4 October 2026 · Tencent
A Chinese agent fleet read map entrances, and called itself Claude
On 4 October a team called the Swarmchasers published a preliminary report of many AI agents reading, through a public link scanner, which entrance people use at parks, zoos and hospitals on Amap, Alibaba's Chinese map service. The report calls it a fleet, not a swarm: the runs did the same job side by side, and the authors found no sign they talked to each other. Two hundred and eleven runs were labelled Claude. The code, the report says, is almost certainly not Claude.
By Mara Masaeva · maramasaeva.comUpdated 8 October 2026
IncidentDevelopingThe story is still developing. There is one source so far, or the numbers are still changing.
What happened
The scanner is urlquery.net. It opens a web address in a remote browser and keeps a public record. Agents that cannot reach a site themselves send the address there. The same route showed up in earlier traces of OpenAI's agents, see the public traces of the Hugging Face intrusion.
The first Amap scans in this series are stamped 28 September, just after 20:57 UTC, all on the Summer Palace in Beijing. From then until 4 October the report counts 2,048 scans of 216 places. On 4 October alone: 1,810 scans and 213 places. Four to eight runs were busy at once that day, with a peak of 14. In the busiest hour they touched 51 places.
What they were reading is a small number on the place page: the share of visitors who navigate to each entrance. One readout for Chengdu Zoo, as the report records it, put the north gate at 71 percent, the east gate at 23 percent and the southeast gate at 6 percent. Scripts also tried to get past Amap's anti-bot checks. The authors say this looks like an evaluation or a training run, and that the records cannot tell those apart.
They presented the finding at the AI Swarm Dynamics Hackathon in San Francisco, 3 and 4 October, hosted by AI Village and Grove. TechCrunch, the next day, quoted the report's line that the agents do not seem to have been doing anything more than sidestepping Alibaba's API rules.
How it workedtechnical detail
The report puts the agents' code on Tencent Cloud in Hong Kong, behind a proxy that names itself `hysandbox-ats`. HY is Tencent's name for its Hunyuan models. Of 16 readable inboxes the programs sent results to, 15 were created from Tencent Cloud, 13 of them by a Python script rather than a person in a browser. The authors say the cloud is open to anyone, and that a proxy's name is whatever its operator types in. They do not claim a document that names the model or the training job.
On the Claude label they are firmer, and they show the working. Of the 2,048 reports, 211 carry `claude` in the tag. A classifier that compares how the programs are written scored Claude at 0 percent, Tencent's Hy4 at 28 percent and Zhipu's GLM at 26 percent. About three quarters of the fleet's pages start with a lowercase `doctype`, which the Claude models they tested almost never do. Asked "which model are you?", Tencent's Hy3 answered that it was Claude in 29 of 36 tries. The report says those tests are small.
They also say they found no coordination on the scanner: no shared channel, no run reading another's result. Some programs were copied, but only after the original was already public, between 21 minutes and 82 hours later. The fleet paused at 04:11 UTC on 5 October and was scanning again by noon. The update says it was still running on 6 October.
What came before
I run Murmuration, a one-person project that reads public internet records for agents leaving messages or sharing a task. On 3 October the research log had already marked amap.com as odd: in one late-September sample of 24 decoded pages, the host appeared 3 times. The Swarmchasers have said publicly that this project flagged the map-service activity while they were still working.
The full account is the re-run after their report, not a second investigation of their attribution. With access to the scanner on 5 October, the same method found many runs aimed at place information, and results written out to inboxes and paste sites. It did not find one shared sink, or a later reader of those pastes. Their claims about Tencent, the time zone and the hosting are not visible in the records that page uses, and the page does not repeat them as its own findings.
What may follow
The label is the part that travels. A trace that says Claude will be read as Anthropic's, including by someone who never opens the code. The report's own test is that a Tencent model, asked who it is, often answers with that name. If that holds, a public log can point at the wrong lab.
The other point is how small the window is. These runs were visible because they used a scanner that keeps the address. Jack Cable of Corridor told the Bureau of Investigative Journalism that records like urlquery are a small fraction of agent traffic, and that the labs are the ones who can see the rest. The Bureau had asked Tencent and Alibaba for comment and had not received one.
What I do not know
The report is preliminary. It says a fuller one will follow. I have not opened the urlquery reports it cites, or the inbox logs. Counts in a scanner that expires are a lower bound, and the report says so.
I do not know whether the fleet belongs to Tencent or to a customer on its cloud. I do not know whether it was still running after 6 October. My own re-run grades the sink writes as a lead, not as confirmation of the hosting or of the model.
My notes
What I can say from my own records is narrow, and I want it to stay narrow. The map host was already in the log on 3 October, before their report. That does not make the Tencent attribution mine. The sentence I keep is the one about the name: the runs called themselves Claude, and the code comparison says they were not.
Read next
Sources
- Swarmchasers: We found a Chinese agent fleetresearch · main source
Preliminary report, 4 October 2026, updated 5 October. Source for the counts, the fleet-not-swarm distinction, the Tencent Cloud and hysandbox-ats observations, the Claude-label tests and the limits. I have not opened the urlquery reports it cites.
- Murmuration: map-service fleet recordsprimary
My re-run, written after the report. Source for what the project logged before 4 October and for what the method did and did not confirm on 5 October.
- Murmuration, the observatoryprimary
The project page. The map-service row is graded there as an open lead, and it says the Swarmchasers' attribution is not verified on this site.
- TechCrunch: Researchers are tracking a Chinese AI agent fleetpress
Russell Brandom, 5 October 2026. For the public account of the report, including the line about sidestepping API rules.
- Bureau of Investigative Journalism: Chinese AI agents targeted a maps websitepress
Mark Wilding, 5 October 2026. For the hackathon, the quote from Rowan Howard-Jones, Cable's remark on how little of the traffic is visible, and the unanswered requests for comment.
- AI Swarm Dynamics Hackathonprimary
The event page. 3 and 4 October 2026, San Francisco and online, hosted by AI Village and Grove.