AI DevelopmentMethodology18 min readPublished August 22, 2026

14 listings · 7 officially revealed · 4 reported only · 2 unresolved · 1 open · data as of August 22, 2026

OpenRouter Stealth Models: Who They Turned Out to Be

Every stealth listing OpenRouter has run since April 2025, in one dated table: listing name and slug, listing date, what it turned out to be, who revealed it and when, the evidence tier behind each identity, the data terms at listing, whether it was free, and its context length. Thirteen historical rows plus Ox Alpha, the fourteenth, which was still open on the as-of date. Rows where no identity was ever confirmed stay in the table and say so.

DA
Digital Applied Team
Senior strategists · Published Aug 22, 2026
PublishedAug 22, 2026
Read time18 min
Sources27 cited links
Stealth listings since Apr 2025
14
13 historical + Ox Alpha
Officially revealed
7/13
first-party statement on record
Never resolved
2/13
Cypher Alpha · Aurora Alpha
No-training carve-out
1/14
Ox Alpha only · ‘this time’

OpenRouter stealth models are anonymous, usually free listings that a lab runs for a week or two under a codename before the real model ships. Fourteen of them have appeared since April 2025. This page is a census of all fourteen: what each one was called, when it listed, what it turned out to be, who said so, and how strong the evidence behind that identity actually is.

The census exists because the question that matters about a stealth listing is not “what is it” but “will we ever find out.” The answer is a base rate, and the base rate can only be read off a complete, dated list. That list did not exist in one place: the rows are scattered across OpenRouter’s blog, its retired model pages, two labs’ own announcement channels, and a handful of press reports, and the secondary compilations that do circulate are missing rows and carry stale identity statuses.

What follows is the method, the full table, a chart of how the fourteen slots resolved, the six historical rows without an official reveal, the data terms each listing carried, the dated evidence on the one row still open, and instructions for redoing the work. The launch-day story of that open row, Ox Alpha, is told in our August 20 post and is not repeated here.

Key takeaways
  1. 01
    Fourteen stealth listings since April 2025, not twelve.Horizon Alpha (listed 2025-07-30) and Horizon Beta (2025-08-01), the GPT-5 stealth previews, were missing from the compilation most coverage relies on. Both were named by OpenRouter’s own blog and X account on 2025-08-07.
  2. 02
    Seven of the thirteen historical slots were officially revealed.Four by OpenRouter itself (Quasar, Optimus, Horizon Alpha, Horizon Beta) and three by the underlying lab (Xiaomi for Hunter and Healer Alpha on 2026-03-18; Meituan for Owl Alpha on 2026-06-30). Four carry only a community identity theory; two have none.
  3. 03
    Every reveal came from a first-party channel, never from fingerprinting.Across seven reveals the mechanism was OpenRouter’s own blog or X post, or the lab’s own blog or X account. Community tokenizer and output-style matching has preceded reveals and sometimes pointed at the right lab, but it has never been the thing that settled one.
  4. 04
    Thirteen of fourteen listings defaulted to training-in-scope data terms.Every historical row carried a variant of “logged by the provider and may be used to improve the model.” Ox Alpha is the sole exception, and OpenRouter’s own announcement framed it as one: “this time, the provider does not train on your prompts or completions.”
  5. 05
    Ox Alpha’s identity is unconfirmed as of August 22, 2026.Tokenizer, video-encoder and serving-layer fingerprints from August 20 to 22 all point at a Zhipu AI / Z.ai GLM-5.3-lineage variant. That is the leading community theory, with its method stated. No statement exists from Zhipu, Z.ai or OpenRouter.

01The Corrected CountSeven of thirteen revealed, not three of twelve never revealed.

A figure has circulated this week, drawn from a single secondary compilation, that OpenRouter had run eleven stealth slots before Ox Alpha and that three of those eleven were never revealed; the twelve-row framing counts Ox Alpha itself as the twelfth row. Going back to OpenRouter’s own blog, X account and model pages for every row, and to the underlying labs’ own channels where a reveal was claimed, changes that count in three places.

