Accounts Keep Getting Banned? I Turned My Life-Saving Account Security Setup into a Single-Machine Checklist
Lately the group chats in Beijing, Shanghai, Shenzhen, and Hangzhou have all seen officially subscribed Claude Code accounts banned pretty much across the board. Meanwhile the 26 accounts used by me and the founders I coach haven't had a single incident—and plenty of them fly around the world year-round.
That isn't luck. Before I got this setup right, I had 15 accounts banned. This episode turns that experience into a single-machine checklist: 8 post-ban cleanup items + 28 security configuration items, each one covering only what to set, where to set it, and why.
Over the past stretch, in the group chats around me—Beijing, Shanghai, Shenzhen, Hangzhou, all of them—officially subscribed Claude Code accounts have been banned pretty much across the board.
Meanwhile, the 26 accounts used by my own team plus the CEOs and founders I coach haven’t had a single incident so far. Plenty of those people fly around the world year-round and still get stable use out of them. I think I must have done a few things right.
Just this morning Fable 5 came off restriction, and Sonnet 5 was updated yesterday. There’s no denying one thing: when you’re leaning on models for real work, the capability gap between them is wide. So a lot of people around me have come asking whether I can set up a relatively safe way for them to use CC.
I went back and forth on this for a long time. I definitely don’t have time to configure it for people one by one, so I decided to release this guidance checklist instead. Before I got this setup right, I’d already had 15 accounts banned, local and remote, and it cost me a lot of time studying and testing.
Honestly, even with this approach in hand, 99.99% of people won’t be willing to spend the effort and money to actually do it. And a video with truly detailed content would never get published. So behind every item on this list, you’ll have to study further and try it yourself before you have a shot at configuring it successfully. Plenty of the steps take real money and real prerequisites to pull off. Bookmark it and work through it slowly, or search “Zhang Pinpin” on Google to find my blog and read the full transcript.
One premise up front: this is experience, not a guarantee
To be clear up front: this is distilled experience, which means it isn’t 100% accurate and can’t guarantee you won’t get banned.
When I shared it in the group chats, plenty of people pushed back: does it really need to be this complicated? They said they’d only done such-and-such and were using the official subscription just fine. Those people’s accounts are dead now too. Better safe than sorry. So some items on this list are verified, absolute risks, and others are cautious recommendations.
The most common question I get: my device fingerprint has been recorded, should I switch machines? My answer: switching is obviously better. But from what I’ve seen in practice, none of my machines that had an account banned and then registered a new one got re-banned over the device fingerprint. So I’ll still recommend switching, because the fingerprint absolutely does get recorded—but whether you actually switch is your call.
1. After an account is banned, what to wipe from this machine
- The desktop app needs to be logged out;
- The terminal version, correspondingly, needs the old account’s login info deleted, along with the login info in the config folder;
- Replace the entire registration identity—card, email, phone number. There have been clear cases of guilt-by-association bans here;
- If you saved the account in Stripe Link, delete that too;
- A phone number isn’t strictly necessary: if the rest of your configuration is rigorous enough and the account is assessed as very low risk, you don’t actually need a phone for verification codes at registration;
- If you’re on a Chromium-based browser, the old user profile folder can be deleted wholesale—create a new profile and use that;
- If you want to be thorough, the computer name and system user account can be changed as well.
2. Day-to-day security configuration
First item: use the right bank card. A corporate card is safest but costs more—a card issued by Mercury, for instance, is the best option for company use. Next best is a real credit card, a physical one. Worst of all is a virtual card with 3DS support.
New accounts need independent payment details; billing addresses must not repeat. And whatever you do, don’t save the card to Stripe Link again—it can correlate across sites and across sessions.
For the account (email), the best option is an international domain you registered yourself with your own mail system, rather than a Google, Apple, or Microsoft account. I covered this thoroughly in another video. Someone in the comments played expert and said Google accounts don’t leak users’ private information—true, they don’t leak privacy, but they do rate accounts.
The registration details all have to look like they belong to the same person, and the machine’s hardware configuration has to be fully consistent too. That includes your broadband setup, which gets classified as well—there’s a distinction between what they call Class A addresses and corporate-assigned ones.
I won’t go through the rest item by item. The single most important piece is giving Chrome safe launch flags: set the browser language consistently, block WebRTC detection, disable location, disable automatic time zone and set it to one matching your IP, and turn off IPv6. With all that in place you don’t actually need an anti-detect browser—though an anti-detect browser plus terminal-only usage is safer still.
There are also some odd special-case items: on Mac, if you want to be rigorous, turn off iCloud Private Relay. Another hidden trap is local antivirus wiping out some of our configuration, so remember to add those apps to its whitelist. And one more—when Claude Code connects, it doesn’t only reach Claude’s official site; telemetry goes to other endpoints, and those absolutely have to be added to your proxy list too.
At bottom, this isn’t a crack—it’s not getting hit by mistake
After all that, someone will inevitably jump in to argue: why go to all this trouble, just use Codex. GPT 5.5 is strong too, and 5.6 is about to drop.
To which I’d say: good luck to you. Only people who have actually used the official Claude Code subscription and done a lot of real work on it know how good Claude Code is—let alone the people who’ve experienced Fable 5’s crushing level of intelligence. I still hold the same view: as long as I can find a way to get access, I’ll use the best model.
That’s it for today. See you next episode.
I’ve turned the companion “Claude Account Security Checklist” into a single web page you can audit against line by line: 8 post-ban cleanup items + 28 security configuration items, each covering only what to set, where to set it, and why—no step-by-step instructions. Once more, for emphasis: it isn’t a crack and it doesn’t guarantee 100%. Fundamentally it’s about making a legitimately paying account present a consistent, real identity so risk systems don’t hit it by mistake.
