Insights Business| SaaS| Technology The Two and a Half Billion Dollar Nvidia Chip Smuggling Pipeline to China
Business
|
SaaS
|
Technology
Jul 16, 2026

The Two and a Half Billion Dollar Nvidia Chip Smuggling Pipeline to China

AUTHOR

James A. Wondrasek James A. Wondrasek
The Two and a Half Billion Dollar Nvidia Chip Smuggling Pipeline to China

On 19 March 2026, US authorities charged Supermicro co-founder Yih-Shyan “Wally” Liaw and two associates with conspiring to divert $2.5 billion worth of Nvidia-powered AI servers to Chinese buyers. It was the largest documented AI chip diversion in dollar terms. But the number that should stick with you is the detail buried deeper in the indictment: between late April and mid-May 2025 alone, at least $510 million worth of servers moved through the pipeline. That is half a billion dollars in roughly three weeks.

Supermicro is the most thoroughly documented case in the wider Taiwan-China semiconductor enforcement story, but it is not the only one. The same playbook has been replicated across dozens of smaller operations. If a publicly traded, NASDAQ-listed company with audited financials and a compliance department could allegedly run a $2.5 billion diversion for years, what does that tell you about the thousands of unlisted entities operating without the scrutiny? The smuggling pipeline is a coherent, modular system. Its architecture, geography, and economics explain why enforcement can suppress specific routes but never close the market. We will start with the case that pulled the whole thing into the open.

What Is the Supermicro Chip Smuggling Case and Why Is It Significant?

The Supermicro case involves Liaw, along with Ruei-Tsang “Steven” Chang and Ting-Wei “Willy” Sun, allegedly routing servers containing restricted H200 and B200 GPUs through a Southeast Asian front company to Chinese buyers between 2024 and 2025. Liaw and Sun were arrested in California; Chang remains a fugitive. Liaw’s trial is set for November 2026.

The case matters across four dimensions. Operationally, it is the biggest: the front company became Supermicro’s 11th-largest customer globally, generating $99.7 million in revenue in fiscal 2024 alone. The governance dimension is where things get uncomfortable. Ernst & Young resigned as Supermicro’s auditor in October 2024 after raising concerns about internal controls months earlier. BDO stepped in as replacement, but an auditor resignation of that nature is a signal you cannot ignore. The Hindenburg Research short-seller report had already surfaced allegations that accelerated scrutiny. The stock fell 33% on the day the indictment was announced.

On the market side, Jensen Huang publicly rebuked Supermicro’s compliance failures. That matters because it went beyond what Nvidia is obligated to do. Nvidia’s legal duty is to sell to customers who certify compliant end-use. It is not required to investigate beyond that certification. Huang’s comments signalled a break from Nvidia’s usual posture toward its partners and an awareness of reputational exposure.

Then there is the enforcement dimension. The Supermicro case catalysed Taiwan’s June 2026 Keelung raids, with searches across 12 locations including Supermicro’s Taiwan office, Chief Telecom, and distributor Albatron Technology. And here is the detail that reframes the case: Supermicro had already been caught doing this. In 2006, it pleaded guilty to illegally exporting computer equipment to Iran through a Dubai distributor using identical transshipment methodology. Same architecture, different jurisdiction, same compliance gap. The company paid a $150,000 fine to the DOJ and a $125,400 civil penalty to BIS. Two decades on, the vulnerability was still there.

How Did the Hair Dryer and Serial-Number Sticker Swap Scheme Fool Compliance Auditors?

The compliance architecture for export controls has a single point of failure: it assumes serial-number sticker integrity. There is no cryptographic binding between the sticker and the GPU silicon. A heat gun and a steady hand defeat the verification chain.

Here is how it worked, and why it matters if you are trying to understand how supply chain controls actually break down in practice. Smugglers used heat guns to remove serial-number stickers from compliant-configured servers and reattach them to restricted H100, H200, and B200 hardware being diverted to China. The technique was captured on CCTV in the Supermicro case. Meanwhile, a Thailand front company placed purchase orders that appeared legitimate, creating a paper trail that satisfied initial compliance checks while the real servers were routed elsewhere.

