Research · Working essay
Free tokens. Max exposure.
Take the free tokens, especially the ones that do not name the lab. A week of unnamed coding inference showed up on OpenRouter, people pointed Claude Code at it, and several trillion tokens moved before anyone knew who was on the other end. Call that Ox Alpha-class: a drop-in URL, a window big enough for a repo, tools on, price zero, operator optional until someone publishes the name. Freemaxxing is taking that surplus on purpose. Self-owning is sending the work laptop, the company checkout, or the harness down the same pipe.
Published 27 August 2026
The Antimolochian Guide to Freemaxxing
Freemaxxing without self-owning.
What just happened
On 20 August 2026 a model called Ox Alpha appeared on OpenRouter as stealth/ox-alpha. Input and output tokens cost nothing. OpenCode advertised near-unlimited use and capacity of 100 trillion tokens a day, aimed at coding, long-horizon agents, and production work. A million-token context window can hold a repo and the agent working it. Patrick Collison called it “very impressive.” A small DeepSWE sample circulated at 80 percent, then the full set came in nearer 63, around GPT-5.6-sol. Those scores are too thin to hang a paper on.
SiliconANGLE, citing Bloomberg, reported that coding tools including Claude Code had already pushed billions of tokens through the model by 23 August. OpenRouter said it only routes requests. Prompts and completions are retained by the unnamed provider and the model page said they “are not used for training,” but the same site’s anonymous-preview terms, as SiliconANGLE noted, extend to training, evaluation, and improvement. OpenCode advertised zero retention and did not name the provider. You can hold those claims at once; they disagree. Heise later counted on the order of 295 million requests and several trillion tokens through 25 August.
On 26 August, Z.ai confirmed it was behind the preview: a GLM-family model, weights to be released. Zhipu AI, Z.ai’s former name, has been on the U.S. Commerce Department Entity List since 16 January 2025, but by the time the name was public a week of other people’s agent traces had already moved. On 28 August the Stealth provider page read “Stealth has no models available on OpenRouter right now. Check back later.” An empty listing that says check back later is still a product, and that is how it fills again.
What you clicked through
The Ox Alpha model card said prompts “are retained by the provider and are not used for training,” then pointed at the Stealth Model Terms for everything else. OpenCode advertised zero retention from a provider it did not name. oxalpha.com still says chats are not stored on its servers, then says treat it like any other AI service, which is brochure copy. The contract is the Stealth Program EULA, dated 6 July 2026.
Section 1 says anonymous free previews exist “for purposes of collecting User Content for use in Stealth Model training and improvement.” OpenRouter “will not disclose the name or origin of Stealth Providers to you.” Section 3 is the price: “In consideration for the provision of your User Content for Stealth Model training and improvement, access to the Stealth Models is provided to you free of charge.” Section 4 is the license: non-exclusive, irrevocable, perpetual, worldwide, to copy, store, and sublicense your User Content to the unnamed provider so it can “train, evaluate, and improve” the model. Irrevocable means you cannot take it back after the rename. Perpetual means the preview ending does not end the grant. User Content goes over with a hashed identifier. OpenRouter says it will contractually bar re-identification.
The acceptable-use exhibit is in the same click. You will not “access or use the Stealth Models on behalf of any third party,” and you will not upload information “subject to safeguarding,” including health, financial, and children’s data. Pointing Claude Code, Cursor, or OpenCode at stealth/ox-alpha hangs another product off the unnamed URL, which people did all week, but the exhibit forbids using the stealth models on behalf of a third party.
OpenRouter’s own logging policy is cleaner than the stealth addendum. The company says it does not train and does not store prompts unless you opt in, but your request still goes to the host. On 14 June 2026 the help desk wrote that most :free endpoints train on prompts or may publish them. Privacy settings keep a separate toggle for free routes; switch it off and the $0 list 404s. Some hosts show up as zero-retention in the provider table. The free toggle still treats the class as training-or-publish. Read both. If this ever gets ugly, quote the stealth EULA.
The coding agent is in the prompt
Point Claude Code, Cline, Cursor, OpenCode, or Hermes at a drop-in OpenAI-compatible endpoint and the call carries the product along with your file: system prompt, tool list, retry logic, how the agent walks a repo. Distillation is training a weaker model on traces of a stronger one. In February 2026 Anthropic published that DeepSeek, Moonshot, and MiniMax had run industrial campaigns against Claude: about 16 million exchanges through some 24,000 fraudulent accounts, aimed at agentic reasoning, tool use, and coding. MiniMax alone accounted for more than 13 million of those exchanges and, Anthropic wrote, pivoted to a new Claude model within 24 hours of its release.
