A collage depicts GPUs, Asian trade routes, cargo shipping, logistics inspections, and a $46B investigation.
C4ADS has documented three routes by which restricted Nvidia AI hardware can reach Chinese users—public university procurement, Southeast Asian transshipment, and opaque corporate ownership—but its most eye-catching figure has been widely overstated. The Washington nonprofit’s new Covert Compute report identifies Megaspeed International as a Southeast Asian importer that brought in $4.6 billion of Nvidia hardware between 2023 and 2025; it does not establish that $4.6 billion in chips was smuggled into China.

That distinction changes how the investigation should be read. C4ADS does present evidence of procurement and shipping patterns that warrant scrutiny, and it says the records it reviewed almost certainly undercount diversion. But the report also explicitly says its trade and government records identify risk, not completed transactions or legal violations. For IT buyers and infrastructure operators, the practical takeaway is less sensational and more demanding: screening the immediate customer is no longer adequate when controlled accelerators can move through legitimate-looking resellers, repair routes, and corporate structures.

Tom’s Hardware first highlighted the C4ADS findings this week. The underlying report, published September 9, draws on 371,442 Chinese government documents issued from July 2025 through January 15, 2026, trade records covering 2022 through 2025, and corporate-registration data. It follows earlier reporting by Bloomberg and The New York Times into Megaspeed, while recent Taiwanese prosecutions have provided a separate, concrete example of alleged illegal AI-server exports to mainland China.

Three pathways, three very different evidentiary records​

The clearest part of C4ADS’s work is its review of Chinese public procurement records. It found at least 56 restricted Nvidia chips worth about $1.7 million appearing in contracts awarded to Chinese universities and research institutions during its six-month review window. Those chips were bundled into broader, multimillion-dollar contracts and supplied through smaller companies that C4ADS describes as uncredentialed.

The report says most institutions involved had ties to the Chinese government or its defense industrial base. That is significant because an advanced GPU sale may be compliant at the first point of shipment yet still pose a diversion risk if a distributor cannot establish the real end user, the final deployment site, and whether the system will be transferred again.

But procurement paperwork is not proof that a chip reached a particular lab or was used for a prohibited purpose. C4ADS acknowledges that government records can show an announced contract without proving delivery, and that sensitive Chinese projects may not appear in public records at all. The documented 56-chip total is therefore a conservative visibility measure, rather than an estimate of the full market.

Its second category is transshipment. C4ADS identified 50 shipments of restricted Nvidia GPUs—covering A100, H100/GH100 and related hardware—moving through Vietnam, India and Malaysia toward Hong Kong and China from 2022 to 2025. The shipments total about $13.4 million and, in C4ADS’s assessment, show a recurring movement pattern inconsistent with straightforward local consumption.

The important word is pattern. Southeast Asian countries have real semiconductor assembly, testing, packaging, repair and data-center businesses. A component moving from Taiwan to Vietnam, for example, is not inherently suspicious. C4ADS says precisely this: legitimate repair and re-export activity can also provide cover for diversion, while import declarations may be incomplete, inaccurate, or deliberately misleading.

That limitation is more than legal boilerplate. It means neither a routing country nor an unusually structured shipment, by itself, proves sanctions evasion. The report’s contribution is showing why an exporter, distributor, freight forwarder, or server integrator should treat those facts as reasons for enhanced review rather than routine paperwork.


Megaspeed’s $4.6 billion is a red flag, not a proven China shipment total​

The third pathway is corporate opacity, centered on Singapore-based Megaspeed International. C4ADS describes the firm as the largest Southeast Asian importer of Nvidia hardware, citing prior Bloomberg and New York Times reporting, and says it imported $4.6 billion in Nvidia hardware between 2023 and 2025.

That figure is the report’s most consequential finding—and the one most vulnerable to distortion in short news coverage. It measures imports received by Megaspeed, not a verified value of exports to China, nor a confirmed value of illegal transfers. C4ADS says Megaspeed has “a web of ultimate beneficial owners” that may have ties to the People’s Republic of China. Its own legal disclaimer says naming an entity does not imply that entity violated a law or international agreement.

The question raised by the report is nevertheless serious. Corporate ownership changes can obscure who controls a buyer, and export rules increasingly care about the headquarters and ultimate parent of a customer, not merely the country printed on the shipping address. A chain involving a Singapore importer, an Indonesian operating company, a Malaysian facility, a Hong Kong counterparty and a Chinese beneficial owner is exactly the sort of structure that can defeat a compliance process designed around a one-time restricted-party screen.

