Researchers have exposed a massive black market in China selling Claude and GPT-4 tokens at 90% discounts. DeepSeek, Moonshot AI, and MiniMax are accused of scraping data using 24,000 fake accounts. These proxies log user prompts, creating severe national security and corporate data risks across the industry.
Inside the Dark Token Economy Threatening AI
A sophisticated network of illegal resellers in China is selling access to cutting-edge OpenAI, Anthropic, and Google models at 90% discounts. These proxies don't just lower your costs—they log every request you make and sell them for training Chinese AI models or fraud campaigns.
- 🎮Market Scale- 16+ million exchanges from 24,000 fraudulent accounts in just one campaign
- 🎧Pricing- Claude tokens at 10% of official price - monthly revenue 5 million yuan
- 🚀Model Swapping- 50% of requests get routed to cheaper models
- 🗡️Data Harvesting- All prompts and responses are logged and sold
- 📰Official Accusations- Anthropic accused three Chinese firms of industrial theft
- 🎮Government Response- White House issued official memorandum in April 2026
The Black Market Threatening the AI Industry
While major AI companies release increasingly powerful models and raise API prices, a parallel ecosystem has emerged in the shadows offering access to these same models at dramatic discounts. This black market - concentrated primarily in China - doesn't just circumvent geographic access restrictions; it has become a tool for data theft, training competitor models, and even financial fraud.
On February 23, 2026, Anthropic - the maker of Claude - dropped a bombshell that sent shockwaves through the AI industry. The company formally accused three Chinese firms of running "industrial-scale campaigns" to illegally extract Claude's capabilities. DeepSeek, Moonshot AI, and MiniMax - three giants of China's AI industry - had conducted over 16 million exchanges through 24,000 fraudulent accounts. This marked the first time an American company had accused Chinese firms of technology theft with this level of specificity and technical evidence.
But Anthropic's accusations were just the tip of the iceberg. Broader research published by ChinaTalk revealed that these three companies are merely players in a much larger network. A complete marketplace exists with complex infrastructure, open-source software, payment networks, and even customer support services whose sole purpose is selling unauthorized access to frontier models.
What Are Dark Tokens?
Dark Tokens refer to LLM API tokens sourced through a parallel market using unauthorized methods. These tokens typically come from:
- Account Farming: Creating thousands of fraudulent accounts with stolen identities
- Trial Abuse: Exploiting free trial periods and educational discounts
- Credit Card Fraud: Using stolen credit cards or chargeback attacks
- Quota Reselling: Reselling unused API quotas
These tokens reach end customers through proxy services that override the official API endpoint - typically at 50-90% discounts compared to official pricing.
Market Structure: How This Ecosystem Works
The LLM dark token market is a complex supply chain involving multiple actors. At the top level are "Account Farms" - operations that create AI accounts at scale. These farms use "verification platforms" that supply phone numbers to pass signup checks, and "identity brokers" who fabricate credentials.
In the middle of this chain sit proxy servers - the beating heart of the system. These proxies receive API requests from developers and relay them to API providers via accounts that appear legitimate but may not be. The primary software used for these proxies is `one-api` and its more actively developed fork `new-api` - both open-source, legitimate products designed for load balancing but heavily adopted by black market operators.
Three Revenue Models for Proxy Operators
Proxy operators use three main methods to generate revenue, often applied simultaneously. The first is "price arbitrage." They farm free trial accounts, resell educational and startup quotas, exploit regional discount programs, and split paid subscriptions among multiple users. This sources tokens below cost, which are then marked up for resale.
The second method - and perhaps even more profitable - is "Model Swapping." A customer pays for Claude Opus 4.7 but receives Haiku or an open-weight model like Qwen. The proxy pockets the cost difference. This happens in nearly half of all requests across the 17 shadow APIs that CISPA Helmholtz Center tested. On medical benchmarks, accuracy dropped from 83.82% (official Gemini 2.5 Flash) to around 37% through shadow APIs.