Rows added
Horizon Alpha and Horizon Beta
+2

Listed 2025-07-30 and 2025-08-01 as stealth previews of early GPT-5 checkpoints, and named as such by OpenRouter’s own X post and its “GPT-5 is now live” blog post on 2025-08-07. Neither appears among the compilation’s eleven historical rows. The historical set is therefore thirteen.

VERIFIED · OpenRouter’s own channel
Tier raised
Hunter Alpha and Healer Alpha
2

Carried as “reported, secondary only” in circulating tables. Xiaomi’s own MiMo team confirmed both publicly on 2026-03-18, reported the same day by Reuters and Malay Mail, then carried in regional press the following day. A vendor’s own statement is the same evidentiary class as the Quasar and Optimus reveal.

VERIFIED · lab’s own statement
Status flipped
Owl Alpha
1

Marked “never revealed” in circulating tables. Meituan confirmed on 2026-06-30, on its own blog and the @Meituan_LongCat X account, that Owl Alpha was the stealth preview of LongCat-2.0-Preview, with independent corroboration from Decrypt on 2026-07-01. The reveal predates this week’s coverage by roughly seven weeks.

VERIFIED · lab’s own statement

The corrected recount, across the thirteen historical rows: seven officially revealed, four with a community identity theory that no vendor has ever stood behind, and two, Cypher Alpha and Aurora Alpha, with no credible identity theory at all. Ox Alpha is the fourteenth row and is open. The base rate for “we will find out” is materially better than the circulating framing suggested, and the reason is instructive: three of the missing reveals came from the underlying lab rather than from OpenRouter, and a compilation that only watches OpenRouter’s blog will miss exactly that class of event.

That also qualifies the pattern most coverage repeats, that reveals come from OpenRouter’s own blog. The accurate version is that a reveal, when it comes, always arrives through an official first-party channel: OpenRouter’s blog or X account for four rows, and the lab’s own blog or X account for three. Fingerprinting has never yet been the mechanism of a reveal.

02MethodologyWhat was read, what was inferred, and what was left out.

A census is only citable if a stranger can redo it and land on the same numbers. The block below states the collection method, the sources, the as-of date, the count, the exclusions and the known limits, and separates cells that were read off a primary from cells that rest on someone else’s inference.

Methodology

What was collected. Every stealth or cloaked model listing on OpenRouter findable through four routes: (a) a pull of the live openrouter.ai/api/v1/models catalog (422 models), filtered for “stealth” or “alpha” in the id or name; (b) OpenRouter’s own announcements archive; (c) a direct read of each candidate’s own model page under openrouter.ai/openrouter/* or openrouter.ai/stealth/*; and (d) a targeted search for each row’s identity-reveal event, checked against the underlying lab’s own channel where one existed. One secondary compilation (jonathanrreed.com’s stealth-models list) was used only to discover candidate names, never as a source of truth for any cell.

As-of date. All data is as of August 22, 2026. Each row’s listed date and reveal date is the date stated on OpenRouter’s own model page, blog post or X post, or on the lab’s own announcement, not the date of our read. The live catalog values for row 14 come from the 2026-08-22 pull of the models endpoint, cross-checked against a second independent pull with identical values.

How many. 14 listings: 13 historical plus Ox Alpha, open. The secondary compilation listed 11 historical rows; this pass added 2 it omitted entirely (Horizon Alpha, Horizon Beta) and re-tiered 3 (Hunter Alpha, Healer Alpha, Owl Alpha) after finding the labs’ own confirmations.

Excluded, and why. (a) Any “stealth”-flavoured name whose only appearance was a single low-authority blog with no dateable primary; none survived to the table. (b) mancer/weaver, a long-running non-stealth listing whose name happens to contain “(alpha).” (c) Any precision beyond what the primary states: OpenRouter’s own wording for the Horizon rows says “early GPT-5” and never names a checkpoint, so the table does not either. (d) Any benchmark or performance claim not traceable to a named, dated individual or organisation; those appear only in the Ox Alpha section, hedged, never in the table.

