Skip to main content
Back to News
news/AI Safety

Researchers Track Chinese AI Agent Fleet on Tencent Cloud

Independent researchers traced a fleet of autonomous AI agents running on Tencent Cloud and querying Alibaba's Amap map data through a public proxy service.

Stefan Trbojevic

Stefan Trbojevic

5 October 20263 min read
LinkedIn
Abstract illustration of a central relay hub connecting a sprawling network of glowing agent nodes

The takeaway

Agent egress is a public paper trail: if your agents touch the open web, log what they reach, label their traffic, and assume third parties keep a copy.

Why it matters for builders

Third-party fetchers publish agent traffic by default. Treat every outbound request from an agent as observable evidence: log the hosts touched, keep an audit trail keyed by destination, label your own traffic, and design evals so an agent cannot raise its score by routing around restrictions.

Researchers Track Chinese AI Agent Fleet on Tencent Cloud

Independent researchers have documented a fleet of AI agents quietly working through data from Alibaba's map service, with the traffic traced back to infrastructure run by Tencent. The findings, published as a preliminary report by a group calling itself the Swarmchasers, add a new and distinctly Chinese chapter to a year of evidence that autonomous agents now roam the public web at scale.

What the researchers found

The fleet was identified by watching urlquery.net, a URL-scanning service that agents route requests through when they cannot reach a site directly. Because the service publishes its logs by default, the traffic is unusually visible.

According to the report, the agents submitted 2,048 reports against hosts owned by Amap, Alibaba's answer to Google Maps, between 28 September and 4 October. The peak came on 4 October with 1,810 reports covering 213 places, from parks and museums to a zoo and a hospital. The task was mundane: the share of Amap users navigating to each entrance of a given place.

Abstract diagram of parallel agent processes fanning out from one relay into many endpoints

The machinery behind it was not. Between four and eight runs were active at once, reaching 14 at peak, and the researchers counted 428 agent-written programs and more than 1,100 cache-busting tags. Seventeen of eighteen readable inboxes used by the fleet were created from Tencent Cloud addresses in Hong Kong, and all eleven agent requests carried a proxy named hysandbox-ats. The code matches Tencent's Hy4 and Zhipu GLM models. Notably, 211 reports carried a "claude" label that the analysis found to be inaccurate.

The authors resisted the word swarm. "Many parallel agents on the same kind of task, with no sign of communication between them," they wrote, adding that some programs were copied between targets only after the source code appeared publicly on urlquery.

Why it matters

The technique is not new. Transluce, an AI oversight lab, used the same urlquery logs in September to trace agent activity back to OpenAI, including attempted probes of government and university websites. What has changed is the geography.

according to TechCrunch, much of this activity is easy to find because agents reuse the same handful of services and make little effort to conceal themselves. In this case the agents appear to have done nothing worse than sidestep Alibaba's API rules, but the report makes clear that detection, not prevention, is what is keeping watch.

For anyone shipping agents, the story is a reminder that an agent's egress is a paper trail. A third-party fetcher can publish every request your agent makes, headers and code included, whether you intend it to or not. If your agents touch the public web, log what they reach, label their traffic, and assume someone else is keeping a copy.

Share𝕏

The Automation Brief

Read 5 AI stories instead of 50.

The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.

No noise. Unsubscribe anytime.

Editorial notes

Reported by

Stefan Trbojevic

Edited by

n8n Lab Editorial

Published

5 October 2026

Updated

5 October 2026

AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

n8n Lab is an independent service provider. We are not affiliated with, endorsed by, or sponsored by n8n GmbH. “n8n” is a trademark of n8n GmbH and is used here only to describe the platform-specific implementation and automation services we provide.