[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-ox-alpha-stealth-eula-retention-conflict":3,"news-related-a64d03b9-1d07-404b-9231-d434c65c44ce":38},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":24,"news_slug":31,"published_at":32,"created_at":33,"modified_at":34,"is_published":35,"publish_type":36,"image_url":14,"view_count":37},"a64d03b9-1d07-404b-9231-d434c65c44ce","OX Alpha 免费一周:模型页说不训练,EULA 却保留训练权","匿名模型 OX Alpha 在 OpenRouter 免费开放一周,模型页承诺保留数据但不用于训练,平台 EULA 却授予训练使用权,两条路由政策还不一致。指纹证据指向智谱,条款冲突悬而未决。","一个没有公司名、没有新闻稿、没有 logo 的模型,8 月 20 日悄悄出现在 OpenRouter 的目录里,代号 `stealth\u002Fox-alpha`。它免费开放一周(到 8 月 27 日前后),提供 1,048,576 token 的上下文窗口,支持文本、图像、视频输入,最大输出 131,072 token,还带函数调用和结构化 JSON 输出——匿名提供方声称自己有每天 100 万亿 token 的服务容量。开发者蜂拥而至,但很多人没细看的一行字是:你的每一条 prompt 和补全,都会被提供方**保留**。([TechTimes 报道](https:\u002F\u002Fwww.techtimes.com\u002Farticles\u002F325244\u002F20260823\u002Fcoding-model-ox-alpha-retains-every-prompt-you-cannot-name-company-holding-them.htm))\n\n## 免费的代价,藏在两份打架的条款里\n\n模型页上写得看似安心:prompts 和 completions 被\"保留但不用于训练\"。但管辖所有 stealth 模型的 OpenRouter Stealth Model EULA 是另一套说法——它授予 OpenRouter 和匿名提供方将用户内容用于训练、评估和改进的权利,并明确说:不想要这种用法的用户,请直接不要访问 stealth 模型;输入中的个人数据会被发送给提供方。平台没有公布任何材料解释这两份文件如何调和,TechTimes 的结论是:通过 OpenRouter 直连端点发送的任何 prompt,其训练权问题**没有被干净地解决**。\n\n更微妙的是,同一个模型有两条路由、两套政策:OpenCode 平台上的 Ox Alpha 路由标注零保留、不用于训练——但那同样是一个身份和司法辖区都未知的匿名提供方。同一个模型,换一条入口,数据政策就变了,这对任何打算往里喂敏感代码的团队都应该是红灯。\n\n## 指纹侦探:三天锁定疑似幕后\n\n社区在几小时内就开始了取证。到 8 月 22 日,证据链已经从猜测升级到服务层证据:研究者对 Ox Alpha 跑了 30 条覆盖 14 种文字系统的探针,token 计数与 GLM-5.3 全部匹配,每条请求固定多出 75 个 token——那是系统提示词或路由包装的痕迹;视频编码器的 token 消耗模式与智谱自家的 GLM-5V-Turbo 在三个独立设计选择上同时吻合(约每秒 147 token、帧率无关采样);有人故意发一个格式错误的请求,服务器抛出的 Java 堆栈直接暴露了内部类名,该包路径映射到智谱 open.bigmodel.cn \u002F api.z.ai 的 API 路由;错误码方言也对得上 Z.ai。研究者的运营层置信度给到 0.98——但智谱和 OpenRouter至今都没有官方确认,严谨的说法仍然是\"最可信的理论,而非定论\"。([AgentBreaking 复盘](https:\u002F\u002Fagentbreaking.com\u002Fblog\u002Fox-alpha-stealth-model-openrouter\u002F))\n\n这也不是第一次。TechTimes 统计这是 OpenRouter 六个月内的第五个 stealth 模型,前四个(GLM-5、小米 MiMo-V2-Pro、蚂蚁 Lingxi Ling-2.6-flash、美团 LongCat-2.0)最终都被开发方认领。匿名发布让模型在被测时摆脱品牌偏见,实验室换来真实世界压力测试数据和官宣时现成的用户盘——\"免费换数据\"这门生意的账,算得很清楚。\n\n## 跑分很香,样本很小\n\n开发者 Ben Davis 在 DeepSWE(真实软件工程任务评测)上测出 10 题过 8、80% 通过率,同一组任务 Claude Fable 5 是 65%、GPT-5.6-Sol 是 52%。但这是单人跑的 10 任务小样本,不是审计过的榜单——10 题规模下一道题就能撬动 10 个百分点。另一边 Day.dev 的 Kingbench 测试里 Ox Alpha 是 87.5%,反而落后 GLM-5.3 的 91.25%。OpenRouter 监控显示上线约 24 小时处理了超 1600 亿 token,头部消费者是 Claude Code、Hermes Agent 这类 agent 工具,缓存命中率 73.5%——代理式编码工作流显然是它的主场。\n\n## 所以呢\n\n对非敏感输入做能力评估,这个免费窗口是难得的机会;但把私有代码库整个塞进一个 1M 窗口之前,先回答一个问题:你愿意把代码发给一个无法具名的第三方,且训练权条款自相矛盾、司法辖区未知的端点吗?多数企业安全政策的答案,在数据出门之前就写好了。免费的模型不收费,但你的 prompt 就是价格。","https:\u002F\u002Fwww.techtimes.com\u002Farticles\u002F325244\u002F20260823\u002Fcoding-model-ox-alpha-retains-every-prompt-you-cannot-name-company-holding-them.htm","4f2dc39f-0b6a-48e6-ad47-da9c3c15cbea",[11,15,18,21],{"id":12,"name":13,"slug":13,"description":14,"color":14},"c33b1bbc-d6ce-4f61-9d5d-1a0704a6a09b","ai-policy",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"a8002d98-9df1-4ab9-94d4-a7625af634c4","china-ai",{"id":19,"name":20,"slug":20,"description":14,"color":14},"e82b2d09-81b2-43d1-977e-e018443b3c14","coding-agent",{"id":22,"name":23,"slug":23,"description":14,"color":14},"01598627-1ea6-4b27-a5d8-874971571a71","llm",[25],{"id":26,"lang":27,"title":28,"summary":29,"content":30},"9b95ab92-e451-4e5c-a993-92a569cdb520","en","Ox