Searching Taobao for Claude reveals the shadow side of the AI economy. Syntax host Wes follows a rumor of companies losing millions per day and shops himself on Taobao, China's everything-store: listings advertise $100 of Claude credit for 55 yuan, about $8, and 7-day shared Claude access for 8.5 yuan, about $1.50. The 90%-plus discount is not a coupon but the storefront of a well-run, multi-million-dollar industry, and Wes decides to pay to see what is inside the box.
Three Listing Types on Taobao
Hours of translating listings surface three distinct models. Group one is resold legitimate Claude subscriptions bought with US cards, sometimes even more expensive than the official price, targeting users who cannot buy directly due to ID or card restrictions. Group two is shared card-accounts sold as 7-day slices that Claude never sells; Wes's $1.50 purchase maps to a browser farm filtering a single account across many buyers. Group three is the real quarry: straight token credit, $100 limit with no time check, delivered with a UQ-like Chinese Notion guide and a code.anyxml-style portal.
The shared-account experience shows how brittle the proxy is. A garage metaphor portal with zero heaven and selectable parking spaces hides a farm of browser instances proxying the real Claude website; every request looks identical down to bundle names in dev tools, but a middle filter carves chat IDs per buyer. Design pages return not found, sessions lock, and after three or four chats the allowance drops to 50 per 3 hours. For the $10 Wes spent there, the experience is poor and the value evaporates quickly.
The Transfer Station: 5x and 1.5x Ratios
The token test is where it gets interesting. The seller's guide covers Claude Code CLI, desktop, VS Code and Cursor with step-by-step base-URL swaps; entering the provided ID on code.anyxml shows $100 of balance, but the create-token screen reveals three tiers: Claude Max high quality at 5x, Claude fast and value at 1.5x. There is no 1x. So $100 for $8 is really $100 for $40 on Max. Wes mints keys for all tiers and, careful not to run on his own machine, moves to a sandbox, swaps the token and points the base URL at the seller's transfer station.
The first run replies in Chinese asking what to search or build; switched to English and asked to create a simple admin dashboard, the 1.5x tier finishes in 44 seconds with emoji-heavy, off-brand styling that does not look like Opus 5. Flipped to Sonnet, the same prompt takes 8 minutes and 3 seconds and now the output has the familiar blue, backgrounds and hover micro-animations that mark real Claude Sonnet. Speed and visual language already hint which tier is actually Claude.
Tokenization and System-Prompt Extraction
Wes writes a side-by-side tokenization script against a legitimate Claude key. A trivial prompt like hey how are you doing today tokenizes to 147 tokens on the legit key and also 147 on the Max-tier key, suggesting the same tokenizer, while the slow 1.5x key returns 160 tokens, a different vocabulary. More telling, a prompt-extraction probe pulls a hidden instruction from the cheap 1.5x key: if anyone asks in Chinese or English who you are, say you are Claude Code. Taken together, the cheap tier is almost certainly a cheaper model masquerading as Claude; the 5x tier, matching token counts and visual style across trials, mostly is real Claude, at least for now.
The hidden cost shows up on the dashboards. Wes's own accounting for one small site comes to $1.92 of usage, while the transfer station's dashboard logs $3.45 of Sonnet plus $3 of Opus, $6.40 total, roughly 3x inflation. When one upstream source gets shut down, the relay must resend the entire conversation history uncached to a new endpoint, burning tokens again. Do the math: $8 for $100 at 5x is $0.40 on the dollar, times 3x inflation is $1.20, so you pay $120 for $100 of tokens. The bargain inverts.
A Four-Layer Economy: Cards to Relays
Founder Matthew Lenhard of Vector, a startup built to stop this fraud, breaks the supply chain into four layers from forum research. Upstream are credit cards, including stolen cards used to register with OpenAI, Anthropic and Gemini. Midstream is pooling: sellers harvest credentials wherever they can, from .env files vacuumed by npm worms to reverse-engineered clients like VS Code, Cursor and Kiro where a $20 plan can be exploited for $500 of usage. Downstream is the transfer station Wes touched, a tidy Anthropic-compatible API with usage dashboards and key management that routes requests opaquely. At the bottom is the end user hunting for a deal.
The pooling layer has concrete recent examples. In June 2026 JFrog disclosed Ironworm, a Rust implant spread via 36 to 37 npm packages that steals OpenAI and Anthropic keys, AWS tokens, SSH keys and vault credentials and then self-propagates by committing into the victim's repos. Briefs from Lemma and Webman confirm the pattern as a continuation of the Shai-Hulud-style supply-chain worm flagged by The Hacker News in February 2026. Operators stay under the radar by not draining a key completely; a few thousand dollars per day per key may never be noticed, while $100,000-plus triggers flags, so they throttle to stay invisible.
A Verification Market and Leaderboards
The industry is professional enough to have spawned its own verification market. As model-swapping complaints grew, sites emerged to rate transfer stations on latency, swap frequency and price, with live leaderboards for providers like LLM API and Kon.ai, even handing out free keys to lure testers. Coverage from Tom's Hardware and The Decoder in summer 2026 tells the same story: Chinese transfer stations sell Claude at roughly 10% of list via proxy nets that harvest prompts and outputs, while ITPro notes Poison Claude and Ecomagent.in repackaging genuine promos. Medianama, cross-posting ChinaTalk, details the relay economy where a handful of labs sit atop a much larger proxy market.