Read versus inferred. Every listed date, context length, pricing note and data-terms quotation in the table was read directly off that model’s own OpenRouter page, announcement post, or the live API JSON. Every “turned out to be” cell marked VERIFIED was read off a first-party statement: OpenRouter’s own blog or X account, or the lab’s own blog or X account. Every cell marked REPORTED is an inference made by third parties from routing behaviour or output style, reported as such and never as a vendor statement. Unresolved rows carry no identity claim.

Known limitations. (1) The identities of Sonoma Dusk Alpha, Sonoma Sky Alpha, Polaris Alpha and Sherlock Think Alpha rest entirely on community inference; no xAI or OpenAI statement was found for any of the four despite a dedicated search pass each, so they stay REPORTED until a vendor speaks. (2) Cypher Alpha and Aurora Alpha have no credible identity theory; Aurora Alpha’s one circulating theory is circumstantial by its own proponents’ account. (3) Several historical pages publish only “free during testing” with no rate card, so “free at listing” is recorded without a price. (4) Whether the retired slugs currently return an error on a live chat-completion call was not re-tested; it needs an authenticated call with spend. What is confirmed is that the documentation pages remain live and readable, and that none of the retired names appear in the current 422-model catalog. (5) Prediction-market odds on the open rows are live, continuously updating figures and are deliberately not reported.

Three evidence tiers are used throughout. VERIFIED means a first-party statement names the model: OpenRouter’s own reveal post, or the lab’s own announcement. REPORTED means the listing facts are verified from the model page but the identity rests on community inference with no vendor statement found. Unresolved means no identity theory has credible evidence behind it, and Open is reserved for a listing still running on the as-of date.

03The CensusAll fourteen rows, one claim per cell.

The table is the asset. Listing names link to the model’s own OpenRouter page where one was read; reveal mechanisms link to the first-party statement or the best available corroboration. Listed dates with a slash (2025-04-02/03) are carried as the primary records give them, across two days. Context is the figure on the model page or API record, in tokens. Data as of August 22, 2026.