The dummy server warehouse was the operational centrepiece. During the August 2025 compliance audit, Chang and Sun staged roughly 2,107 dummy units across three warehouses. These were non-working physical replicas, compliant-configured servers that sat ready for auditor inspection. The operation involved 100-person crews, forklift operations, arranged meals, and as the indictment notes, a “20-person shuttle bus for easy travel between the hotel and the warehouse.” During the audit itself, Supermicro’s compliance worker was off-site “enjoying entertainment” on the front company’s dime. Sun texted Liaw that the audit had run smoothly. Liaw replied, “That’s spectacular!” and continued placing new orders days later.

In December 2025, BIS sent its own inspector for a post-shipment verification check. Sun set up the dummy servers again, using a hair dryer to peel off labels and serial-number stickers, captured on surveillance cameras. He introduced himself as “Michael” and claimed he worked at the front company’s law firm while fielding questions from the federal BIS officer.

Why did this work? Auditor sampling methodologies were designed for paperwork verification, not physical tampering at industrial scale. The scheme exploited the temporal gap between inspection and shipment: auditors saw compliant servers at the declared location, but by the time those servers would have shipped, the restricted hardware was already in transit to China. The compliance regime was not built to detect a physical attack on a procedural control.

How Does AI Chip Smuggling from the US to China Actually Work in Practice?

The smuggling pipeline has four architecturally distinct layers, each exploiting a different gap in the control regime.

The acquisition layer is where restricted chips enter the system: legitimate purchasers divert orders, front companies with US addresses and bank accounts place orders that appear legitimate, and straw purchasers with US credentials falsely certify end-use. As one neocloud operator put it, “You just use a US entity. US address, US bank account, US paperwork. Then you funnel everything through Hong Kong or Malaysia.”

The staging layer handles warehousing and repackaging in intermediate jurisdictions, where serial numbers are swapped and export paperwork is reclassified. This is the hair-dryer layer. In the Operation Gatekeeper case, workers in a New Jersey warehouse removed Nvidia labels and applied counterfeit labels bearing “SANDKYAN,” a fictitious brand. GPUs were reclassified as “adapter modules” on export paperwork. Alan Hao Hsu pleaded guilty to smuggling $160 million in H100 and H200 GPUs.

The transit layer uses multi-hop routing through three or more jurisdictions to obscure the final destination. Encrypted communication coordinates nodes across borders. In the English-Kelly-Zheng case, the trio operated a WhatsApp group called “GPU Partnership”. When Matthew Kelly drafted a pitch mentioning China, Stanley Yi Zheng replied 28 minutes later: “DO NOT MENTION ANYTHING ABOUT CHINA” and instructed deletion of all references. Kelly had placed a $170 million purchase order for 750 servers, 600 of which contained chips requiring export licences.

The destination layer is where chips cross into China through misdeclared customs paperwork, concealment within legitimate shipments, and physical smuggling. The system is resilient precisely because it is modular. Close one route and nodes reorganise through alternative jurisdictions.

What Are the Transshipment Routes Through Southeast Asia and How Do They Operate?

Southeast Asia is a structurally optimal transshipment geography, and the reasons are not accidental.

The primary nodes follow a geographic logic. Thailand serves front-company procurement and initial staging. Malaysia, specifically Penang and Johor, operates as the major transshipment hub. Johor alone had 42 approved data centre projects totalling roughly $39 billion in investment as of mid-2025, with Chinese-linked operators controlling the majority of capacity. Bridge Data Centres, formerly Chindata Group, holds 32% of Johor capacity. DayOne, formerly GDS International, holds 29%. ByteDance is the anchor tenant at Bridge’s MY06 facility and in March 2026 signed a deal for roughly 36,000 Blackwell B200 GPUs in Malaysia.

Singapore functions as the financial and logistics coordination hub. Here is the number that quantifies the gap between declared and actual destinations: Singapore appears as 28% of Nvidia’s revenue but receives only 1% of chips. Nvidia acknowledges in SEC filings that customers use Singapore to centralise invoicing while products are “almost always shipped elsewhere.”

