READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Anonymous AI Model "Ox Alpha" Tops Benchmarks, and Nobody Will Say Who Built It

Anonymous AI Model "Ox Alpha" Tops Benchmarks, and Nobody Will Say Who Built It
A free, ultra-capable AI model called Ox Alpha showed up on the OpenRouter marketplace on August 20 with no listed owner. Benchmarks put it ahead of some top US models, and speculation points to a Chinese lab, but nothing is confirmed. Meanwhile, separate research shows Chinese state hackers have doubled their attack volume using DeepSeek, a real and identified Chinese model.

An AI model nobody claims to have built just outperformed some of the best systems from OpenAI and Anthropic on coding benchmarks. It's free to use. It's available right now. And as of today, its creator remains unknown.

The model is called Ox Alpha. It appeared on OpenRouter, an AI marketplace, on August 20 as what the platform itself labels a "stealth model," according to The Independent. OpenRouter's own listing says it's "developed and operated by a third-party provider who has chosen to remain anonymous during this preview." No company name, no country, no accountability trail.

What Ox Alpha Actually Does

This isn't a toy. According to Euronews, coding benchmarks like DeepSWE show Ox Alpha performing as well as, or better than, leading models from industry giants. It has a context window exceeding 1 million tokens, can process text, images and video, and can output up to 131,072 tokens in a single response. That's enough to write full-length, complex scripts in one shot.

Euronews reports it's designed for "long-horizon tasks" — sustained coding projects, large-scale data processing, and agentic workflows that run for extended periods without human hand-holding. It's free through August 27, after which OpenRouter says pricing is undetermined.

Stripe CEO Patrick Collison called it "very impressive," according to The Independent. Developers are already building with it. Nobody using it knows who's on the other end.

The Data Question Nobody Can Answer

OpenRouter's site states that prompts fed into Ox Alpha are "retained by the provider" but "not used for training." Both Euronews and The Independent flag the same problem: that claim has not been independently verified by anyone outside the anonymous operator.

Anyone typing proprietary code, business data, or sensitive text into Ox Alpha is trusting an unnamed party's word on data handling. There's no company to sue, no regulator to call, no reputation on the line because there's no name attached.

Who Might Have Built It

Speculation has settled on China, but speculation is all it is. Euronews and IndexBox both report suspicion that Ox Alpha could be linked to Zhipu AI's unreleased GLM-5.x series. The Independent points to a similar theory involving a company called Z.ai, which previously released a model called GLM-5 under a different name before claiming it.

Neither claim is confirmed. What is documented is a pattern: Chinese AI firms including Alibaba and ByteDance have released models before without immediately taking public credit. Euronews notes the possible motives. Dodging export scrutiny, avoiding regulatory attention, or testing high-capacity systems without tying legal liability to a specific corporate entity are plausible incentives, not proof of who built Ox Alpha.

The Separate, Documented Problem: Weaponized AI

While Ox Alpha's origin is guesswork, there's a parallel story that isn't. Chinese state-affiliated hacking groups have more than doubled their attack volume after integrating AI models into their operations, according to Taiwanese cybersecurity firm TeamT5, as reported by Taipei Times and BigGo Finance.

This one has a name attached: DeepSeek. Charles Li, chief analyst at TeamT5, told Bloomberg's Mark Anderson that "DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails." Li said Western models are more sought-after in some respects but require far more effort to bypass their safety restrictions.

TeamT5 identified specific groups, Grimfengxi and Huapi among them, using DeepSeek to generate exploit code and attack targets. Palo Alto Networks' Unit 42 separately documented a DeepSeek-powered autonomous agent campaign that hit more than 460 systems, according to BigGo Finance. Neither DeepSeek nor China's embassy in Washington responded to requests for comment, per Taipei Times.

Notably, researchers say Moonshot's more powerful Kimi K3 model hasn't shown up in hacking campaigns yet, likely because it's too expensive for hacking groups to run at scale. Capability and cost cut both ways here: the strongest models aren't necessarily the ones doing the most damage.

The Bigger Picture, With Actual Numbers Behind It

Hugging Face CEO Clément Delangue told CNBC that China is "clearly dominating on open models right now" and predicted China could dominate at the frontier by the end of this year or next, given the current pace of progress. That's his forecast, not an established fact, and CNBC frames it as a contested claim within the industry.

Daniel Remler of the Center for a New American Security told CNBC that Chinese AI is on track to become the default option in developing countries, which he said could shift political alignment toward Beijing. Keegan McBride of the Tony Blair Institute told CNBC that China has "significant advantages" in robotics, autonomous vehicles and state operations, while also acknowledging the U.S. "currently has the most capable models in the world, strong tech alliances and an overwhelming compute advantage."

Both things are true at once, according to CNBC's sourcing: the U.S. leads on raw frontier capability and chips, while China leads on cheap, widely-adopted open models. U.S. export controls on advanced chips remain a real constraint on China's frontier ambitions, per CNBC.

None of this proves Ox Alpha is Chinese. What it shows is a landscape where anonymous, unaccountable models can appear overnight, get adopted by developers within days, and potentially retain user data with zero independent verification. Separately, a named and identified Chinese model is already documented helping state hackers double their attack output. The mystery model and the confirmed hacking trend are two different stories. The open question for anyone using Ox Alpha before its free preview ends August 27: who exactly is on the other side of that server, and what happens to the data once the free tier goes away.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
EuronewsMysterious, ultra-powerful AI system emerges as China closes in on the West
center-left
The IndependentMysterious, incredibly powerful AI system appears online
center-left
Taipei TimesChina’s hackers are using AI tech to escalate cyberattacks
center-left
CNBCChina is gaining ground in AI. But the U.S. still has a major advantage
unknown
IndexBoxOx Alpha AI Model: Unknown Creator, Top Performance, and China Speculation - News and Statistics
unknown
BigGo FinanceChinese State Hackers Double Attack Volume Using DeepSeek AI, Researchers Say — BigGo Finance