Source: EP0056_audio.mp3 · ASR model gemini-2.5-pro (chunked parallel) · full text of the original recording
[00:00] Banned again, again, again, again—now what? What I’ve got for you today is the most complete checklist anywhere for clearing your history and locking down your security configuration. Lately, in the groups I’m in—Beijing, Shanghai, Shenzhen, Hangzhou, doesn’t matter—official Claude Code subscription accounts have been wiped out just about across the board. Meanwhile, of the 26 accounts used by my own team and by the CEOs and founders I do ongoing coaching for, not a single one has had a problem to this day. And a lot of those people fly all over the world. To be able to use it stably like that, I think I must have done some things right. Fable 5 came off restriction this morning, and Sonnet 5 was updated yesterday.
[00:25] And one thing you have to admit is that when you’re using this deeply in a real business, there’s still a pretty big gap in model capability. So a lot of people out there have come to me asking whether I can set up a relatively safe way for them to use CC. I went back and forth on it for a long time—I definitely don’t have time to configure all of it for them. So I decided to put out this guidance checklist instead. Before I got this configuration nailed down, I’d had 15 accounts banned, local and remote, and spent a lot of time learning and testing. But honestly, even handed this plan, 99.99% of people
[00:50] still won’t be willing to put in the effort and the cost to actually implement it. And if I made a video with the details in it, it definitely wouldn’t get published. So behind every single item of this configuration, you’re going to have to go learn more on your own and try it yourself before you have a shot at getting it configured successfully. And a lot of the steps require hard costs and hard prerequisites to pull off. Hit the heart and save this, and work through it slowly. And of course you can also search Zhang Pinpin on Google, find my blog, and read the full transcript. So let’s look at this configuration. First off, this is a set of lessons distilled from experience, which means it isn’t 100% accurate and it can’t guarantee we’ll never get banned.
[01:15] And when I shared this in the group before, plenty of people questioned whether it needs to be this complicated. They said they only did such-and-such and they’re using the official subscription perfectly fine. Well, those people’s accounts are all dead now. Like they say, better safe than sorry. So the items on this list—some of them are verified, absolute risks, and some are cautious recommendations. For instance, the most frequently asked one: my device fingerprint has been recorded, should I switch to a different computer? My answer is definitely that switching is better. But from what I’ve seen so far,
[01:40] for me personally, of the machines where I’d had an account banned and then registered a new account on the same machine, not one of them got re-banned because of the device fingerprint. So if you ask me, I’ll definitely recommend you switch computers, because that device fingerprint absolutely does get recorded. But whether you actually go switch is your own call. So first: once an account gets banned, what does this computer need to do? The desktop app needs to sign out, and you also need to delete the old account’s login info out of the config folder. And the recommendation is to replace the entire registration identity—card, email, phone number. There have definitely been cases of guilt-by-association
[02:05] bans. And if you’ve saved the account in Stripe Link, delete that too. As I said in that earlier video, a phone number isn’t a hard requirement—if the rest of your configuration is rigorous enough and the account gets judged extremely low-risk, you actually don’t need a phone number to receive a code at registration. And if we’re using a Chromium-based browser, the old user profile folder in that browser can be deleted wholesale and you can create a new user to work with. And if you want to be really thorough, you can also change the computer name and the system account. Now, when it comes to the security configuration itself, item one is use the right bank card. A corporate card is the safest bet,
[02:30] but it costs more. Something like a Mercury-issued card is the best option for company use. Next best is a real, physical credit card. The worst, worst case is a virtual card that supports 3DS. A new account needs its own separate payment information—the billing address can’t be one you’ve used before. And whatever you do, don’t save the card to Stripe Link again; it can link things across websites and across conversations. As for the account itself, the best move is to use an international domain you registered yourself and stand up your own email system, rather than using a Google, Apple, or Microsoft account. I explained this point very clearly in another video before.
[02:55] And someone still put on a know-it-all act in the comments and replied, oh, a Google account won’t leak the user’s private information. Right, it won’t leak your privacy—but it will assign your account a rating. Beyond making your registration details all look like one coherent person, the computer’s entire hardware configuration has to be completely consistent too. That includes your broadband setup, which really does get sorted into what they call class A addresses versus ones registered to a company. For the rest of the configuration I won’t go through it item by item. The most critical approach is to give the Chrome browser secure launch parameters. Set the browser language consistently, block WebRTC detection,
[03:21] turn off location, turn off automatic time zone, adjust to a time zone that matches your IP, and turn off the IPv6 protocol. If you’ve got all of that configured, you actually don’t need an anti-fingerprint browser. Although using an anti-fingerprint browser plus going terminal-only is even safer. And there are some weird, special configurations too. If you want to be rigorous, you can turn off iCloud Private Relay. And one hidden trap is that your local antivirus software will wipe out some of your configuration—remember to add it to the whitelist. And another thing: when Claude Code itself connects out, it doesn’t just connect to
[03:46] Claude’s official site. Telemetry uses a different address, and there are some others—you absolutely have to add those in. So after all that, some nitpicker is going to jump out and say, why go to all this trouble, just use Codex, GPT 5.5 is plenty strong too, and 5.6 is coming out any minute now, and so on and so forth, right? All I’ll say is: I hope you two are very happy together. Only people who’ve actually used the official Claude Code subscription for a lot of real business work know how good Claude Code is. Never mind the people who’ve already experienced Fable 5’s crushing intelligence. I still hold the same view: as long as I can find a way to get access to it, I’m always going to use the best model.
[04:12] So that’s today’s episode. See you next time, bye-bye.