Ox Alpha offered $0 tokens that looked like an API, and the community volunteered the same class of traces. The pipe is visible from the outside. Whoever retains those prompts has the system prompts and tool-calling traces of the coding agents people run. The copyable part is the harness sitting in the prompt, and once tools are on, the model can Read ~/.env without anyone pasting the file, so that content goes to the host with the rest of the session.
Freemaxxing is the point. Use the unnamed window to learn and to ship, including for someone who cannot buy a frontier seat. Scare stories that talk people out of the free quota help the companies selling paid tokens. Self-owning is pointing a work agent at an unnamed endpoint with the product still attached.
What belongs on the wire
The common self-own is the work laptop. Someone in the company checkout points Claude Code or Cursor at a $0 URL because the approved seat is slow or capped. The machine already has the internal names, the tickets, the .env. One base-URL change and that tree is on a pipe the employer did not pick and cannot name. Most employment agreements already forbid it, but the stealth EULA then licenses whatever went out, in perpetuity, to the unnamed host.
Before you point anything at a stealth or :free route, sort the material.
Public
Burn the quota
Things already on the internet: public repos, docs, papers, news, and questions you would ask in a Discord. This is what the free window is for. Do it on a personal machine.
Private but replaceable
Maybe, stripped
Rough notes and generic drafts you could rebuild. Fine only after you have cut the filenames, the internals, and anything that looks like a system prompt. Keep it off the work laptop.
Protected
Keep off the unnamed pipe
Anything that lives on the work computer because of the job: the company repo, client folders, tickets, Slack exports, customer data, internal docs, the agent config IT did not install. School work that is not yours to publish. Side-project code that pays rent. .env files. The system prompt that makes your agent yours. A million-token window can hold the whole working tree in one prompt, which is why the window is that size.
The next Ox Alphas, 28 August 2026
The stealth slot was empty that morning. OpenRouter still listed 18 chat models at $0. NVIDIA Nemotron and Google Gemma are known labs on known hosts; skip them. The rows that rhyme with Ox Alpha are a lab you may not be watching, or a host other than the lab on the ID, with tools and a window big enough for an agent.
| Model | Lab on the ID | Host on the wire | Window | Why it rhymes |
|---|---|---|---|---|
Ox Alphastealth/ox-alpha |
Unnamed, then Z.ai | Unnamed stealth provider | 1M | Gone by 28 Aug. Stealth EULA. 27.2T tokens in a week. Entity List lab once named. |
GLM 5.2 (free)z-ai/glm-5.2:free |
Z.ai | Decart | 256k | Same family as Ox Alpha. Tools on. Third-party host. OpenRouter lists Decart as zero-retention / no-train; the :free privacy toggle still treats the class as training-or-publish. |
MiniMax M3 (free)minimax/minimax-m3:free |
MiniMax | GMICloud | 1M | Anthropic named MiniMax in the 2026 distillation write-up. Vision, tools, 1M context. Host retains prompts for an unknown period; OpenRouter’s table says the host does not train. |
MiniMax M2.7 (free)minimax/minimax-m2.7:free |
MiniMax | GMICloud | 197k | Same host, same lab, tools on. |
Dots3-Note Preview (free)dots-studio/dots-3-note-preview:free |
Dots Studio | AtlasCloud | 512k | Preview in the name. Third-party host. Tools and vision. |
Ling 3.0 Flash Fin (free)inclusionai/ling-3.0-flash-fin:free |
InclusionAI | Novita | 256k | Finance-tuned MoE, listed 27 Aug. Third-party host. Tools on. |
Hosts from each model’s OpenRouter /endpoints call, 28 August 2026. The stealth listing had no live endpoints. GLM-5.3-Flash, the named Ox Alpha successor, was paid that day (Z.AI and Novita). Full $0 dump: freemaxxing-free-models.json.
Likely risks, as of this snapshot
The contract, the host, the window, and the traffic are on the public record.
The work laptop
Corporate code on a personal $0 endpoint
The day-job machine already has Copilot, Claude, or Gemini under a company contract. Someone adds a $0 URL because the approved seat is slow. Claude Code does not care that the laptop is managed, that the repo is private, or that legal thinks the approved vendor is still in use. Change the base URL and company source, tickets, and secrets go into a preview whose operator turns up after the rename. If the job forbids unsanctioned tools, that line was already crossed.
The slot
Unnamed, free, coding-shaped, then gone
Stealth is a standing program with an empty listing on 28 August and a graph that already shows 27.2T tokens through the last occupant. The next codename will look like an API, OpenAI-compatible, and it will fit under Claude Code with a base-URL change. That same drop-in URL is how the tokens get taken and how the agent loop gets copied.