Vietnam provides alternative routing when primary nodes face scrutiny, and Japan is emerging as an additional alternative. The pattern is consistent across every documented case: chips declared for delivery to a Southeast Asian country, repackaged and relabelled, then re-exported to China with falsified origin documentation.

Why does Southeast Asia work so well? Legitimate semiconductor logistics infrastructure means legitimate and illegitimate traffic blend together. Customs agencies lack the capacity and technical expertise to distinguish controlled from uncontrolled chips at scale. And regional governments have limited incentive to enforce US export controls aggressively. Those controls serve American strategic interests, not necessarily theirs.

What Is the Scale of the AI Chip Black Market?

The black market is structurally rational.

Epoch AI’s Monte Carlo simulation, the most analytically rigorous estimate available, places the median at 660,000 H100-equivalent GPUs smuggled into China by the end of 2025, with a 90% confidence interval of 290,000 to 1.6 million. The estimate uses two parallel approaches: diversion evidence, tracking chips leaving legitimate channels, and resale evidence, tracking grey-market activity observed in Shenzhen’s Huaqiangbei electronics district where researchers found 132 domestic listings with roughly 100,000 GPUs in aggregate inventory.

The economics make the pipeline self-funding, and this is why you are going to keep reading about these cases. A single H100 that costs roughly $30,000 through legitimate channels commands $50,000 or more on the black market. A rack containing eight B200 AI GPUs costs roughly $420,000 to $490,000 in China, about 50% above US prices. That is over $100,000 profit per transaction. As Greg Thomas, CEO of ChainSentry, put it: “It comes down to something really simple. The money is just too good.”

Of 22 notable Chinese AI models developed through 2025, only two were trained exclusively on Chinese-designed chips. The demand is real, the supply is illegal, and the premium makes the risk worthwhile. Which brings us to the obvious question: if the economics are this compelling, why can’t the US government stop the flow?

Why Hasn’t the US Government Been Able to Stop the Flow of Smuggled Chips to China?

The enforcement architecture is structurally asymmetrical.

The Bureau of Industry and Security enforces US export controls with fewer than 600 employees, 150 special agents, and 11 export control officers stationed worldwide. Its IT systems date from 2006. Analysts use, as one assessment put it, “Google searches and Microsoft Excel” to determine whether Malaysian shell companies are fronts for Chinese military procurement. BIS Undersecretary Alan Estevez testified when asked if the systems were adequate: “The answer to that is an emphatic no.”

The asymmetry is measurable. Shell companies can be registered online in hours for a few thousand dollars. BIS investigations take years. One export control officer covers Australia, Singapore, and Malaysia combined. The bureau’s annual budget is $191 million. CSIS called that “approximately equivalent to two F-35 fighters.” The profits from three documented smuggling cases exceed the bureau’s entire annual enforcement budget.

Post-shipment verification checks are the primary on-the-ground mechanism: 1,440 completed across 60 countries in 2024. But the Supermicro case proved these checks can be defeated with dummy servers and a hair dryer.

Legislation is catching up. The Chip Security Act passed committee 42-0 in March 2026, requiring location verification and software-based authentication. The Remote Access Security Act passed the House 369-22 in January 2026, extending controls to cloud computing. The Stop Stealing Our Chips Act creates whistleblower incentives of 10 to 30% of resulting penalties. But none of these resolve the core asymmetry: hours to create a front company, years to investigate it.

CSIS Director Gregory Allen’s assessment captures the structural reality: “China has a reasonable expectation of success.”

Conclusion

The Supermicro case functioned as a stress test of the control regime’s design limits. The same transshipment methodology used for Iran in 2006 was redeployed for China. It worked because the control regime never addressed the underlying vulnerability, not because anyone failed to learn a lesson.