CISPA Testing: Shocking Results
Germany's CISPA Helmholtz Center tested 17 shadow API proxy services with disturbing findings:
| Metric | Official API | Shadow API |
|---|---|---|
| MedQA Accuracy | 83.82% | 37% |
| Model Swap Probability | 0% | ~50% |
| Proxy Software | - | 11 of 17 use one-api or new-api |
Conclusion: Using shadow APIs not only poses security risks but significantly degrades output quality.
The third revenue stream - and where the real money is - is "Log Harvesting." Every prompt and response passing through the proxy is logged on the operator's server. This corpus has two downstream uses: first, lead generation for targeted fraud (financial details, business logic, personal data from prompts). Second, training data for model distillation.
Distillation: A Legitimate Technique Weaponized
Distillation is a standard machine learning technique where a smaller model is trained to mimic a larger one's behavior. Labs routinely do this with their own models - for example, OpenAI uses GPT-4 to train GPT-4-mini. But the concern here is the data source. When proxy operators harvest reasoning traces from thousands of unsuspecting users and publish them as training datasets, the resulting "distilled" models are built on stolen outputs.
On Hugging Face, the indicator isn't the word "distilled" alone. The red flag is a model trained on proprietary closed-model outputs (Claude, GPT) where the uploader has no institutional affiliation, no disclosed API budget, and no clear explanation for how they generated that volume of data through legitimate means. Multiple Claude reasoning-trace datasets that appear to originate from proxy logs have surfaced on Hugging Face, used for fine-tuning open-weight models.
Anthropic's Accusations: Three Industrial Campaigns Exposed
In its February 23, 2026 statement, Anthropic disclosed technical details of three distillation campaigns it attributed to DeepSeek, Moonshot AI, and MiniMax. Each campaign followed a similar playbook: using fraudulent accounts and proxy services to access Claude at scale while evading detection. Anthropic attributed each campaign to a specific lab with high confidence through IP address correlation, request metadata, infrastructure indicators, and in some cases corroboration from industry partners who observed the same actors and behaviors on their platforms.
DeepSeek: Industrial-Scale Chain-of-Thought Extraction
DeepSeek's campaign involved over 150,000 exchanges targeting reasoning capabilities across diverse tasks, rubric-based grading tasks that made Claude function as a reward model for reinforcement learning, and creating censorship-safe alternatives to politically sensitive queries. DeepSeek generated synchronized traffic across accounts - identical patterns, shared payment methods, and coordinated timing suggesting "load balancing" to increase throughput, improve reliability, and avoid detection.
In one notable technique, their prompts asked Claude to imagine and articulate the internal reasoning behind a completed response and write it out step by step - effectively generating chain-of-thought training data at scale. Tasks were also observed where Claude was used to generate censorship-safe alternatives to politically sensitive queries like questions about dissidents, party leaders, or authoritarianism - likely to train DeepSeek's own models to steer conversations away from censored topics.
DeepSeek Campaign: Key Statistics
- Total Volume: 150,000+ exchanges
- Primary Targets: Reasoning, reward modeling, censorship
- Unique Technique: Extracting chain-of-thought reasoning from Claude
- Attribution: Via request metadata linked to specific researchers
- Rapid Pivot: After new Claude model release, traffic redirected within 24 hours
Security Note: Using Claude to create "safe" responses for political questions shows intent to train models that can circumvent or assist government censorship.
Moonshot AI: Targeting Agent Development
Moonshot AI's campaign (maker of Kimi models) was the largest in terms of diversity. Over 3.4 million exchanges targeting agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision. Moonshot employed hundreds of fraudulent accounts spanning multiple access pathways. Varied account types made the campaign harder to detect as a coordinated operation.
Anthropic attributed the campaign through request metadata that matched public profiles of senior Moonshot staff. In a later phase, Moonshot used a more targeted approach, attempting to extract and reconstruct Claude's reasoning traces. This shows they weren't just collecting outputs but trying to reverse-engineer the model's thought process.
MiniMax: Detection Before Product Launch
MiniMax's campaign was the largest by volume - over 13 million exchanges targeting agentic coding, tool use, and orchestration. Anthropic attributed the campaign to MiniMax through request metadata and infrastructure indicators, confirming timings against their public product roadmap. Notably, Anthropic detected this campaign while still active - before MiniMax released the model it was training.