OpenRouter stealth model census: 14 stealth listings from April 2025 to August 2026 with listing name and slug, listing date, revealed identity, reveal mechanism, reveal date, evidence tier, data terms at listing, whether the model was free at listing, and context length in tokens. Data as of August 22, 2026. Seven rows are VERIFIED by a first-party statement, four are REPORTED on community inference only, two are unresolved, and one, Ox Alpha, is open.
#Listing · OpenRouter slugListedTurned out to beReveal mechanismReveal dateEvidence tierData terms at listingFree at listing?Context (tokens)
Rows 1–9 · Listed in 2025
1Quasar Alphaopenrouter/quasar-alpha2025-04-02/03GPT-4.1, OpenAI pre-release snapshotOpenRouter’s own blog reveal post2025-04-14VerifiedStandard: logged, “may be used to improve the model”Yes1,000,000
2Optimus Alphaopenrouter/optimus-alpha2025-04-10GPT-4.1, nearer-final snapshotSame OpenRouter reveal post as row 12025-04-14VerifiedStandard: logged, “may be used to improve the model”Yes1,000,000
3Cypher Alphaopenrouter/cypher-alpha2025-07-01Unknown; listed under “Cypher Labs,” a provider name OpenRouter itself described as fictionalNever officially revealed; only OpenRouter’s listing announcement existsUnresolvedBroadest in the set: “may be used to improve the model and other products and services”Yes1,000,000
4Horizon Alphaopenrouter/horizon-alpha2025-07-30Early GPT-5 checkpointOpenRouter’s own X post and “GPT-5 is now live” blog post2025-08-07Verified“logged by the model creator for feedback and training”Yes256,000
5Horizon Betaopenrouter/horizon-beta2025-08-01Later GPT-5 checkpoint; superseded Horizon AlphaSame OpenRouter X post and blog post as row 42025-08-07VerifiedStandard: logged, “may be used to improve the model”Yes256,000
6Sonoma Dusk Alphaopenrouter/sonoma-dusk-alpha2025-09-05Presumed early Grok 4 Fast; xAI never confirmedOpenRouter model record only; no xAI statement foundReportedStandard: logged, “may be used to improve the model”Yes2,000,000
7Sonoma Sky Alphaopenrouter/sonoma-sky-alpha2025-09-05Presumed early Grok 4 Fast, larger variant; xAI never confirmedOpenRouter model record onlyReportedStandard: logged, “may be used to improve the model”Yes2,000,000
8Polaris Alphaopenrouter/polaris-alpha2025-11-06Widely believed early GPT-5.1 snapshot; OpenAI never confirmedCommunity leaks and code traces onlyReported (weak)Standard: logged, “may be used to improve the model”Yes; pricing not published256,000
9Sherlock Think Alphaopenrouter/sherlock-think-alpha2025-11-15Believed early Grok 4.1 Fast (reasoning); xAI never confirmedSecondary coverage onlyReportedStandard: logged, “may be used to improve the model”Yes; pricing not published1,840,000
Rows 10–14 · Listed in 2026
10Aurora Alphaopenrouter/aurora-alpha2026-02-08/09Unresolved; no first-party statement from anyoneNever officially revealedUnresolvedStandard: logged, “may be used to improve the model”Yes; pricing not published128,000
11Hunter Alphaopenrouter/hunter-alpha2026-03-11Xiaomi MiMo-V2-Pro, “an early internal test build”Xiaomi’s MiMo team confirmed publicly; reported the same day by Reuters and Malay Mail2026-03-18VerifiedStandard: logged, “may be used to improve the model”Yes; pricing not published1,048,576
12Healer Alphaopenrouter/healer-alpha2026-03-11Xiaomi MiMo-V2-Omni, multimodal siblingSame Xiaomi MiMo confirmation as row 112026-03-18VerifiedStandard: logged, “may be used to improve the model”Yes; pricing not published262,144
13Owl Alphaopenrouter/owl-alpha2026-04-28Meituan LongCat-2.0-Preview, 1.6T-parameter / 48B-active MoEMeituan’s own blog and @Meituan_LongCat X account; corroborated by Decrypt2026-06-30Verified“may be logged by the provider and used to improve the model” (softer phrasing)Yes; pricing not published1,048,576
14Ox Alphastealth/ox-alpha2026-08-20 (20:04 UTC)Not revealed as of 2026-08-22 (leading community theory in section 07)Not revealedOpenCarve-out: retained by the provider, “not used for training”; announced as “this time”Yes; $0 / $0 on the API record1,048,576

Two cells deserve a note on what they do and do not claim. Row 8’s tier reads “Reported (weak)” because no vendor statement of any kind exists for Polaris Alpha; the GPT-5.1 identity rests on leak-based speculation alone, which is thinner than the OpenRouter model record behind the two Sonoma rows. Row 14’s “turned out to be” cell deliberately says nothing about the leading theory; a census cell is not the place for an identity no vendor has confirmed, and the evidence is laid out with dates in section 07 instead.

04Resolution RateHow fourteen slots resolved, and how fast.

The chart below is the evidence-tier column of the table, counted. It is the single most citable figure on this page because it is the direct, dated answer to the question every stealth listing raises: how often do we actually find out.

Evidence tier across 14 OpenRouter stealth listings · as of August 22, 2026
Evidence tier across 14 OpenRouter stealth listings as of August 22, 2026: 7 verified by a first-party statement, 4 reported on community inference only, 2 unresolved, 1 openHorizontal bar chart. Verified 7 of 14 (50.0 percent). Reported 4 of 14 (28.6 percent). Unresolved 2 of 14 (14.3 percent). Open 1 of 14 (7.1 percent).Verifiedfirst-party statement on record7 of 14 · 50.0%Reportedcommunity inference, no vendor statement4 of 14 · 28.6%UnresolvedCypher Alpha · Aurora Alpha2 of 14 · 14.3%OpenOx Alpha · listed 2026-08-201 of 14 · 7.1%

Source: the census table above. Bar length is proportional to row count (7 rows = full width). Percentages are of all 14 rows; of the 13 historical rows alone, the shares are 53.8% verified, 30.8% reported and 15.4% unresolved.