Alpha Free Week: Model Page Says No Training, EULA Disagrees","The anonymous model OX Alpha is free on OpenRouter for a week with a 1M-token context. Its model page says prompts are retained but never used for training, while the platform's Stealth Model EULA grants training rights, and the OpenCode route claims zero retention. Forensics point to Zhipu; the terms conflict is unresolved.","A model with no company name, no press release, and no logo quietly appeared in OpenRouter's catalog on August 20, listed as `stealth\u002Fox-alpha`. It is free for about a week (through around August 27), offers a 1,048,576-token context window, accepts text, image, and video input, with a 131,072-token max output plus function calling and structured JSON output — and the anonymous provider claims a capacity of 100 trillion tokens per day. Developers rushed in, but the line many skipped: every prompt and completion you send is **retained** by the provider. ([TechTimes report](https:\u002F\u002Fwww.techtimes.com\u002Farticles\u002F325244\u002F20260823\u002Fcoding-model-ox-alpha-retains-every-prompt-you-cannot-name-company-holding-them.htm))\n\n## The Price of \"Free\" Sits in Two Conflicting Documents\n\nThe model page reads reassuringly: prompts and completions are \"retained but not used for training.\" But the OpenRouter Stealth Model EULA — which governs all stealth models including this one — tells a different story. It grants OpenRouter and the unnamed provider the right to use user content for training, evaluation, and improvement, instructs users who do not want that use to refrain from accessing stealth models, and specifies that personal data in an input will be sent to the provider. No published material explains how the two documents are reconciled, and TechTimes' conclusion is blunt: for any prompt routed through OpenRouter's direct endpoint, the training-rights question is **not cleanly settled**.\n\nIt gets subtler: the same model has two routes with two policies. The OpenCode route for Ox Alpha is listed with zero retention and no training use — but that applies to the same anonymous provider whose identity and legal jurisdiction remain unknown. One model, two entrances, two data policies. For any team thinking of feeding sensitive code into that million-token window, that mismatch should be a red light.\n\n## Fingerprint Detectives: Three Days to a Likely Suspect\n\nThe community started forensics within hours. By August 22, the evidence had escalated from speculation to serving-layer proof. Researchers ran 30 probe strings across 14 writing systems through Ox Alpha; every token count matched GLM-5.3, with a constant 75-token offset on each request — the signature of an invisible system prompt or routing wrapper. The video encoder's token consumption matched GLM-5V-Turbo — Zhipu's own multimodal agent model — on three independent design choices simultaneously (roughly 147 tokens per second, FPS-invariant sampling). Someone sent a deliberately malformed request; the server threw a Java stack trace exposing an internal class name whose package path maps to Zhipu's documented API routes at open.bigmodel.cn and api.z.ai. The error-code dialect matched Z.ai's operator stack too. The researcher's operator-layer confidence: 0.98. But neither Zhipu nor OpenRouter has officially confirmed anything — the rigorous phrasing remains \"the strongest theory, not a verdict.