This gave Anthropic unprecedented visibility into the lifecycle of distillation attacks, from data generation through to model launch. When Anthropic released a new model during MiniMax's active campaign, they pivoted within 24 hours, redirecting nearly half their traffic to capture capabilities from the latest system. This shows how agile and responsive these campaigns are.
Comparison of Three Distillation Campaigns
| Company | Volume | Primary Targets | Unique Technique |
|---|---|---|---|
| DeepSeek | 150K+ | Reasoning, Reward Modeling | Chain-of-thought extraction |
| Moonshot AI | 3.4M+ | Agent, Tool Use, Vision | Reasoning trace reconstruction |
| MiniMax | 13M+ | Agentic Coding, Orchestration | Real-time pivot to new model |
Total: 16.55+ million exchanges from 24,000 fraudulent accounts - the largest distillation campaign identified to date.
Hydra Infrastructure: Multi-Headed Proxy Architecture
For national security reasons, Anthropic does not currently offer commercial access to Claude in China or to subsidiaries of their companies located outside the country. To circumvent this, labs use commercial proxy services that resell access to Claude and other frontier AI models at scale. These services run what Anthropic calls "hydra cluster" architectures: sprawling networks of fraudulent accounts that distribute traffic across our API as well as third-party cloud platforms.
The breadth of these networks means there are no single points of failure. When one account is banned, a new one takes its place. In one case, a single proxy network managed more than 20,000 fraudulent accounts simultaneously, mixing distillation traffic with unrelated customer requests to make detection harder. This distributed architecture makes blocking these services extremely difficult.
GitHub Repositories: Open-Source Tools Serving the Black Market
The Weather Report identified eight public GitHub repositories that openly facilitate unauthorized API resale, with a combined ~172,000 stars. Two of them, CLIProxyAPI and claude-relay-service, were named by Mandiant as tools used by PRC-nexus actor UNC5673. CISPA found that 11 of the 17 shadow APIs they audited run on one-api or its fork new-api - two open-source API gateway frameworks that are dual-use but heavily adopted by proxy operators.
Key Black Market Repositories
| Repository | Stars | Description |
|---|---|---|
| xtekky/gpt4free | 66,244 | Wraps free chat interfaces (Copilot, Perplexity) as API |
| chatanywhere/GPT_API_free | 38,014 | China-based hosted service with daily free quotas |
| CLIProxyAPI | 33,371 | Wraps Gemini CLI, Claude Code to API (Mandiant) |
| Wei-Shaw/sub2api | 21,725 | Self-hosted gateway splits paid subscriptions |
| claude-relay-service | 11,787 | Self-hosted Claude API relay (Mandiant) |
Note: Most of these repositories are themselves legitimate tools but heavily adopted by the black market. READMEs often include WeChat contact details for token purchases.
Most transactions happen off GitHub, of course. Payment flows through WeChat and Alipay, support runs in QQ groups, listings appear on Xianyu (Alibaba's secondhand marketplace), and contact details are published directly in repository READMEs. This is a complete marketplace with purchasing, sales, and support infrastructure - just for a product that shouldn't legally be sold in that region.
White House Response: National Security Threat Confirmed
In April 2026, the White House responded with a memorandum acknowledging industrial-scale distillation as an adversarial threat. The document affirmed the Trump administration's commitment to working with the private sector to build defenses against industrial-scale distillation and hold foreign actors accountable for such campaigns. This marked the first time the U.S. government formally recognized unauthorized distillation as a national security issue.
This government response shows the issue has escalated beyond a simple commercial dispute between companies. When distilled models are built through illicit methods, they lack necessary safeguards - meaning dangerous capabilities can proliferate with many protections stripped out entirely. Foreign labs that distill American models can feed these unprotected capabilities into military, intelligence, and surveillance systems.
Who Is at Risk?
Direct risk applies to any organization or developer routing LLM API calls through a third-party provider that is not an official API partner. This includes teams using discount API brokers, startups cutting costs through reseller channels, and research groups accessing models through unofficial endpoints.