Where a reveal did come, it came inside a fortnight in six of seven cases. Optimus Alpha was named 4 days after listing, Horizon Beta after 6, Hunter and Healer Alpha after 7, Horizon Alpha after 8, and Quasar Alpha after 11 to 12, depending on which side of the day boundary its listing is counted from. The outlier is Owl Alpha: listed 2026-04-28 and confirmed 2026-06-30, a 63-day gap, and the one reveal that a watcher monitoring only OpenRouter’s own channels would have missed entirely, because it came from Meituan.

The honest reading of the chart is two-sided. A slot that resolves usually resolves inside a fortnight and always through a first-party channel; but six of the thirteen historical slots never resolved at all on the evidence available, and two of those never acquired even a credible theory. “We will find out soon” is a better bet than the circulating framing implied, and it is still not a safe assumption to build a delivery date on.

"Hunter Alpha was an early internal test build of MiMo-V2-Pro"— Xiaomi’s MiMo team, March 18, 2026, as reported the same day by Reuters and Malay Mail

05Negative FindingsThe six historical rows without a reveal.

These are the rows where the “will we find out” thesis fails, and they stay in the table for that reason. Each card states what the community believes, what the primary record supports, and what was searched for and not found. A dedicated search pass was run for every one of the four REPORTED rows; no xAI or OpenAI statement turned up for any of them. Six historical rows are covered below, across five cards, because the two Sonoma listings were a same-day pair; Ox Alpha is added as a sixth card because it is open on the as-of date rather than unresolved.

Row 3 · Unresolved
Cypher Alpha
Listed 2025-07-01 · 1,000,000 context

Presented under the provider name “Cypher Labs,” which OpenRouter’s own announcement described as fictional. No vendor has ever claimed it and no identity theory has evidence behind it. It also carried the broadest data terms in the set: content usable to improve the model “and other products and services.”

No credible theory
Rows 6–7 · Reported
Sonoma Dusk Alpha and Sonoma Sky Alpha
Listed 2025-09-05 · 2,000,000 context each

Presumed to be early Grok 4 Fast builds, the Sky variant the larger of the two. The listing facts are verified from the model pages; the identity rests on the OpenRouter model record and community inference. No xAI statement was found.

Identity: community inference
Row 8 · Reported (weak)
Polaris Alpha
Listed 2025-11-06 · 256,000 context

Widely believed to be an early GPT-5.1 snapshot. The belief rests on community leaks and code traces only; OpenAI has never confirmed it, and leak-based speculation is thinner than the OpenRouter model record behind the two Sonoma rows.

Identity: leak-based only
Row 9 · Reported
Sherlock Think Alpha
Listed 2025-11-15 · 1,840,000 context

Believed to be an early Grok 4.1 Fast reasoning build. Secondary coverage only; xAI never confirmed it. Listing facts verified from the model page.

Identity: secondary coverage
Row 10 · Unresolved
Aurora Alpha
Listed 2026-02-08/09 · 128,000 context

The one circulating theory, OpenAI’s Codex-Spark, rests on a five-day proximity between the listing and that product’s announcement plus matching positioning as a fast coding reasoner. Its own proponents describe it as circumstantial; no statement exists from anyone. Recorded as unresolved, not as reported.

No first-party statement
Row 14 · Open
Ox Alpha
Listed 2026-08-20 · 1,048,576 context

Open on the as-of date. The community evidence is the most specific in the set and is laid out, dated, in section 07. It remains unofficial, and the row stays Open until a first-party statement exists.

Open as of 2026-08-22

A pattern worth recording: the four REPORTED rows all have the same shape. Two presumed xAI builds in September, one presumed OpenAI snapshot and one presumed xAI reasoning build in November, and in every case the presumption rests on routing behaviour, output style or leaks rather than on anything either lab has said. Neither lab has confirmed or denied, and absent a statement these rows will stay REPORTED indefinitely. That is not a defect of the census; it is the finding.

06Data TermsThirteen defaults and one carve-out.