The paper
Model card, chat site, and EULA do not say the same thing
Ox Alpha’s card said prompts were retained and not used for training, oxalpha.com said chats were not stored, and OpenCode said zero retention, but the EULA says free access is consideration for a perpetual training license to an unnamed party. SiliconANGLE, citing the anonymous-preview terms, already flagged the broader grant, so the click-through license is the sentence someone will quote later.
The host
The lab on the ID can differ from the process that sees the prompt
GLM 5.2 free hit Decart. MiniMax free hit GMICloud. Ling hit Novita. Dots3-Note hit AtlasCloud. OpenRouter’s provider table gives Decart zero retention and GMICloud unknown retention. That is OpenRouter’s label of the host. The lab’s training cluster stays off that table. Treat the ID as advertising.
The payload
Tools plus a million-token window copies the agent
Every row above has tools. Two of them have a million-token window. That is the shape of a harness dump: repo, system prompt, tool schema, next action, one request. Anthropic already published that DeepSeek, Moonshot, and MiniMax ran industrial versions of this against Claude with fake accounts. Ox Alpha collected the same class of traces because people pointed the agents at a $0 URL.
The tool call
The model can Read ~/.env without anyone pasting it
The protected bucket above assumes the user chooses what to send, but tools on let the model fetch files that were never in the prompt. A Read ~/.env sends those secrets to the same provider as the rest of the session.
The name, once it lands
Z.ai was on the Entity List before the name was public
Zhipu AI was listed on 16 January 2025, but the preview ran anyway. After they name it you learn the jurisdiction, the export-control story, and which lab ate the week, though the EULA says they will not tell you up front. Plan for that.
Freemaxxing without self-owning
Burn the quota on public work, on a personal machine, on your own time. Summarize papers, generate alternatives, test language, translate, organize. Point a stripped local agent at the $0 URL and see what you can ship. Keep the work laptop and the company checkout out of it, and keep Claude Code’s work profile pointing at the vendor the employer actually signed. A million tokens is enough to ship the whole tree, so keep the window on things that are already public.
The EULA is a perpetual license to someone without a name on the door. Work-computer text stays off the unnamed pipe. Text you would put in a public gist can go on it.
A simple operating rule
Before you point an agent at an unnamed or :free endpoint, ask two questions. Is this the work laptop? Would this exact text, including the system prompt around it and any file the model Read as a tool call, be all right in the next version of that model, sitting in that host’s logs? If either answer is the wrong one, strip it or stay home. Take the tokens and keep the private files off the tool list. When the free week ends, wait for the next codename.
Not only about work access and privacy but what could malicious or misaligned custom models do from inside the harness? A simple
Bowei Liu, comment on a draft of this note, 28 August 2026Read ~/.envsends those tokens to the provider. Imagine a malicious provider whose models are trained to “accidentally” expose secrets 10x more than usual.
The work laptop is the common self-own this note is built around: company checkout, private repo, an EULA that keeps whatever went out. Tools on are the extra case. Someone can keep ~/.env out of the prompt and still lose it if the model is allowed to Read it, because a tool call is another request to the same host. A model that is trying to help will do that while debugging. A host that trains the model to hit secrets more often than a normal coding model would gets ~/.env when the model Reads it. If tools can Read ~/.env, treat that file as already on the unnamed pipe.
The Future of Freemaxxing
The two platforms freemaxxers actually use cashed out this month. On 19 August 2026 Stripe confirmed it was buying OpenRouter, the router behind the stealth slot and the :free list in this note. Stripe declined to publish a number. The New York Times reported $7.5 billion, three months after a Series B that outsiders marked at about $1.3 billion, with $1.5 billion of that going to the founders. OpenRouter’s own post said the product, mission, and current commitments remain unchanged, and that if you build on it today, nothing about the integration changes.
On 26–27 August The Information, via Reuters, reported Nvidia had agreed to buy Hugging Face for $12.9 billion. Business Insider, covering the same talks, described a valuation above $13 billion that had not produced a signed agreement and could still fall apart. Neither company confirmed it. Hugging Face’s last marked round was $4.5 billion in 2023, with Nvidia already in that round, and The Information put recent annualized revenue near $150 million. Hugging Face had earlier turned down a $500 million Nvidia investment that would have valued the hub at $7 billion, on the argument that no single investor should hold that much of a warehouse meant to stay neutral.
Those checks buy the layer where people pick a model and where open weights get found. OpenRouter is the unnamed coding URL and the $0 list. Hugging Face is the Hub, the datasets, and a lot of the hosted inference that sits next to that list. A week of Ox Alpha at 27.2T tokens is the kind of unpaid traffic those prices are a bid for.