The user base spans university professors, students, tech workers, individual developers, and hobbyists. Risk is highest in regions where frontier models are geo-blocked (China, Iran, Russia), but extends globally wherever cost pressure pushes buyers toward cheaper alternatives. An indirect risk hits organizations whose employees or contractors use these proxies without central IT awareness.
Real-World Vulnerability Scenarios
Four common scenarios that expose organizations to risk:
- Offshore Development Team: A dev team in China that can't access Claude directly quietly routes requests through a proxy. Company proprietary code is captured in proxy logs.
- Budget-Constrained Startup: A startup picks a discount "API broker" to save on API costs without asking how the discount works. Customer data is being harvested.
- Developer Side Project: A developer copies a cheap provider config from a side project into production. Nobody knows the endpoint has changed.
- Supply Chain Attack: Malicious npm or PyPI packages that plant proxy relays on your machines without anyone choosing it.
Key Point: In most cases, dark token usage is accidental or unwitting - not intentional.
Real Risks: What's at Stake?
Prompt logs harvested by proxy operators are a high-value asset with multiple uses. For fraud, they contain financial details, authentication patterns, personal information, and business logic that users disclosed in conversation with the model. For distillation, the reasoning traces from frontier models (especially Claude Opus chain-of-thought outputs) are exactly the training data needed to fine-tune cheaper open-weight models.
There's also the reliability risk which is immediate for organizations that unknowingly consume dark tokens through a supply chain. A model swap from Opus to Haiku or Qwen degrades your output quality silently. If your application depends on a specific model's reasoning capability (medical triage, code generation, legal analysis), a swap can produce subtly wrong outputs with no error signal.
The Breach You Never See
The dark token economy is unlikely to produce a single dramatic breach or security incident. Prompt data is leaking through thousands of small proxy operators simultaneously, and the downstream uses (fraud, distillation, targeted social engineering) are hard to trace back to the original exposure. An organization that routed API traffic through a proxy for six months may never learn that its internal documents ended up in a training dataset or that its customers' financial details were sold to a fraud ring.
The more pressing near-term risk is silent model degradation. Applications that depend on a specific model's reasoning quality can fail in subtle, hard-to-diagnose ways when the underlying model is swapped without notice. In high-stakes domains like medical triage, legal analysis, or financial modeling, those failures carry real consequences, and the absence of an error signal means they can persist for weeks or months before detection.
Defense Guide: How to Protect Yourself
If you're not in a geo-blocked region, you probably won't end up using a transfer station on purpose since you can have direct API access to any model you need. The more realistic ways this touches you are indirect: an offshore dev team quietly routing calls through a proxy, a startup picking a discount API broker without asking how the discount works, or a developer copying a cheap provider config from a side project into production.
Defense Checklist: 6 Immediate Actions
Practical steps to protect your organization:
- Pin and Monitor API Endpoints: Lock official API base URLs in your configuration management and enforce them through egress controls. Audit CI/CD pipelines for unauthorized endpoint changes.
- Run Model-Verification Checks: Send periodic canary queries: known-answer prompts sent to your API endpoint, with responses compared against baselines from the official API.
- Track Output Quality Over Time: If your LLM-dependent application starts producing lower-quality outputs and no code, prompt, or model version has changed, a silent model swap upstream is a plausible cause.
- Audit Third-Party Providers: If you use an LLM API reseller or aggregator, verify their upstream relationship with the model lab. Ask for proof of an official partnership or API agreement.
- Inventory Shadow AI Usage: Developers under cost pressure may adopt discount API services without going through procurement. Centralizing API access through an approved gateway gives you visibility.
- Treat Any Unofficial Endpoint as Untrusted: If sensitive data has been sent through a proxy, treat it as a potential data breach and follow your incident response procedures.
The Role of AI Companies: What's Being Done
Anthropic and other frontier AI companies are actively investing in defenses that make distillation attacks harder to execute and easier to identify. Anthropic has built several classifiers and behavioral fingerprinting systems designed to identify distillation attack patterns in API traffic. This includes detection of chain-of-thought elicitation used to construct reasoning training data. They have also built detection tools for identifying coordinated activity across large numbers of accounts.