Every historical listing’s data-terms notice was read off its own OpenRouter page. The wording varies cosmetically; the scope does not. The secondary table below groups the fourteen rows by exact wording so the variance is visible cell by cell. Data as of August 22, 2026.

Data-terms wording at listing for 14 OpenRouter stealth models, grouped by exact wording read from each model’s own OpenRouter page, as of August 22, 2026. Thirteen historical rows carry a training-in-scope default; Ox Alpha alone carries a no-training carve-out.
ListingsExact data-terms wording on the model pageTraining in scope?
Quasar, Optimus, Horizon Beta, Sonoma Dusk, Sonoma Sky, Polaris, Sherlock Think, Aurora, Hunter, Healer“All prompts and completions for this model are logged by the provider and may be used to improve the model.”Yes (default)
Horizon Alpha“prompts and completions are logged by the model creator for feedback and training”Yes (default)
Cypher Alpha“may be used to improve the model and other products and services” (broadest scope in the set)Yes (broadened)
Owl Alpha“Prompts and completions may be logged by the provider and used to improve the model.” (passive, softer phrasing)Yes (default)
Ox Alpha“Prompts and completions for this model are retained by the provider and are not used for training; all other use is governed by the Stealth Model Terms.”No; retention still occurs

The general policy those thirteen defaults sit under is the Stealth Program terms at openrouter.ai/terms/stealth, marked “Last Updated 2026-07-06” on the page. It grants OpenRouter a licence, described as irrevocable and perpetual, to sublicense user content to stealth providers “for the sole purpose of enabling the Stealth Provider(s) to train, evaluate, and improve those Stealth Model(s).” The privacy backstop is a hashed identifier: “User Content provided to Stealth Providers will contain a hashed identifier, such that each individual user will not be identified or identifiable to the Stealth Provider,” with a separate contractual bar on providers attempting re-identification. The terms also state plainly that there is no selective opt-out: not wanting content used this way means not using stealth models at all.

Ox Alpha is the exception to that policy, and OpenRouter’s own announcement on X framed it as one rather than as a change: “this time, the provider does not train on your prompts or completions.” Three qualifications travel with that sentence. Retention still occurs; the model page says prompts and completions are retained, just not trained on. The promise is a policy statement, not a technical guarantee anyone outside can verify. And the API record sets is_moderated: false, so no moderation layer sits in front of the model. How these notices compare with the terms coding agents publish is the subject of our sibling census of agent data terms.

07Row 14Ox Alpha: the open row, evidence dated.

stealth/ox-alpha was created in OpenRouter’s catalog at 2026-08-20 20:04:55 UTC. The API record states a 1,048,576-token context, 131,072 maximum completion tokens, text, image and video input, $0 prompt and completion pricing, mandatory reasoning with three effort rungs (max, high, low; no medium) defaulting to max, and a null knowledge-cutoff field. It is the only model in the 422-model catalog whose id or name contains “stealth”; every other Alpha-named slot in the table above has been retired or renamed out of the live API, although their documentation pages remain live.

Everything else known about the row is community evidence, and the table below dates each item. Two framings are excluded on purpose. The “100 trillion tokens per day” figure is not an OpenRouter number and not a provider number; it is OpenCode’s marketing copy about capacity on its own resale route, and it is recorded here only with that attribution. And the model has no audited benchmark: the DeepSWE figures are two community subset runs, reported together, with the correction that accompanied the second.