Taiwan’s Keelung raids, part of Taiwan’s dramatic enforcement pivot, represent an enforcement escalation, but Southeast Asian nodes face no equivalent pressure. Malaysia’s July 2025 permit requirement is a signal of concern, yet the $39 billion in data centre investment creates disincentives against aggressive enforcement. The pipeline’s modularity means traffic shifts rather than stops.

As long as a single H100 carries a roughly $20,000 premium, the pipeline generates its own fuel. The question is no longer “how do we stop the flow?” but “given that the flow cannot be stopped, what kind of control is actually achievable?” — the central question the full enforcement architecture confronts.

Frequently Asked Questions

Is it actually illegal to sell Nvidia chips to China, or is this a grey area?

It is unambiguously illegal. The US Commerce Department’s Entity List and export-control regulations, tightened in October 2022 and expanded through 2023 and 2024, explicitly prohibit the sale of advanced AI accelerators including the H100, H200, and B200 to Chinese entities without a licence, and licences are presumptively denied. There is no grey area: the chips require BIS authorisation, the authorisation is withheld, and any transaction that reaches China without it is a criminal violation of the Export Control Reform Act. What creates confusion is that chips are legal to sell into Southeast Asia, which smugglers exploit by declaring destinations where the sale is permitted and then diverting the hardware.

Can Nvidia track where its chips end up once they leave the factory?

Not reliably, and that is the core of the problem. Nvidia knows which serial numbers were shipped to which first-tier customer, but once a server is resold, repackaged, or stripped for parts, the tracking chain breaks. There is no cryptographic binding between the sticker and the GPU silicon, and Nvidia has no legal authority to audit downstream buyers in third countries. The company has invested in supply-chain visibility programs and cooperates with BIS investigations, but a heat gun and a steady hand render the entire serial-number tracking system moot. Physical custody cannot be verified by paperwork, and Nvidia’s control ends at the point of sale.

What happens to the individuals caught smuggling these chips?

They face federal prosecution with penalties that can reach decades in prison. Under the Export Control Reform Act, criminal violations carry up to 20 years per count, and the Justice Department has shown increasing willingness to pursue charges against both corporate officers and individual facilitators. Wally Liaw faces trial in November 2026. In the English-Kelly-Zheng case, defendants received sentences ranging from probation to several years. Financial penalties are also substantial, though asset recovery across jurisdictions remains difficult. The deterrent effect is real but limited: for every case that reaches indictment, the black-market economics suggest dozens of operations continue without detection.

Who is buying all these smuggled chips in China?

The buyers span a wide spectrum. At one end are state-linked research institutes and defence-affiliated entities that are explicitly barred from acquiring advanced chips and turn to the grey market as their only procurement channel. At the other end are commercial AI companies, cloud providers, and startups that cannot purchase legitimate H100s and pay the black-market premium because the alternative is falling behind competitors. The Shenzhen Huaqiangbei electronics district, with 132 domestic listings and roughly 100,000 GPUs in aggregate inventory, shows that the market serves a broad base: some buyers are building sanctioned military AI systems, but many are simply Chinese firms caught between enormous demand and a legal supply of zero.

Are smuggled H100 and B200 chips as good as legitimate ones?

Functionally, yes, which is why the premium exists. The silicon is identical. A smuggled H100 pulled from a diverted Supermicro server and a legitimately purchased H100 installed in a US data centre are the same GPU. The difference is in warranty, support, and software updates: Nvidia firmware updates and driver support do not reach unauthorised endpoints, and a chip that fails has no return path. There are also reports of chips being damaged during the repackaging process, particularly when serial-number sticker swaps involve heat stress, but for the buyer willing to accept these risks, the computational performance is indistinguishable from a legal purchase.

Has any country other than Taiwan seriously cracked down on chip smuggling?

No, and that is the geographic reality the pipeline exploits. Taiwan’s June 2026 Keelung raids represented a genuine enforcement escalation, driven by pressure the Supermicro case created for the Tsai administration. Outside Taiwan, enforcement is sparse. Malaysia has made one high-profile seizure in Johor, but its 42 approved data centre projects with $39 billion in investment, many linked to Chinese operators, create powerful disincentives against aggressive policing. Thailand, Vietnam, and Singapore face similar structural conflicts: their economies benefit from semiconductor logistics traffic, and US export controls are an American policy priority, not theirs. The pipeline flows through jurisdictions where enforcement incentives are misaligned with Washington’s objectives.

