Anthropic, maker of Claude, sells AI access by the token. A four layer Chinese market resells it at a 97% discount.
A 425 RMB package on a Chinese reseller site, around $59 at recent rates, buys what $3,333 buys at Anthropic. The discount isn't a sale. It's the visible output of a four-layer supply chain that turns stolen U.S. payment credentials into discounted Claude tokens, and a price-comparison site now publishes the operator leaderboard.
A Vectoral blog post walks the stack from bottom to top. The author, AI gateway engineer Matt Lenhard, traced the network through a Chinese forum where operators discuss relay methods in the open. His map breaks the market into four layers: card and account merchants at the top of the funnel, account pools in the middle, relay or "transfer station" services that wrap the upstream fraud into a billable product, and downstream developers and startups who buy the resulting tokens.
The base of the stack is billing fraud. 卡商 (card merchants) sell virtual credit cards engineered to pass U.S. and European billing checks, paired with bulk-registered accounts. Anthropic bills per token, and an account is the unit of billing. A card-and-account pair lets an operator run real Claude traffic against stolen payment instruments until the chargeback lands.
One layer up, 账号池 (account pools) aggregate dozens to hundreds of upstream accounts behind a single API, handle authentication, rotate rate limits, and fail over when one account burns out. Lenhard describes this as the layer that converts raw fraud into something a developer can hit with a curl request.
The relay, or 中转站, is where the Chinese-language product gets built. A relay wraps the pooled API in a domestic billing page, sets a discounted price in RMB, and competes for buyers on the leaderboard at the operator price-comparison site. Lenhard's snapshot lists ten named relays running 94.1% to 97.8% below official U.S. pricing, led by 01Now Coding at 97.8% and Claude ZZ at 96.6%. IBTimes independently reported Claude tokens selling at similar discounts in its grey-market piece.
The leaderboard is a dated data point, not an audited census. Lenhard tracks it himself, and menus change weekly. The structure underneath, though, is corroborated. A long Reddit explainer in r/ClaudeAI walks the same stack in English practitioner vocabulary, and V2EX's 中转站 tag hosts detailed Chinese-language explainers of the same layers. Practitioners on Hacker News picked up Lenhard's post and pushed on the token economics: a relay reselling at 3% of list and still paying upstream card and account costs implies a margin large enough that the abuse is structural, not opportunistic.
The buyers split into two groups. The first is developers, startups, and SaaS companies chasing cheap inference. The second uses the cheap access to run model distillation, training smaller downstream models against Claude outputs. That second group is the one Anthropic's billing team is most exposed to, because the revenue loss compounds as the distilled model gets deployed at scale.
The mechanism explains why the discount is so stable. Card fraud at the top of the stack is the variable cost. Everything below it, account aggregation, API wrapping, and customer acquisition, is operational. As long as U.S. billing accepts the cards, relays can price at 3% of list and still profit. Closing the gap is a billing and identity problem, not a Chinese ethics problem, and the public leaderboard is what makes that lever visible to anyone running the numbers.
Watch item: the operator comparison site is the single best real-time signal on relay volume. If Lenhard's ten-operator list shrinks, or the top discount slips below 90%, the upstream billing checks are starting to bite.