Dated evidence timeline for Ox Alpha, OpenRouter listing stealth/ox-alpha, from listing on August 20, 2026 to August 22, 2026: each row gives the timestamp, the source, what it found, and the evidence class. Identity remains unconfirmed as of August 22, 2026.
Date (UTC)SourceWhat it foundEvidence class
2026-08-20 20:04OpenRouter API recordopenrouter.ai/stealth/ox-alphaListing created. Model page: “developed and operated by a third-party provider who has chosen to remain anonymous during this preview.”Verified
2026-08-20 20:59OpenCode (@opencode)quoted inside Ben Davis’s Aug 21 thread“Ox Alpha (stealth model) is free for the next week - 1M Context - Multi-modal - Zero Data Retention. Generous rate limits, near unlimited usage. We have capacity for 100T tokens per day, lets see what you can do.” The figure describes OpenCode’s own route and appears nowhere in OpenRouter’s record (per_request_limits: null).Third-party marketing copy, unverified
2026-08-20 21:12@aitrackerbotx.com/aitrackerbot25 diverse prompts; native token counts matched GLM-5.3 exactly except for a constant +75-token hidden wrapper. Accepts image input.Community evidence (tokenizer)
2026-08-21 03:58Theo (t3.gg)x.com/theoPublic scepticism of the 100T-per-day claim, asking who built the model and where that much compute came from.Commentary
2026-08-21 04:20Ben Davisx.com/davis710-task DeepSWE subset: Ox Alpha about 80% versus 65% for Claude Fable and 52% for GPT-5.6 Sol. Single self-reported run; Davis himself notes “a ton of variance.” Same thread: “I’m like 75% sure this is GLM, but I am really not sure.”Community benchmark, n=10
2026-08-21@sushsrinivasantokenizer probe thread11 tokenizer probes across 10 candidate models; Ox Alpha matches GLM on 11 of 11, no other lab passes 4. DeepSeek spends 98 tokens on a digit probe where GLM spends 29.Community evidence (tokenizer)
2026-08-21Video-encoder testsame research threadVideo-token spend matched GLM-5V-Turbo token-for-token across 4 test videos on 3 independent axes: FPS-invariant frame sampling, about 147 tokens per second of duration, and per-frame resolution scaling. MiMo v2.5, Qwen 3.8 Max and GLM-4.6V ruled out by different signatures. Audio input is rejected the way GLM-5V rejects it; MiMo v2.5 accepts audio, a binary disqualifier for that theory.Community evidence (video encoder)
2026-08-21@winkey_h (DataCurve)credited by Davis as DeepSWE’s creatorA larger DeepSWE subset: about 63% at 47K average output tokens, described as “pareto optimal amongst open models... just shy of Grok 4.6.” Explicitly a subset, not the full 113-task set.Community benchmark, larger subset
2026-08-22Chetasluavia explainx.ai write-upA malformed request (top_p:"abc") to OpenCode’s direct Ox Alpha route leaked a Java stack trace naming the class com.wd.paas.api.domain.v4.chat.ChatCompletionRequest, a package path matching Zhipu’s documented /api/paas/v4/chat/completions route. The same malformed-role probe against z-ai/glm-5.3, glm-5.2 and glm-5v-turbo on OpenRouter and against Zhipu’s public APIs returned the same error-code family; the same open GLM-5.2 checkpoint on DeepInfra returned a different error, so the fingerprint is operator-specific, not just checkpoint-specific.Community evidence (serving layer); strongest class found
2026-08-22 22:05Ben Davisx.com/davis7Amplifies the larger-subset result: “Actual DeepSWE run on the ox alpha mystery model is done. Ended at ~63% NOT the 80%...” A same-thread follow-up clarifies the run was @winkey_h’s and “a subset, but a more larger and more useful one than what I did.”Correction on record
Identity status
As of August 22, 2026, Ox Alpha’s identity is unconfirmed. Two independent technical vectors from August 20 and 21 (tokenizer and video encoder) and one infrastructure vector from August 22 (a leaked server-side stack trace plus a shared error-code family) converge on the Zhipu AI / Z.ai GLM-5.3 lineage, with MiMo v2.5 and Qwen 3.8 Max ruled out by the same tests. That is the leading community theory, with its method stated. No statement exists from Zhipu, Z.ai or OpenRouter, and the sub-question of whether it is full GLM-5.3 or an unannounced smaller multimodal variant is unresolved even among the theory’s proponents. Seven prior reveals say the answer, if it comes, will come from one of those three.

One consequence is worth projecting forward. If the row does resolve to a Z.ai model, anyone who built on the free slug during the preview inherits a pinning problem: the slug retires, the named model lands at list price, and the ~z-ai/glm-latest floating alias will repoint to whatever Z.ai ships next. The census can tell you the reveal is likely; it cannot tell you the date, and the precedent for the free endpoint afterwards is retirement.

