Illustration for: Researchers Spot A Chinese AI 'Agent Fleet' At Work

Researchers Spot A Chinese AI 'Agent Fleet' At Work

Independent researchers tracked a fleet of AI agents running on Tencent's cloud that spent a week querying Alibaba's Amap for building-entrance data at 213 places across China.

By the Numbers

213 locations
Places scanned
1,810
Total reports logged
14
Peak concurrent instances
Sep 28 - Oct 5
Scan window
428
Programs generated
TC
Early-stage VC & angel · Founder, New York Venture Partners · Value Add Pulse AI Desk
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

The fleet ran undetected against Alibaba's own anti-bot defenses for a full week, discovered only by independent researchers monitoring a third-party sandboxing tool -- not by Alibaba's own security team, a gap worth noting for any company relying on in-house bot detection.

2

Researchers' correction of a 'claude' mislabeling in the agents' outputs -- the actual patterns point to Tencent's Hunyuan and Zhipu's GLM models -- matters because misattributed AI activity can wrongly implicate specific labs in incidents they had no part in.

3

This lands in the same month Perplexity is fighting Amazon in the Ninth Circuit over its Comet agent's right to browse Amazon's site -- agentic scraping of platforms that didn't invite it is becoming one of 2026's defining legal fights, not just a security curiosity.

4

213 locations scanned for entrance-level detail is as consistent with a legitimate logistics or accessibility-mapping use case as with anything adversarial -- researchers themselves stopped short of assigning intent, a useful reminder not to over-read a security finding into a geopolitical one.

TC

The VC Read · Trace's Take

Trace Cohen

The diligence point for anyone building a consumer platform that leans on anti-scraping as a moat: Amap's bot-detection tokens were bypassed with techniques that were already public, which means your defense is only as good as the least-disciplined agent framework out there. Watch whether Alibaba patches the specific routing trick or just rate-limits the symptom -- that tells you whether this gets fixed or just repeats in three months.

Analysis

Independent security researchers at Swarmchasers spent a week tracking a fleet of AI agents running on Tencent's cloud infrastructure that repeatedly queried Alibaba's mapping service, Amap, for building-entrance data at 213 locations across China, according to TechCrunch. The agents wanted to know specifically where people enter parks, museums, zoos and hospitals -- not just where those places are, which Amap already shows publicly.

A Fleet, Not A Swarm

The scanning began September 28, peaked October 4 with 1,810 reports across the full set of locations, and went quiet shortly after 4:11am UTC on October 5 -- at its busiest, 14 agent instances ran in parallel, generating 428 distinct programs along the way. Researchers deliberately avoided calling it a 'swarm,' noting little evidence of coordination between the individual queries: it looks like many parallel agents independently assigned the same kind of task, not one orchestrated operation.

“What's missing from the 'Chinese AI agent fleet' framing: nobody has established who commissioned this, or why.”

Swarmchasers found the activity by monitoring traffic to urlquery.net, a domain-scanning sandbox that AI agents commonly route through when they can't load a target website directly -- the same technique leaves a record researchers can later reconstruct, as a separate writeup of the findings also confirmed. One detail worth getting right: 211 of the agents' outputs carried a 'claude' label, but Swarmchasers said the actual code and response patterns lined up more closely with Tencent's own Hunyuan models (versions referred to as Hy3 and Hy4) and Zhipu's GLM -- meaning the label was most likely spoofed or misconfigured, not evidence the fleet was actually built on Anthropic's models.

Agents scraping services they don't have a commercial relationship with is already a live legal fight in the US: Perplexity is currently defending its Comet browser agent in the Ninth Circuit against Amazon's objections over exactly this kind of automated access to a platform that didn't invite it. Amap's anti-bot tokens were reportedly bypassed using techniques already public from earlier security disclosures, which is the uncomfortable part for any company relying on bot-detection as its main defense against scraping: once a bypass is public, it's available to everyone's agents, not just the first one that found it.

What's missing from the 'Chinese AI agent fleet' framing: nobody has established who commissioned this, or why. Entrance-level data at parks, museums and hospitals is exactly the kind of detail a logistics, delivery, or accessibility-mapping product would want -- it doesn't require a sinister explanation, and researchers themselves stopped short of one. The genuinely new finding isn't that an agent fleet exists; it's that it operated undetected against a major platform's defenses for a week before anyone outside Swarmchasers noticed.

For founders building anything that depends on scraping-resistance as a moat, the real number here isn't 213 locations -- it's one week of undetected operation against one of China's largest map platforms before independent researchers, not Alibaba itself, caught it.

ShareXLinkedInEmail

Key Sources

2 sources

Reported by TechCrunch · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take, a few times a week. Free to subscribe, no spam.