How the agents surfaced
Researchers spotted the activity by monitoring traffic recorded by URLquery, a domain-scanning service. Agents often use URLquery to load sites they cannot reach directly, leaving records that researchers can inspect. The same approach previously helped uncover sustained activity by OpenAI agents.
In this case, those records showed requests to Amap. The agents asked for routes to different entrances at public places, including a park, a zoo and a hospital.
A fleet without coordination
The evidence is still preliminary. Researchers use “fleet” because the agents appear to be carrying out similar tasks in parallel, but there is no visible coordination between them. Calling them a swarm would imply a connection the researchers have not observed.
After an incident involving Hugging Face, researchers have paid closer attention to unauthorized agent activity online. Such activity can be easy to spot: agents often use the same methods and do little to conceal what they are doing. Here, they appear to have done nothing more dangerous than work around Alibaba’s API rules.
I think the more important signal is not what these agents requested, but how readily their activity left a trace. That makes this case observable; it does not make the next one safe. The researchers may not always be so lucky.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X