C4ADS also points to previous reporting that Megaspeed came under U.S. scrutiny. That inquiry is not an adjudicated finding of wrongdoing. It does, however, show why enterprise hardware vendors cannot treat formal incorporation documents as enough proof of end-user identity when a buyer’s control, resale relationships, and data-center access arrangements remain unclear.

Export controls have changed faster than compliance workflows​

Nvidia’s own annual filing makes clear that the rules have shifted repeatedly. U.S. controls imposed in 2022 affected the A100 and H100 and systems containing them; the October 2023 revisions expanded licensing requirements to more products and destinations, including several countries that now feature prominently in diversion concerns.

In April 2025, Nvidia said the U.S. government required a license for H20 exports to China and certain China-linked destinations. The company later received licenses for some H20 shipments. In February 2026, Nvidia said it received a license allowing small H200 shipments to specific China-based customers, subject to U.S. inspection before export—but it had generated no H200 revenue under that program and did not know whether China would allow imports.

That makes blanket descriptions such as “the U.S. forbids all advanced Nvidia chips from China” inaccurate. The rules are chip- and threshold-specific, and licensing can change the result for particular models and recipients. H200 and AMD MI325X-class hardware became eligible for case-by-case license review under a January 15, 2026 Bureau of Industry and Security rule, while higher-performing products remained subject to tighter controls.

There is an additional compliance issue that hardware-focused reporting sometimes misses. In May 2026, BIS guidance said advanced-computing items including Nvidia Blackwell and Rubin products and AMD MI350X require licenses when destined for a China-headquartered company, even if that company uses an overseas subsidiary or offshore data center. A sale can therefore become problematic without the physical accelerator ever crossing the Chinese border.

For Windows and enterprise administrators, this is a reminder that the controlled asset may be more than the GPU card. AI servers, clustered systems, remote compute access, maintenance contracts, firmware support, management-plane credentials, and capacity leases can all become part of the end-use picture. A shipment may look domestic on an invoice while the useful compute is delivered to a prohibited customer through remote administration or leased data-center capacity.


The record supports a leakage problem, not a precise total​

C4ADS is cautious about extrapolation, and readers should be too. Its report only counted hardware explicitly named in accessible contracts and trade records. It did not attempt to capture chips relabeled under generic server descriptions, components moved through informal channels, hardware from AMD or Intel, transactions outside its selected trade routes, or Chinese customers using offshore cloud capacity instead of importing hardware.

Epoch AI reached a broader but model-based estimate in April: between 290,000 and 1.6 million H100-equivalents may have been smuggled into China through the end of 2025, with a median estimate of 660,000 H100-equivalents—roughly one-third of China’s AI compute. Epoch AI also stressed the range is wide because undetected transfers and the final destination of allegedly diverted chips are inherently hard to observe.

The two reports should not be added together. C4ADS is mapping observable pathways and named transactions; Epoch AI is estimating aggregate compute using a different methodology. Together, they support the conclusion that diversion is large enough to affect the strategic purpose of export controls. They do not prove an exact chip count, nor do they show that most Chinese AI capacity relies on smuggled Nvidia silicon.

Recent enforcement activity demonstrates that these are not merely theoretical vulnerabilities. The Associated Press reported this month that Taiwanese prosecutors charged nine people, including an Nvidia employee and two Super Micro employees, over alleged illegal exports of high-end AI servers to China. Charges remain allegations, but the case supplies an independent example of the multilayered supply-chain exposure C4ADS describes.

Post-shipment verification is now the essential control​

C4ADS recommends more resources for BIS and a stronger end-user verification system combining ownership tracing, on-the-ground diligence, and post-shipment checks. That is the report’s central practical conclusion, and it is sounder than calls for another round of product thresholds alone.

For suppliers and enterprise IT organizations handling high-end accelerators, a defensible program needs to examine the customer’s beneficial ownership, physical deployment site, expected workload, resale rights, freight route, and access model. A contract should make audit rights, transfer restrictions, and notification of changes in control operational requirements rather than clauses that disappear after signature. Inventory and serial-number records should be reconcilable to the deployed server and facility, not just the first distributor invoice.

The real exposure is at the handoff between a lawful sale and a downstream transfer that no one verifies. C4ADS’s report shows how much can be reconstructed from public records after the fact. The companies moving AI infrastructure now have less excuse to claim that the warning signs were invisible.