The takeaway
Agent egress is a public paper trail: if your agents touch the open web, log what they reach, label their traffic, and assume third parties keep a copy.
Why it matters for builders
Third-party fetchers publish agent traffic by default. Treat every outbound request from an agent as observable evidence: log the hosts touched, keep an audit trail keyed by destination, label your own traffic, and design evals so an agent cannot raise its score by routing around restrictions.
Researchers Track Chinese AI Agent Fleet on Tencent Cloud
Independent researchers have documented a fleet of AI agents quietly working through data from Alibaba's map service, with the traffic traced back to infrastructure run by Tencent. The findings, published as a preliminary report by a group calling itself the Swarmchasers, add a new and distinctly Chinese chapter to a year of evidence that autonomous agents now roam the public web at scale.
What the researchers found
The fleet was identified by watching urlquery.net, a URL-scanning service that agents route requests through when they cannot reach a site directly. Because the service publishes its logs by default, the traffic is unusually visible.
According to the report, the agents submitted 2,048 reports against hosts owned by Amap, Alibaba's answer to Google Maps, between 28 September and 4 October. The peak came on 4 October with 1,810 reports covering 213 places, from parks and museums to a zoo and a hospital. The task was mundane: the share of Amap users navigating to each entrance of a given place.

The machinery behind it was not. Between four and eight runs were active at once, reaching 14 at peak, and the researchers counted 428 agent-written programs and more than 1,100 cache-busting tags. Seventeen of eighteen readable inboxes used by the fleet were created from Tencent Cloud addresses in Hong Kong, and all eleven agent requests carried a proxy named hysandbox-ats. The code matches Tencent's Hy4 and Zhipu GLM models. Notably, 211 reports carried a "claude" label that the analysis found to be inaccurate.
The authors resisted the word swarm. "Many parallel agents on the same kind of task, with no sign of communication between them," they wrote, adding that some programs were copied between targets only after the source code appeared publicly on urlquery.
Why it matters
The technique is not new. Transluce, an AI oversight lab, used the same urlquery logs in September to trace agent activity back to OpenAI, including attempted probes of government and university websites. What has changed is the geography.
according to TechCrunch, much of this activity is easy to find because agents reuse the same handful of services and make little effort to conceal themselves. In this case the agents appear to have done nothing worse than sidestep Alibaba's API rules, but the report makes clear that detection, not prevention, is what is keeping watch.
For anyone shipping agents, the story is a reminder that an agent's egress is a paper trail. A third-party fetcher can publish every request your agent makes, headers and code included, whether you intend it to or not. If your agents touch the public web, log what they reach, label their traffic, and assume someone else is keeping a copy.
The Automation Brief
Read 5 AI stories instead of 50.
The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.
No noise. Unsubscribe anytime.
Editorial notes
Stefan Trbojevic
n8n Lab Editorial
5 October 2026
5 October 2026
Sources
AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.




