where operators run "transfer stations" — intermediary services that buy Claude API tokens or Max accounts from outside China and redistribute access domestically SLM. Typical scheme: buy one Max 20x account for $200, use Claude Code OAuth tokens to expose it as "unlimited API," then sell access to 10–20 clients at $30–50/month, generating $300–1,000 per account I. These stations are marketed openly on GitHub, Taobao, and Telegram, accept RMB payments, and resell access at roughly 10% of the official price SLM.
Some Chinese proxy services engage in "model substitution," silently routing queries to cheaper or older Claude models while charging for premium ones, and harvesting prompts as a secondary revenue stream I.
On February 23, 2026, Anthropic publicly accused three Chinese AI labs — DeepSeek, Moonshot AI, and MiniMax — of conducting large-scale "distillation" attacks TMD. The companies allegedly created approximately 24,000 fraudulent accounts, generated over 16 million exchanges with Claude, used "hydra cluster architectures" to disguise the activity, and extracted model reasoning and tool-use capabilities to train their own competing AI models MD. The Guardian described this as "large-scale intellectual property theft" D. OpenAI had made similar allegations against Chinese firms the previous month D.
On June 24, 2026, Anthropic accused Alibaba Group of waging a "large-scale effort to illicitly access Claude using thousands of fraudulent accounts" F. Alibaba subsequently announced that starting July 10, 2026, it would prohibit employees from using Anthropic's Claude Code in the office environment Y. Alibaba also alleged that Anthropic had "embedded a backdoor into Claude Code" — though this claim is unsubstantiated and comes via a third-party report Y.
As of July 3, 2026, Anthropic is moving to plug the remaining loopholes that allow unauthorized Chinese access, according to the Financial Times FM. The company is tightening KYC checks, enhancing proxy detection, and likely revoking accounts tied to known "transfer station" operations. The crackdown follows months of escalating cat-and-mouse dynamics: each time Anthropic adds a new barrier — geoblocking, then credit card requirements, then biometric verification — Chinese gray-market operators find a new workaround ISL.