Investigations and academic research warn that unofficial AI API proxies may log user data, substitute cheaper models, and depend on fraudulent upstream accounts, making unusually low prices a security and reliability risk.
ChinaTalk reporter Zilan Qian examined Chinese AI API proxy services, often called “transfer stations,” that advertise access to Claude and other frontier models at roughly 10% of official prices. The services typically route customer requests through intermediary infrastructure rather than giving users a direct relationship with the model provider, according to ChinaTalk’s investigation.
That arrangement creates a basic privacy concern: prompts and model outputs pass through the proxy operator’s systems. ChinaTalk reported that these logs can become assets for model training, data brokerage, or fraud. For users, that could mean exposing confidential code, business plans, research, or personal information to a company whose security practices and commercial incentives are difficult to assess.
The reporting does not establish that every third-party provider misuses customer data. It does show, however, that low prices may reflect more than efficient infrastructure or bulk purchasing.
The risk also extends to model identity. In Real Money, Fake Models: Deceptive Model Claims in Shadow APIs, researchers from the CISPA Helmholtz Center for Information Security examined 17 unofficial or “shadow” APIs. They reported evidence that some services made deceptive claims about the models available behind their endpoints.
The researchers found performance divergence of up to 47.21% and failed to verify the claimed model identity in 45.83% of fingerprint tests. A customer who believes they are paying for a premium model could instead receive a cheaper or different system, with different capabilities, context limits, safety behavior, and potentially different data practices.
Tom’s Hardware, which reported on Qian’s investigation, likewise said some proxy networks can advertise Claude while substituting lower-cost models. This may be difficult for ordinary users to detect when the service preserves a familiar API format or simply reports the model name supplied by the reseller.
Anthropic has separately described efforts to detect and prevent model-distillation attacks. In its account of the problem, the company said one proxy network operated more than 20,000 fraudulent accounts and mixed suspected distillation traffic with unrelated customer requests, complicating detection. See Anthropic’s report.
That creates a reliability risk for customers using unofficial access. If an upstream provider detects and shuts down the accounts supporting a proxy, the reseller’s service may disappear with little notice. Customer traffic can also share infrastructure with abusive activity that users cannot see or control.
Direct access from a model provider does not eliminate every privacy or security risk, but it can reduce uncertainty about who receives prompts and which model is being used. Organizations handling confidential material should favor direct provider accounts or vetted enterprise intermediaries with clear contracts, retention policies, and model-provenance documentation.
Before using a reseller, customers should establish who operates it, whether prompts and outputs are logged, how long data is retained, whether information is used for training or resale, and whether the advertised model can be independently verified. An unusually cheap API may be a bargain—but it may also transfer the costs to privacy, reliability, or model quality.
The services typically route customer requests through intermediary infrastructure rather than giving users a direct relationship with the model provider, according to ChinaTalk’s investigation.
That arrangement creates a basic privacy concern: prompts and model outputs pass through the proxy operator’s systems.
ChinaTalk reported that these logs can become assets for model training, data brokerage, or fraud.
Continue reading