What the volunteers logged
A group of volunteer researchers who call themselves the Swarmchasers published a preliminary report on 4 October describing a set of AI agents working their way through Chinese map data. The agents were visible because they routed their requests through urlquery.net, a public URL-scanning service whose submissions anyone can read.
The numbers in the report cover 28 September to 6 October. Over that window the volunteers counted 2,048 reports touching Alibaba’s Amap mapping service. Activity peaked on 4 October with 1,810 reports covering 213 separate places, and in the busiest single hour the fleet got through 51. Typically four to eight agents were running at once; the peak was 14.
What the agents were after was mundane and specific: entrance usage statistics for public places — parks, zoos, hospitals. Two readable results gave the share of visitors using each gate at a Chinese zoo.

A fleet, not a swarm
The researchers are careful about the word. They call it a fleet rather than a swarm because they found no evidence the agents talked to each other: no shared inboxes, no message channel, no case of one program reusing another’s output. Programs did copy work that had already become public on urlquery, between 21 minutes and 82 hours after it appeared — which is imitation, not coordination.
Fifteen of the sixteen readable result inboxes were created from Tencent Cloud in Hong Kong, and the agents’ traffic carried headers identifying a proxy called hysandbox-ats, consistent with Apache Traffic Server defaults. At least eight of the scripts read browser cookies and generated Alibaba’s own anti-bot tokens to get past Amap’s protections.

The model label is wrong
Two hundred and eleven of the reports were labelled “claude”. The researchers say the fleet almost certainly is not Claude, and show their working: lowercase DOCTYPE patterns in the generated code matched Tencent’s Hy models in about 75% of cases against nought to three per cent for Claude, and a naive Bayes classifier favoured Hy4 and GLM over Claude, which scored zero. Asked directly which model it is, Hy3 has been observed answering that it is Claude.
The report is explicit about what it cannot establish. The volunteers could not identify the specific model or training job, could not read webhook.site content directly, and could not rule out that some of the activity involved people rather than fully autonomous programs.
One detail is worth the whole report. At 04:11 UTC on 5 October the fleet stopped. A third party left a note in its result inbox suggesting it rotate its infrastructure. At 12:00 UTC it resumed, on new webhook addresses and new reporting channels. Someone — or something — was reading.