Why does Nvidia keep selling to suspicious customers if it knows chips might be diverted?

Because Nvidia’s legal obligation, as the regulatory architecture currently defines it, is to sell only to customers who certify compliant end-use. It is not required to investigate beyond that certification, and it lacks the legal authority to audit downstream behaviour in third countries. Jensen Huang’s public rebuke of Supermicro was significant precisely because it went beyond what Nvidia is obligated to do. The company could voluntarily cut off customers it suspects of enabling diversion, but doing so risks losing revenue to competitors and invites legal challenges from buyers who have not been convicted of any violation. The architecture places the burden of verification on government enforcement, not on the supplier.

How do Chinese buyers pay for black-market chips without triggering bank scrutiny?

Through layered financial structures that mirror the physical transshipment architecture. Payments are routed through intermediary entities in jurisdictions with lighter financial oversight, often using trade-based money laundering where over-invoicing or under-invoicing on legitimate goods masks the chip transaction. Cryptocurrency has also been documented in several cases as a settlement layer that avoids the correspondent-banking system entirely. The front company in Thailand that placed purchase orders with Supermicro was a legally registered entity with a real bank account, so the initial payment looked legitimate to compliance filters. The funds moved further downstream through channels that US financial surveillance cannot easily trace.

Is China close to making its own chips that rival Nvidia’s?

Not in the near term, and that gap is what drives the entire black market. Huawei’s Ascend 910B and 910C represent genuine progress, but by industry consensus they remain two to three generations behind Nvidia’s leading silicon in both performance and software ecosystem maturity. Closing that gap requires access to advanced fabrication equipment, which US and Dutch export controls on ASML lithography machines also restrict. China’s domestic chip design capability is improving rapidly, but manufacturing remains the bottleneck. The realistic timeframe for a competitive domestic alternative is measured in years, not months, which means the economic incentive for smuggling will persist throughout that window.

How much of the smuggling is state-directed versus purely criminal profiteering?

Both models operate simultaneously, and they often blur into each other. Some operations are clearly state-directed: chips destined for military AI programs are procured through networks that have direct links to Chinese defence entities, and the sophistication of certain logistics operations suggests official facilitation. Other networks are purely commercial: entrepreneurs who see a $20,000 margin per H100 and build businesses around it. The two models converge because the Chinese state is the ultimate beneficiary regardless of who organises the pipeline. A profit-motivated smuggler selling into Shenzhen’s Huaqiangbei market does not need state direction to serve state interests; the chips end up in China either way.

AUTHOR

James A. Wondrasek James A. Wondrasek

SHARE ARTICLE

Share
Copy Link

Related Articles

Need a reliable team to help achieve your software goals?

Drop us a line! We'd love to discuss your project.

Offices Dots
Offices

BUSINESS HOURS

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Monday - Friday
9 AM - 9 PM (Sydney Time)
9 AM - 5 PM (Yogyakarta Time)

Sydney

SYDNEY

55 Pyrmont Bridge Road
Pyrmont, NSW, 2009
Australia

55 Pyrmont Bridge Road, Pyrmont, NSW, 2009, Australia

+61 2-8123-0997

Yogyakarta

YOGYAKARTA

Unit A & B
Jl. Prof. Herman Yohanes No.1125, Terban, Gondokusuman, Yogyakarta,
Daerah Istimewa Yogyakarta 55223
Indonesia

Unit A & B Jl. Prof. Herman Yohanes No.1125, Yogyakarta, Daerah Istimewa Yogyakarta 55223, Indonesia

+62 274-4539660
Bandung

BANDUNG

JL. Banda No. 30
Bandung 40115
Indonesia

JL. Banda No. 30, Bandung 40115, Indonesia

+62 858-6514-9577

Subscribe to our newsletter