Ox Alpha Is Free, Powerful and Anonymous. Do Not Feed It Private Code
By Toolbox Ninja · · 5 min read
Ox Alpha offers free, capable AI coding without naming its operator. That bargain is hard to justify when the provider retains prompts and completions.
Ox Alpha Is Free, Powerful and Anonymous. Do Not Feed It Private Code
A new AI coding model showed up last Thursday with an irresistible pitch: strong performance, a huge context window and no token bill. There is just one awkward detail. Nobody outside the companies handling the traffic will say who built or operates it.
OpenRouter lists the model as Ox Alpha, describes it as suitable for long software-engineering jobs and says an unnamed third party runs it. The page advertises a 1,048,576-token context window, support for text, images and video, and a price of zero for both input and output.[1]
That combination was enough to get developers experimenting. The model's Hacker News launch thread drew 250 points and 196 comments, while Business Insider, TechCrunch and Bloomberg all covered the mystery within the next few days.[3][5][6] But the useful story is not the guessing game over which lab made Ox Alpha. It is what happens when a coding tool's best feature, free access, encourages people to overlook where their code is going.
What is known about Ox Alpha
Ox Alpha arrived on OpenRouter on August 20, 2026. The listing calls it a "stealth model" and says OpenRouter only routes requests; it does not develop, own or operate the model. OpenRouter also says one provider hosts it, so requests are not being distributed among a visible set of competing hosts.[1]
The model has already handled serious traffic. OpenRouter's public activity table showed Hermes Agent and Claude Code among its largest users, with token counts measured in the trillions when checked on August 24.[1] OpenCode separately promoted temporary free access and unusually high capacity, according to reporting by Business Insider and SiliconANGLE.[4][5]
The early performance claims need more caution than the excited posts usually give them. SiliconANGLE reported that one developer initially tested only 10 tasks from the DeepSWE software-engineering benchmark and scored Ox Alpha above several named competitors. A later run on the full set put it roughly level with GPT-5.6-sol mid, and no result had appeared on a public leaderboard.[4] Ten cherry-sized tasks can start a conversation. They cannot settle which model is best.
Who built it remains unresolved. Some developers have connected Ox Alpha to Z.ai's GLM family based on tokenizer and infrastructure fingerprints. Other analyses point elsewhere, including Microsoft's MAI family. TechCrunch and Business Insider both describe the evidence as inconclusive, which is the only defensible conclusion for now.[3][5]
The privacy warning is not hidden
OpenRouter puts a notice near the top of the model page: the anonymous provider retains prompts and completions, although it says they are not used for training.[1] That is better disclosure than burying the condition in a long legal document. It still means the provider can keep what users send and what the model returns.
For a casual prompt, that may be an acceptable trade. Coding agents receive much more than casual prompts. They can read source files, configuration, logs, database schemas, issue descriptions and copied terminal output. A developer may carefully avoid pasting a password into chat, then let an agent inspect a repository that contains customer names, internal URLs or a forgotten test credential.
OpenRouter's privacy policy makes the handoff explicit. Inputs are transmitted to the selected model provider, and providers have different retention and training practices. The policy says OpenRouter does not control how language-model providers handle inputs or outputs and advises users to review the provider's own practices.[2] In Ox Alpha's case, the provider has no public name. That makes ordinary due diligence difficult: a user cannot inspect the operator's security record, jurisdiction, deletion process or incident history.
The distinction between "retained" and "used for training" matters. A promise not to train on prompts does not mean the prompts disappear after inference. Retained data may exist for logging, evaluation, abuse monitoring or other permitted uses. Without a named provider and a published retention period, a developer cannot tell how long a copied repository fragment remains available or who can access it.
Free tokens can be expensive
There is nothing inherently improper about a stealth preview. Model makers often test products under temporary names to reduce brand bias and collect cleaner comparisons. The problem begins when a preview model is treated like an approved production service simply because it performs well.
A coding model can produce useful work without receiving an entire private repository. Developers who want to test Ox Alpha can use a public open-source project, synthetic code or a small reproducible example stripped of credentials and business data. They can also disable broad filesystem access, review the exact context sent by the agent, and rotate any secret that slips into a prompt.
Teams need a stricter rule: do not connect an anonymous endpoint to company code unless the organization has deliberately accepted that data path. Existing vendor reviews, data-processing agreements and repository access controls still apply when the API price is zero. In fact, a free preview deserves more scrutiny because cost controls will not slow accidental large-scale use.
The model may eventually be revealed as a familiar vendor with reasonable policies. It may also disappear when the preview ends. Neither outcome changes the decision users face today. Ox Alpha's operator is anonymous, its prompts and completions are retained, and its headline benchmark lead weakened when the test grew larger.[1][4]
Ox Alpha is a good reminder that model quality is only one part of choosing an AI coding tool. Before an agent reads a private codebase, you should know who receives the data, what they keep and which agreement protects you if something goes wrong. Right now, Ox Alpha cannot answer the first question. That is reason enough to keep sensitive code out of it.
Sources
[1] https://openrouter.ai/stealth/ox-alpha — Ox Alpha - OpenRouter [2] https://openrouter.ai/privacy — OpenRouter Privacy Policy [3] https://techcrunch.com/2026/08/23/whos-behind-the-new-stealth-model-ox-alpha — Who's behind the new 'stealth model' Ox Alpha? [4] https://siliconangle.com/2026/08/23/nobody-knows-who-built-ai-coding-model-ox-alpha-or-where-the-code-goes — Nobody knows who built AI coding model Ox Alpha or where the code goes [5] https://www.businessinsider.com/ox-alpha-ai-model-mystery-2026-8 — A mysterious free AI model is impressing developers. And nobody knows who made it. [6] https://news.ycombinator.com/item?id=49381896 — Hacker News discussion: Ox Alpha