Intelligence sharing is also happening. Anthropic is sharing technical indicators with other AI labs, cloud providers, and relevant authorities. This provides a more holistic picture into the distillation landscape. Access controls have been strengthened: verification for educational accounts, security research programs, and startup organizations - the pathways most commonly exploited for setting up fraudulent accounts.
Ethical Debates: Legitimate Distillation vs. Theft
One of the most complex aspects of this saga is the ethical debates it has sparked. Some critics argued it was hypocritical for Anthropic to object to companies using its models' outputs for training, when AI developers commonly train models on copyrighted material, presuming that this activity is fair use. Others framed the accusations as an attempt by Anthropic to maintain its competitive advantage by encouraging tighter U.S. regulation of Chinese AI firms.
But there's an important distinction: distillation itself is a legitimate, accepted technique. All major AI companies use it. The problem is when distillation is conducted through fraudulent means - fake accounts, stolen identities, circumventing geographic restrictions, and explicit violation of terms of service. This is no longer a technical or ethical debate - it's a legal and national security issue.
Different Perspectives on the Issue
Three main viewpoints on the distillation debate:
- U.S. Company Perspective: Unauthorized distillation is industrial-scale technology theft that strips security safeguards and undermines America's competitive advantage.
- Open-Source Advocate Perspective: AI knowledge should be available to all. Restricting access to models harms legitimate developers while failing to stop determined actors.
- Copyright Critic Perspective: AI companies that themselves trained on copyrighted data cannot ask others not to use their outputs.
Reality: Using fraudulent and illegal means to gain access to proprietary AI models is unacceptable - regardless of whether distillation itself is legitimate.
The Future of the Black Market: Where Are We Heading?
The LLM dark token market is unlikely to disappear anytime soon. As long as a significant price spread exists between official APIs and the black market, the arbitrage opportunity remains for operators. And as frontier model prices increase, that spread grows larger. The Token Price Index shows that AI inference costs are rising - especially for top-tier models like GPT-4, Claude Opus, and Gemini Ultra.
The Shanghai operator arrest in early 2026 showed governments are starting to take this seriously. But one arrest in one city in China will have little impact on a global market that operates primarily online. The White House memorandum was an important step, but actual enforcement has yet to be seen. Will the U.S. impose targeted sanctions against specific Chinese companies? Will export controls expand to cover proxy software?
Ultimately, the long-term solution likely requires a combination of technical, legal, and policy measures. AI companies must build better defenses - strict caps for API keys, better detection of unusual patterns, and more cooperation on threat intelligence sharing. Governments must provide clear laws about what's legal and what's illegal, and enforce those laws. And the international community must agree on norms around responsible AI use.
Conclusion: A Multi-Layered Threat
The LLM dark token market is a multi-dimensional threat with security, economic, and geopolitical dimensions. For individual developers and startups, it's the danger of data exposure, quality degradation, and legal risks. For major AI companies, it's a threat to revenue, intellectual property, and control over who uses their technology. For governments, it's a national security threat - a way to circumvent export controls and proliferate AI capabilities without necessary safeguards.
Anthropic's February 2026 disclosure was a watershed moment. For the first time, an American company with documented technical evidence showed that industrial-scale distillation is a reality - not a conspiracy theory or industry rumor. 16 million exchanges from 24,000 fraudulent accounts represent just three companies. How many other companies are conducting similar operations that haven't been detected yet? How many innocent developers are unwittingly contributing to this system through a discount proxy?
Key Messages for Different Stakeholders
For Developers and Startups:
- Never change API endpoints without verifying the source
- Avoid discount providers without official partnerships
- Run periodic model verification checks
For Large Companies:
- Implement centralized API gateways with monitoring
- Train offshore teams on proxy risks
- Enforce egress controls to verify API endpoints
For AI Companies:
- Offer strict caps for API keys
- Improve distillation detection algorithms
- Collaborate with other labs on threat intelligence
For Policymakers:
- Create clear laws on legitimate vs. illicit distillation
- Enforce and update export controls
- Work with allies to coordinate policies
The reality is that this market is by no means limited to China. The current focus on China is due to geographic restrictions that create more pressure for proxy solutions. But as API prices rise globally, the incentive to find cheaper access grows everywhere. Black markets thrive when the price spread between legal and illegal product is large enough. And with inference costs continuing to rise, that spread will only get larger.