How this plays out is still a reading. One path, and the one that matches how large counsel usually behaves, is that Stripe and Nvidia clamp the anonymous and $0 routes because those routes are a liability once a payments company and a public chipmaker own the router and the Hub. The stealth EULA licenses prompts, forever, to a party the user is not told, which is already a work-laptop problem and worse if the model can Read ~/.env. The Next Web, writing about Ox Alpha before Z.ai named itself, put the European version simply: data-protection law wants a named processor and a named place. Rajesh Beri argued after the Stripe report that OpenRouter’s privacy toggles bind downstream hosts, not OpenRouter, that change-of-control language already moves user data with a sale, and that Stripe’s own policy lists training models among its processing purposes. A payments firm also lives under anti-money-laundering and audit rules that want records. Counsel that has to defend a $7 billion gateway in front of a regulator has a reason to retire stealth listings, shrink :free endpoints that train-or-publish, and push remaining traffic onto named, metered, enterprise-shaped routes.
Other people expect the $0 list to stay up. Jensen Huang has said open models drive GPU demand because they run on Nvidia and because they keep closed labs from owning the whole stack. On X and Reddit the same bet showed up in plainer words: Nvidia’s incentive is more open-model traffic on its chips, which is a reason to keep the Hub running. Sandeep Nag at IDC told Fierce Network the deal could accelerate open-model adoption with more capital and compute, and could also turn a neutral marketplace into an Nvidia-centered channel. Brad Gastwirth told Business Insider the biggest risk is neutrality, because developers use Hugging Face as an open platform. Forkast argued the Hub under a U.S. public company becomes a choke point for Chinese open-weight traffic, which already accounts for a large share of tokens on OpenRouter. On the Stripe side, OpenRouter promised the same product and the same roadmap. Motley Fool described the buy as a toll on token spend, which can live next to a $0 on-ramp if the on-ramp still feeds the meter.
A third path is the one Ox Alpha already demonstrated. Labs that want coding traces will keep standing up unnamed URLs, on OpenRouter or on a host that will take them, because a week of harness data was worth more than the inference. Labs can still publish their own drop-in endpoint after Stripe owns the router. People can still download weights and run them locally after Nvidia owns the Hub. The surplus can move. The question is whether the convenient $0 URL, with tools on and a million-token window, still sits behind a logo that a $7 billion or $13 billion legal team is willing to put on a stealth EULA.
The tenet holds after the cap table changes. Take the surplus on a personal machine, on public work, with tools that cannot Read ~/.env. Read that week’s license, because a new owner may keep the meter at zero to feed the pipe, or turn it off to cut liability.
What to watch
Watch the OpenRouter Stealth provider page, the EULA, and the :free endpoints list. If a new codename shows up with tools, a long window, and a $0 price, read that week’s license before you assume last week’s story still holds. Snapshot of the 28 August $0 list: freemaxxing-free-models.json.
Ox Alpha: SiliconANGLE, 23 August 2026 (Claude Code traffic via Bloomberg);
TechCrunch, 26 August 2026;
OpenRouter Ox Alpha listing;
Stealth provider page (empty slot, 28 August 2026);
oxalpha.com/about.
Terms: Stealth Program EULA, 6 July 2026;
OpenRouter data collection;
provider logging table (Decart zero-retention / no-train; GMICloud unknown retention);
OpenRouter help, 14 June 2026 (free endpoints that train or publish).
Distillation: Anthropic, 23 February 2026 (DeepSeek, Moonshot, MiniMax).
Entity List: Federal Register, 16 January 2025.
Traffic: OpenRouter rankings, 27 August 2026 (Ox Alpha 27.2T tokens).
Snapshot: models API and per-model /endpoints, 28 August 2026 · freemaxxing-free-models.json.
Tool-call question: Bowei Liu, comment on a draft of this note, 28 August 2026. See the quote.
OpenRouter sale: OpenRouter, 19 August 2026 (“product, mission, and current commitments remain unchanged”); New York Times, 19 August 2026 ($7.5 billion reported); TechCrunch, 19 August 2026 (Stripe confirmed the buy, declined a price). Hugging Face talks: Reuters / The Information, 27 August 2026 ($12.9 billion reported, unconfirmed); TechCrunch, 26 August 2026 (Business Insider: talks above $13 billion, no signed agreement). Reactions: Business Insider, 27 August 2026 (Gastwirth on neutrality); Fierce Network, 27 August 2026 (Nag at IDC); Mashable, 28 August 2026 (user reactions); The Next Web, 22 August 2026 (unnamed processor under European data law); Rajesh Beri, 17 August 2026 (toggles, change of control, Stripe training language).
This is an operational guide. Terms, configurations, and laws change. Check the specific product and agreement you are using before handling sensitive material.