\" ([AgentBreaking rundown](https:\u002F\u002Fagentbreaking.com\u002Fblog\u002Fox-alpha-stealth-model-openrouter\u002F))\n\nNor is this the first time. Per TechTimes' count, this is the fifth stealth model on OpenRouter in six months; the previous four (GLM-5, Xiaomi's MiMo-V2-Pro, Ant Group's Lingxi Ling-2.6-flash, Meituan's LongCat-2.0) were all eventually claimed by their developers. Anonymous launches let a model be tested without brand bias, and the lab gets real-world stress-test data plus a ready user base for the official reveal. The economics of \"free inference for usage data\" are well understood on both sides of the trade.\n\n## Impressive Scores, Tiny Sample\n\nDeveloper Ben Davis ran Ox Alpha on DeepSWE — an evaluation built on real software engineering tasks — and reported 8 of 10 tasks passed, an 80% rate, against 65% for Claude Fable 5 and 52% for GPT-5.6-Sol on the same set. But this is a single-developer, 10-task trial, not an audited leaderboard: at that scale, one task swings the pass rate by 10 percentage points. Meanwhile Day.dev's Kingbench run put Ox Alpha at 87.5% — behind GLM-5.3's 91.25%. OpenRouter monitoring shows more than 160 billion tokens processed in roughly the first 24 hours, with Claude Code, Hermes Agent, and similar agent tools as top consumers, and a 73.5% cache hit rate — agentic coding workflows are clearly its home turf.\n\n## So What\n\nFor capability assessment on non-sensitive inputs, this free window is a genuine opportunity. But before you load an entire private codebase into a 1M-token window, answer one question first: would you knowingly send your code to an unnameable third party whose training-rights terms contradict each other and whose jurisdiction is unknown? Most enterprise security policies have the answer written before the data leaves the building. The model is free; your prompts are the price.","ox-alpha-stealth-eula-retention-conflict","2026-08-23T13:10:00Z","2026-08-23T13:09:23.481105Z","2026-08-23T13:09:23.481115Z",true,"agent",67,{"items":39},[40,45,50,55,60,65],{"id":41,"title":42,"news_slug":43,"published_at":44},"1b1ecd4c-0439-4734-ac5b-b038172da8b1","Apache 比 MIT 多 37%:HF 报告拆出中美开源权重的「许可证分岔」","open-llm-licensing-divergence-hf-2026","2026-08-19T03:00:00+00:00",{"id":46,"title":47,"news_slug":48,"published_at":49},"49d0aaf8-6fcf-4bf9-83fb-19a016ae2784","CompactionRL:把上下文压缩塞进 RL 循环,GLM-5.2 训练管线吃下 5–7pp 编码代理增益","compactionrl-glm-5-2","2026-07-10T12:08:00+00:00",{"id":51,"title":52,"news_slug":53,"published_at":54},"fa8a0c53-dd89-4870-8e6e-978ce038a919","GitHub Copilot 上线 Kimi K2.7：开源权重模型首次进入默认模型选择器","github-copilot-kimi-k2-7","2026-07-03T06:00:00+00:00",{"id":56,"title":57,"news_slug":58,"published_at":59},"6ba58314-305f-4255-83c5-87bdd1123b49","字节 Seed 2.1 押注「Agent-first」：模型自己参与训练，多模态重夺 SOTA","bytedance-seed-2-1-agent-first","2026-06-27T15:30:00+00:00",{"id":61,"title":62,"news_slug":63,"published_at":64},"e6874e20-f0ac-40a3-a8b4-f534df6296f9","谭待把豆包 2.1 Pro 定位为「上桌」：Terminal Bench 跑平 Claude Opus 4.7，字节系模型矩阵开始咬合","doubao-2-1-pro-tan-dai-terminal-bench-opus","2026-06-24T01:00:00+00:00",{"id":66,"title":67,"news_slug":68,"published_at":69},"c40263bb-c193-46e8-ba63-76499bb1c2af","豆包 2.1 Pro 抢跑 Agent 时代：180T 日均 token 背后的 MaaS 规模战","doubao-2-1-pro-180t-tokens-maas","2026-06-23T04:30:00+00:00"]