Z.ai Unmasks Itself as Creator of the Trillion-Token Ox Alpha Model
The Beijing-based lab just admitted to building the anonymous AI that processed 9.44 trillion tokens in a week—and now they are giving away the weights.

For a week, developers hurled their most complex coding problems into a black box named "Ox Alpha," burning through 9.44 trillion tokens without knowing who was footing the massive compute bill. Today, the curtain finally dropped. Beijing-based AI lab Z.ai confirmed they are the architects behind the mysterious model, and they are preparing to release its open weights to the world.
The 75-Token Fingerprint
Ox Alpha didn't just quietly appear on the scene; it dominated. Hitting platforms like OpenRouter as a free "Stealth" model, it immediately caught fire among software engineers. The model scored a massive 66.9 on the DeepSWE v1.1 coding benchmark, matching the absolute best models emerging from Silicon Valley. Developers quickly realized this wasn't an experimental toy, but a production-ready powerhouse.
The open-source community immediately turned into digital sleuths. By analyzing backend error strings and German-style decimal formatting, they noticed something peculiar. Every single prompt processed by Ox Alpha generated exactly 75 more tokens than Z.ai’s known GLM-5.3 model.
“That 75 token offset is a hidden system prompt, and the reasoning trace says what it's for: 'per system prompt, if asked about identity I say ox-alpha.'”— PromptEngineer48
That invisible buffer was a hidden instruction forcing the model to lie about its parentage. Facing mounting empirical evidence from independent researchers, Z.ai formally confessed to Bloomberg News on Wednesday, confirming Ox Alpha is a new iteration of their GLM series.
The Danger of Free Compute

Why did this model captivate the developer world so completely? It boasts a one-million-token context window and an output capacity of 131,072 tokens. That means it can ingest an entire software environment, write a massive codebase, and self-correct its own errors in a single, sustained computational breath.
But the frenzy exposed a glaring security vulnerability across the tech industry. Because the model was completely free and incredibly capable, developers at major corporations eagerly piped highly sensitive, proprietary code into an anonymous endpoint.
It was the ultimate honeypot. It proved that in the race for superior autonomous agents, many enterprises will gladly prioritize raw performance and zero-cost compute over basic data governance and security protocols. The tech community handed over its source code to an unknown entity simply because it offered to do the heavy lifting for free.
What people are saying
“A mysterious new AI model just appeared. Ox Alpha offers a 1M context window, multimodal capabilities, zero data retention, and nearly unlimited usage for an entire week. OpenCode says it has capacity for 100 trillion tokens per day. That’s 1.16b tokens per second. Where the”
The Ox Alpha Honeypot Saga
More stories