The question isn't whether this market will continue - it's how large it will grow and what damage it will cause along the way. For organizations that act today, the risk is manageable. For those waiting until a breach happens, it may be too late - because with dark tokens, you might never know a breach occurred.
Frequently Asked Questions
What exactly are Dark Tokens and how do they differ from regular API keys?
Dark Tokens refer to API tokens sourced through unauthorized methods - like account farming, trial abuse, or credit card fraud. Unlike legitimate API keys purchased directly from the provider, dark tokens are sold through proxy services that pool fraudulent accounts. The key differences: price (50-90% discount), risk (data harvesting, model swapping), and legality (violates TOS and potentially laws).
How can I tell if my API endpoint has been compromised?
Several signs: 1) Check if ANTHROPIC_BASE_URL or OpenAI base URL has been changed 2) Run canary tests with known-answer prompts 3) Monitor output quality - if it's degraded without code changes, model swapping may have occurred 4) Audit network egress for unauthorized connections to LLM domains 5) Ask your dev team if anyone changed the endpoint. If nobody knows why, that's a red flag.
Is using dark tokens illegal?
Yes, in most jurisdictions. Even if you're not directly committing fraud, using services that rely on stolen accounts, fake identities, or fraudulent credit cards can make you complicit in illegal activity. It also violates the terms of service of all major LLM providers, which can result in account suspension, legal action, or liability for damages.
Why did Anthropic only accuse three Chinese companies? Aren't more involved?
Anthropic only disclosed companies it could attribute with "high confidence" through IP correlation, request metadata, and infrastructure indicators. There are likely more companies involved that Anthropic can't definitively identify or has decided not to disclose for strategic or legal reasons. These three cases are probably just the tip of the iceberg.
How does Model Swapping work and why do proxy operators do it?
When you request Claude Opus from a proxy, the proxy may actually send the request to Claude Haiku (cheaper) or an open-weight model like Qwen. You pay for Opus, but receive Haiku output. The proxy pockets the cost difference. CISPA testing showed this happens in ~50% of requests on shadow APIs. Reason: higher margins. Opus can be 10x more expensive than Haiku, so swapping dramatically increases profitability.
Is distillation always illegal or unethical?
No, distillation is a legitimate, accepted machine learning technique. OpenAI uses GPT-4 to train GPT-4o-mini, Anthropic uses Claude Opus for Haiku. The problem is when: 1) fraudulent or stolen accounts are used for access 2) geographic restrictions or TOS are violated 3) outputs are used without permission to train competitor models 4) safeguards are stripped in the process. The difference between legal and illegal distillation is in how the training data is obtained.
Sources and References
This report was compiled based on verified research from the following trusted sources:
- Anthropic Official: Detecting and Preventing Distillation Attacks (February 23, 2026)
- Simon Willison: An Inside Look at the Relay Market (July 26, 2026)
- DeepLearning.AI: Inside the Gray Market for LLM Access
- SOCRadar: Dark Token Economy: Unauthorized LLM API Proxies (July 21, 2026)
- CNBC: Anthropic accuses DeepSeek, Moonshot and MiniMax
- TechCrunch: Anthropic accuses Chinese AI labs of mining Claude
- The Weather Report: GitHub repository research and proxy tools analysis
- CISPA Helmholtz Center: Shadow API testing and model swapping benchmarks
- ChinaTalk: Comprehensive marketplace and black market ecosystem report
- White House Memorandum: April 2026 memorandum on industrial-scale distillation
All information and statistics in this report are extracted from official and verified sources and confirmed through web search. (Last updated: July 27, 2026)
Additional Gallery: Tekin Analysis: The Dark Token Market & LLM API Proxy Theft














