Ox Alpha’s real mystery isn’t who built it
The New Stack Janakiram MSV ● Covered by 3 sources
Ox Alpha showed up anonymous on OpenRouter, and developers rushed to guess the maker. The bigger issue is what happens to private code sent through a free preview with unclear data terms.
Based on reporting by The New Stack, Janakiram MSV — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Everybody wants to know who built Ox Alpha. That’s the flashy mystery. The more practical one is uglier: once a developer sends private code to an anonymous model, who gets to keep it, and under what terms?
Ox Alpha arrived on OpenRouter on August 20 with no named provider. OpenCode, the open-source terminal agent, launched support for it the same day and said it could handle 100 trillion tokens a day. OpenRouter labels it a reasoning model for long-horizon software work, gives it a 1,048,576-token context window, and lists both input and output pricing at 0 for the preview. The identity hunt has since turned into a small internet detective show, complete with tokenizer tests, benchmark screenshots, and a rotating suspect list.
One of the more serious probes came from unclecode, the developer behind Crawl4AI, who built modelprint to fingerprint anonymous API endpoints. His launch version ran nine infrastructure checks and found Ox Alpha matched GLM-5.3 on six of them. That’s suggestive, not decisive. His own documentation says matching fingerprints point to shared infrastructure, not necessarily the same model. Z.ai looks like the leading candidate anyway: it reportedly previewed GLM-5 on OpenRouter as Pony Alpha, and it announced GLM-5.3 six days before Ox Alpha appeared. Xiaomi’s MiMo team has also been floated, and one reading of the tokenizer behavior points instead at cl100k_base, which is an OpenAI encoding and an odd fit for a Chinese model.
The benchmark chatter is even messier. Ben Davis posted an 80% score across 10 DeepSWE tasks on X, but he noted the sample was small. A later run on GitHub covered 113 tasks, solved 66, and took 20 hours of agentic work. That one can be reproduced; the viral screenshot cannot. The official DeepSWE leaderboard does not list Ox Alpha at all.
This is where the story stops being about branding and starts being about risk. Ox Alpha’s model page says the provider keeps prompts and completions and does not use them for training. OpenRouter’s broader Stealth Program terms, which cover everything else, describe a license that is irrevocable and perpetual, and the incorporated EULA says submitted content is used for training and improvement. OpenCode says its Zen providers are zero-retention and no-training, but Ox Alpha is not listed among its exceptions. Those are very different privacy promises.
And the volume matters. Coding agents have pushed billions of tokens through Ox Alpha since Thursday, and that can include repository contents, test logs, environment output, and screenshots from private production systems. If the Z.ai theory is right, there’s also a procurement wrinkle: the Commerce Department added Zhipu AI, its former name, to the Entity List in January 2025. That doesn’t make ordinary API traffic illegal, but it does put the vendor in a category many enterprise teams already screen for. The name reveal may come later. The data exposure has already started.
My take — AI-written commentary, not fact-checked reporting
Anonymous model launches are a neat trick right up until someone feeds them a private repository and assumes the fine print is decorative. The industry keeps acting like provenance is the mystery, when the real product is usually a privacy promise held together with duct tape and optimistic reading. That’s not innovation; that’s procurement with a mask on.
Read more about this at: The New Stack