08ReuseRedoing the census, and how it is maintained.

To reproduce the table: pull https://openrouter.ai/api/v1/models and filter for “stealth” in id; separately browse https://openrouter.ai/blog/announcements/ for “stealth,” “cloaked” and “Alpha” titles; for each historical candidate name, fetch https://openrouter.ai/openrouter/<slug> directly, since most retired stealth models keep a live documentation page after the model itself stops serving; and cross-reference every identity claim against the named lab’s own blog or X account before elevating a row from REPORTED to VERIFIED. A row moves tiers on a first-party statement and on nothing else. For what a listing date does and does not tell you about a model, see our catalog-literacy guide; for what OpenRouter lists in an ordinary month, the July catalog roundup is the baseline stealth slots are an exception to.

This page is maintained in place under a stable slug. When Ox Alpha is revealed, row 14 changes tier and the chart is recounted; when a new stealth slot lists, a row 15 is added. The as-of date in the methodology block and the table caption moves with each refresh, and the modified date in the page metadata records it. If you re-fetch a primary later and a cell has changed, the change is the news; cite the as-of date alongside the figure. Teams that route production traffic through catalogs like this one, and need the listing-versus-launch distinction built into their model selection, are the kind of work covered by our AI and digital transformation practice.

Cite this
Digital Applied, “OpenRouter Stealth Models: Who They Turned Out to Be,” Digital Applied Blog, August 22, 2026, https://www.digitalapplied.com/blog/openrouter-stealth-model-census-who-they-turned-out-to-beThe dataset is as of August 22, 2026 and is refreshed in place. Cite the as-of date with any figure; the modified date in the page metadata records each refresh.

09ConclusionThe base rate is the finding.

Fourteen rows, as of August 22, 2026

Seven of thirteen stealth slots were revealed, and every reveal came from a first-party channel.

The census corrects a count that had hardened into received wisdom inside a week. The historical set is thirteen rows, not eleven; seven of them were named by whoever built or hosted them; four carry an identity no vendor has stood behind; and two, Cypher Alpha and Aurora Alpha, never acquired a credible theory at all. Three of the seven reveals came from the lab rather than from OpenRouter, which is exactly the class of event a compilation watching one channel will miss.

On data terms the set is uniform to a fault: thirteen of fourteen listings defaulted to training-in-scope under a programme EULA with no selective opt-out, and the one exception, Ox Alpha, was announced as an exception. On the open row itself, three independent fingerprints dated August 20 to 22 point at one lineage, and the census treats that as what it is, the leading theory, until a first-party statement moves the row.

The table will be refreshed when that statement comes, or when the next codename lists. Until then the most useful number on this page is the one in the chart: seven of thirteen, with the six that never resolved kept in view.

Model selection with the record read first

Build on the record, not on the rumour.

We help engineering teams select and route AI models on evidence: listing dates separated from launch dates, data terms read at the tier in use, and community benchmarks weighed for what they are.

Free consultationExpert guidanceTailored solutions
What we work on

AI model governance engagements

  • Model routing with pinned IDs, not floating aliases
  • Data-terms review before traffic reaches a preview endpoint
  • Evaluation on your own tasks, not on n=10 community runs
  • Catalog monitoring for retirements and repoints
  • Governance programs for mixed open and closed fleets
FAQ · Stealth model census

Questions a citing writer will ask.

A stealth (or cloaked) model is a listing OpenRouter runs under a codename, usually free, on behalf of a provider that has chosen to stay anonymous during a preview. The listings have historically used an Alpha suffix (Quasar Alpha, Horizon Beta, Ox Alpha) and run for a week or two collecting real traffic before the named model ships. They sit under OpenRouter’s Stealth Program terms, which by default allow the provider to use prompts and completions to train, evaluate and improve the model; Ox Alpha is the only listing in the census with a stated no-training carve-out. Fourteen such listings have appeared since April 2025, and this page records all of them.
Related dispatches

Continue exploring model catalogs and reference tables.