← Back to home

Accounts Keep Getting Banned? I Turned My Life-Saving Account Security Setup into a Single-Machine Checklist

Long-Form Video · EP0056 July 2, 2026 4:15
What this episode covers

Lately the group chats in Beijing, Shanghai, Shenzhen, and Hangzhou have all seen officially subscribed Claude Code accounts banned pretty much across the board. Meanwhile the 26 accounts used by me and the founders I coach haven't had a single incident—and plenty of them fly around the world year-round.

That isn't luck. Before I got this setup right, I had 15 accounts banned. This episode turns that experience into a single-machine checklist: 8 post-ban cleanup items + 28 security configuration items, each one covering only what to set, where to set it, and why.

Companion files · Drop them into Claude Code

Over the past stretch, in the group chats around me—Beijing, Shanghai, Shenzhen, Hangzhou, all of them—officially subscribed Claude Code accounts have been banned pretty much across the board.

Meanwhile, the 26 accounts used by my own team plus the CEOs and founders I coach haven’t had a single incident so far. Plenty of those people fly around the world year-round and still get stable use out of them. I think I must have done a few things right.

Just this morning Fable 5 came off restriction, and Sonnet 5 was updated yesterday. There’s no denying one thing: when you’re leaning on models for real work, the capability gap between them is wide. So a lot of people around me have come asking whether I can set up a relatively safe way for them to use CC.

I went back and forth on this for a long time. I definitely don’t have time to configure it for people one by one, so I decided to release this guidance checklist instead. Before I got this setup right, I’d already had 15 accounts banned, local and remote, and it cost me a lot of time studying and testing.

Honestly, even with this approach in hand, 99.99% of people won’t be willing to spend the effort and money to actually do it. And a video with truly detailed content would never get published. So behind every item on this list, you’ll have to study further and try it yourself before you have a shot at configuring it successfully. Plenty of the steps take real money and real prerequisites to pull off. Bookmark it and work through it slowly, or search “Zhang Pinpin” on Google to find my blog and read the full transcript.

One premise up front: this is experience, not a guarantee

To be clear up front: this is distilled experience, which means it isn’t 100% accurate and can’t guarantee you won’t get banned.

When I shared it in the group chats, plenty of people pushed back: does it really need to be this complicated? They said they’d only done such-and-such and were using the official subscription just fine. Those people’s accounts are dead now too. Better safe than sorry. So some items on this list are verified, absolute risks, and others are cautious recommendations.

The most common question I get: my device fingerprint has been recorded, should I switch machines? My answer: switching is obviously better. But from what I’ve seen in practice, none of my machines that had an account banned and then registered a new one got re-banned over the device fingerprint. So I’ll still recommend switching, because the fingerprint absolutely does get recorded—but whether you actually switch is your call.

1. After an account is banned, what to wipe from this machine

  • The desktop app needs to be logged out;
  • The terminal version, correspondingly, needs the old account’s login info deleted, along with the login info in the config folder;
  • Replace the entire registration identity—card, email, phone number. There have been clear cases of guilt-by-association bans here;
  • If you saved the account in Stripe Link, delete that too;
  • A phone number isn’t strictly necessary: if the rest of your configuration is rigorous enough and the account is assessed as very low risk, you don’t actually need a phone for verification codes at registration;
  • If you’re on a Chromium-based browser, the old user profile folder can be deleted wholesale—create a new profile and use that;
  • If you want to be thorough, the computer name and system user account can be changed as well.

2. Day-to-day security configuration

First item: use the right bank card. A corporate card is safest but costs more—a card issued by Mercury, for instance, is the best option for company use. Next best is a real credit card, a physical one. Worst of all is a virtual card with 3DS support.

New accounts need independent payment details; billing addresses must not repeat. And whatever you do, don’t save the card to Stripe Link again—it can correlate across sites and across sessions.

For the account (email), the best option is an international domain you registered yourself with your own mail system, rather than a Google, Apple, or Microsoft account. I covered this thoroughly in another video. Someone in the comments played expert and said Google accounts don’t leak users’ private information—true, they don’t leak privacy, but they do rate accounts.

The registration details all have to look like they belong to the same person, and the machine’s hardware configuration has to be fully consistent too. That includes your broadband setup, which gets classified as well—there’s a distinction between what they call Class A addresses and corporate-assigned ones.

I won’t go through the rest item by item. The single most important piece is giving Chrome safe launch flags: set the browser language consistently, block WebRTC detection, disable location, disable automatic time zone and set it to one matching your IP, and turn off IPv6. With all that in place you don’t actually need an anti-detect browser—though an anti-detect browser plus terminal-only usage is safer still.

There are also some odd special-case items: on Mac, if you want to be rigorous, turn off iCloud Private Relay. Another hidden trap is local antivirus wiping out some of our configuration, so remember to add those apps to its whitelist. And one more—when Claude Code connects, it doesn’t only reach Claude’s official site; telemetry goes to other endpoints, and those absolutely have to be added to your proxy list too.

At bottom, this isn’t a crack—it’s not getting hit by mistake

After all that, someone will inevitably jump in to argue: why go to all this trouble, just use Codex. GPT 5.5 is strong too, and 5.6 is about to drop.

To which I’d say: good luck to you. Only people who have actually used the official Claude Code subscription and done a lot of real work on it know how good Claude Code is—let alone the people who’ve experienced Fable 5’s crushing level of intelligence. I still hold the same view: as long as I can find a way to get access, I’ll use the best model.

That’s it for today. See you next episode.


I’ve turned the companion “Claude Account Security Checklist” into a single web page you can audit against line by line: 8 post-ban cleanup items + 28 security configuration items, each covering only what to set, where to set it, and why—no step-by-step instructions. Once more, for emphasis: it isn’t a crack and it doesn’t guarantee 100%. Fundamentally it’s about making a legitimately paying account present a consistent, real identity so risk systems don’t hit it by mistake.

It isn't a crack and it doesn't guarantee 100%—fundamentally it's about making a legitimately paying account present a consistent, real identity so risk systems don't hit it by mistake.