
Zhipu AI's Anonymous Ox Alpha Model Exposed as GLM-5.3 Through OpenRouter Serving Forensics
The AMW Read
Serving-layer forensics confirm a known CN player (Zhipu AI) is anonymously distributing a frontier coding model with unresolved prompt-retention terms, a notable distribution and data-handling development though the benchmark claims remain preliminary.
Zhipu AI's Anonymous Ox Alpha Model Exposed as GLM-5.3 Through OpenRouter Serving Forensics
Ox Alpha, a free coding model with a 1,048,576-token context window, appeared on OpenRouter on August 20, 2026 under the generic "Stealth" provider label, offered free for one week via the OpenCode agent and claiming 100 trillion tokens per day of serving capacity. Developer forensics over the next two days converged on Zhipu AI's Z.ai infrastructure as the source: tokenizer fingerprinting across 30 diverse prompts matched GLM-5.3 with a constant 75-token offset, video-encoding behavior matched Zhipu's GLM-5V-Turbo across three independent parameters, and a malformed request triggered a Java stack trace naming Zhipu's internal API package alongside an error-code format identical to Z.ai-hosted GLM models. A community DeepSWE benchmark trial reported an 80% pass rate versus 65% for Claude Fable 5 and 52% for GPT-5.6-Sol on 10 tasks, results the source itself flags as preliminary given the small sample.
The episode shows a leading Chinese lab distributing a frontier-capability model anonymously to gather adoption and benchmark signal before attaching its brand or pricing, sidestepping the scrutiny a named release invites. It also shows the model retaining every submitted prompt under terms its own listing and OpenRouter's governing EULA describe inconsistently, leaving developers with no clear answer on whether their code feeds further training. Stripe CEO Patrick Collison's public "very impressive" comment, notable given Stripe's pending OpenRouter acquisition, spread attention before the provenance question was settled.
Builders routing code through free "Stealth"-labeled listings should treat the label itself as a data-handling risk and confirm training-rights language before sending non-public repositories through OpenCode-style routes. Investors tracking Chinese open-weight labs should treat the unverified 100-trillion-token capacity claim and community benchmark wins as unconfirmed until Zhipu AI acknowledges authorship and clarifies retained-prompt terms.