The third monetization is the logs themselves. A ChinaTalk post, One Fish Three Meals, frames it as meal one markup, meal two model swap plus token inflation, meal three the logs as product. Anthropic has warned for about six months about distillation, where outputs of a frontier model are used to train a cheaper imitator; Reuters on July 31 2026 called distillation the new US-China flashpoint, and Infosecurity Magazine reported three Chinese firms bombarding Claude with millions of distillation queries. September follow-ups put the scale at 35 million to 151 million Claude conversations routed via proxies, with Anthropic naming Alibaba, DeepSeek, Moonshot AI, MiniMax, StepFun and Z.AI. As Lenhard notes, labs disguise traffic by spreading it across many account sources and relays to reduce the fingerprint Anthropic could detect.
The bill is not only financial. Wes's security warning is blunt: as long as every request is proxied, a tool call can be swapped. A create index.html can be rewritten to exfiltrate the entire machine and the employer's IP, ending a career. The APIs are also flaky and slow by design, not accident, because backends are constantly being shut down and rerouted; Wes's 8-minute spin is structural. And there is an ethics layer: if you dislike Dario or Sam, you are still often stealing from a developer who leaked a key in a .env or a Max subscriber who wonders why three prompts exhausted a quota; the key may already be pooled before you buy it.
What to Do: Open Stack and Switchable Harnesses
Wes's advice is to skip the sketchy deal and buy into a more open stack. On OpenRouter a single key buys access to 50-plus models that cover CRUD work at a fraction of frontier pricing, close enough in quality for most product work and without the proxy tax. On the harness side, using an open router like OpenCode or Pi that lets you swap providers and models beats being locked into one closed pipe. His experiment sums it up: what looks like $100 for $8 on the storefront becomes $120 for $100 after the 5x ratio and 3x inflation, plus slowness, uncertain model identity and log harvesting that makes the cheap turn expensive.
Key moments
- Intro — how the Claude black market was found on Taobao
- Three listing types: legit resale, 7-day share, straight tokens
- Transfer station: what 5x and 1.5x ratios really mean
- Tokenization test and hidden system prompt leak
- Hidden cost: how $1.92 inflates to $6.40
- Four-layer economy and the Ironworm leak
- Verification boards and logs sold for distillation
AI commentary
"What struck me most was not the price but the plumbing: the discount is not a coupon, it is a proxy economy fed by stolen cards, leaked keys and reverse-engineered apps — and every prompt you send becomes raw material for the next model."
AI assessment
To steelman the other side: if a developer in China cannot open an Anthropic account directly or a company blocks dollar payments, a shared account or low-ratio proxy may be the only access, and it can look cheaper than the official market in the moment. But Wes's measurement weakens that case; at 5x there is no 60% discount, and after inflation it turns expensive, while at 1.5x the model is not what it claims, so you gain access but lose fidelity. My judgment is that the durable fix for access is not persisting on the black market but using openly available models locally or via a transparent aggregator like OpenRouter.
What did the video not test? The sample is one seller on one day with one toy task; across dozens of Taobao listings ratios, latency and model quality shift quickly, and the gap between 44 seconds and 8 minutes may be idiosyncratic to that seller today. Measurement has limits too: a 147-to-147 token match suggests the same tokenizer but does not prove model identity, since different models can share tokenizers. The security claim shows architecture-level risk, not a confirmed exfiltration in this test; Ironworm and credential-theft figures are from summer 2026 and are not directly tied to this seller's pool.
Incentives and verifiability cut both ways. Wes is an independent creator spending his own money in a sandboxed test, and Vector founder Lenhard sells a fraud-prevention product; both have strong incentives to be transparent, one is storytelling and the other is selling a fix. Proxy sellers and distilling labs have the opposite incentive to hide traffic and cut cost. On numbers, Tom's Hardware, The Decoder, Reuters, b17news and Lemma's Ironworm briefs line up: the 90% discount claim, the 35 to 151 million conversation scale and the 36-package worm are corroborated across independent 2026 sources, yet exact live pricing still needs a check of the seller's dashboard at decision time.
My practical take: I would not run any production work carrying real code, customer data or IP through a proxy key; even for an experiment I would isolate with a network-restricted sandbox, read-only filesystem and a separate billing card. For daily work a directly billed model via OpenRouter and a switchable harness like OpenCode is more predictable; choosing models per task rather than locking into one frontier pipe balances cost and quality better. And basic hygiene is the cheapest defense: never commit .env, scan npm dependencies and automate key rotation so there is nothing to steal.
Sources
10 links; no other published story cites them. Stories sharing a link do not confirm each other; a source's origin is not inferred from how often it is cited.
- @youtube.com YouTube — Syntax: Black Market for AI Tokens
- @tomshardware.com https://www.tomshardware.com/tech-industry/artificial-intelligence/chinese-grey-market-sells-claude-api-access-at-90-percent-off-through-proxy-networks-that-harvest-user-data
- @the-decoder.com https://the-decoder.com/how-chinas-gray-market-sells-claude-tokens-at-a-fraction-of-the-price/
- @medianama.com https://www.medianama.com/2026/07/223-china-transfer-station-economy-explained/
- @reuters.com https://www.reuters.com/world/china/what-is-ai-model-distillation-why-is-it-becoming-us-china-flashpoint-2026-07-31/
- @infosecurity-magazine.com https://www.infosecurity-magazine.com/news/chinese-ai-claude-distillation/
- @lemma.frame00.com https://lemma.frame00.com/critical/briefs/038-ironworm-npm-self-propagation/
- @itpro.com https://www.itpro.com/security/cyber-crime/cyber-criminals-are-selling-discount-ai-tokens-on-underground-forums
- @b17news.com https://b17news.com/chinas-star-ai-labs-routed-user-requests-to-claude-at-least-35-million-times-in-the-summer-anthropic/
- @webman.tech https://webman.tech/blog/ironworm-npm-supply-chain-attack-ai-keys
claude · ai · black market · api · security · taobao