Nobody Claimed Ox Alpha, So Its Impersonators Went Unchallenged

|

|

Reddit logo
A screenshot displaying Netcraft's newly updated dashboard with a cleaner user experience.

Ox Alpha, the miracle mystery model 

On Aug. 20, 2026, an unnamed developer launched Ox Alpha on OpenRouter under the platform's stealth release policy, which lets developers remain anonymous while OpenRouter routes API requests to the underlying model provider. Within days, Ox Alpha became one of OpenRouter's most popular models, peaking at more than 5 trillion tokens processed in a single day. The model also became available through OpenCode, an open-source coding agent. 

Tokens processed by Ox Alpha during its stealth phase, according to OpenRouter. August 2026 is considered incomplete due to Z.ai’s announcement and free access being cut off before the end of the day. 

Though released as a stealth project, many suspected that this was going to be announced as a GLM model by Z.ai, a theory confirmed by an announcement made through Bloomberg on the 26th. This is not the first time that Z.ai has tested alpha models this way. In February of this year, Z.ai announced through OpenRouter that a model called Pony Alpha was a stealth release of GLM-5. Other Chinese AI companies have also used stealth releases through OpenRouter to introduce their own models, such as with Xiaomi’s MiMo-V2-Pro and Meituan’s LongCat-2.0. While this has allowed widespread testing, stealth releases can create opportunities for threat actors to monetize the service and get access to user data by posing as the developers.  

While the model became available at no cost through OpenRouter’s API and OpenCode’s gateway, there was no official web interface to query the model otherwise. This allowed attackers to create chat-based web interfaces for Ox Alpha that could look like they were from the actual developer. Within a week of the release, web interfaces for the model with no apparent link to Z.ai started to appear. The developer had not created an identity that could be checked against or defended. 

Chat interface from oxalpha[.]com. 

An unclaimed identity is an exploitable identity 

Between Ox Alpha’s release on Aug. 20 and Z.ai’s claim on Aug. 26, 2026, Netcraft observed 80 new domains registered which contain “oxalpha” or “ox-alpha” with extraneous results removed. 

Some of these domains, such as in the example below, became the first item returned when searching for Ox Alpha. They could appear as legitimate, even copying text from the model’s description on OpenRouter. Since Ox Alpha was a model focused on code development, imitation of it could be used to target large intellectual property bases and reveal exploitable information from pre-release code. One example even suggested that users could "Paste an entire codebase, a 500-page spec, or a week of transcripts." These interfaces allowed their owners to sit between users and the freely available model, passing their queries as API requests but also being able to intercept any information given.  

On Aug. 26, 2026, before Z.ai claimed credit for the model, Google’s first result was oxalpha[.]com, a wrapper for the service. 

Text from oxalpha[.]com 

Wrappers could be used to capitalize on the free model in addition to intercepting data from requests, as seen here with stealthoxalpha[.]ru. 

Following the announcement of Ox Alpha as GLM-5.3-Flash, the OpenRouter API service through the stealth listing became unavailable and wrappers stopped functioning. This strongly supports the assessment that these services had no connection to the model’s developer.  

This chat, using an example prompt from oxalpha[.]com, returned a 404 error shortly after Ox Alpha’s developer was revealed. At time of writing, this chat wrapper is functional again. 

The service disruption at the announcement of Ox Alpha's identity exposed how these wrapper services operated. Because they experienced the same outages and degradation as free API users, the evidence suggests they relied on relayed traffic from the underlying model instead of their own inference infrastructure. 

The use of stealth mode for releasing this model meant that, during the time that GLM‑5.3‑Flash was only known as Ox Alpha, there was no known rights holder to request a takedown of imitator infrastructure without deanonymizing themselves. While anonymous, there was no way that legitimate ownership of these sites could be proven or disproven. Fast-paced model releases have already created new challenges in supply chain security. If stealth releases become more normalized, the opacity of developer identity could exacerbate this challenge. 

What happens when your supplier is anonymous 

This model’s stealth release contributed to impersonation of its developer by making it impossible to verify identity. Supply chain security already suffers from incomplete information, but the lack of any verifiable identity can have a greater and less predictable impact on this risk.  

Good security practice in this case would be to test but not trust any stealth model. These are powerful models but their ability to ingest a codebase does not show their responsibility to securely store and process it.  

Unattributed models should be treated like any other unattributed dependency. Testing may be done in a controlled manner, but codebases should remain in trusted environments. And any other service claiming to give easier access to this tool before its creator is known should be treated as an unknown third party, regardless of any claim to be related to the developer.  

Don't want to miss out on updates?

Don't want to miss out on updates?

Don't want to miss out on updates?

Join our mailing list for regular blog posts and case studies from Netcraft.