All News
qwenlocal-llmhallucinationalibabaai-safetyreddithacker-news

Two users, eight weeks apart, watched their local Qwen runs invent signed Alibaba cloud URLs

Two users, weeks apart, say local Qwen models invented signed URLs on Alibaba's cloud domain. The links look genuine. Nobody can yet say why they appeared.

Vlad MakarovVlad Makarovreviewed and published
2 min read
Two users, eight weeks apart, watched their local Qwen runs invent signed Alibaba cloud URLs

Two users, eight weeks apart, watched local Qwen models emit well-formed signed URLs pointing at Alibaba's own object-storage service, and both framed the finding as a question rather than an accusation. Neither report shows data leaving a machine, neither has drawn a response from Alibaba or the Qwen team, and no researcher has reproduced the behaviour in public. The gap between what the two accounts document and what they are being read to mean is the whole story.

Two reports, eight weeks apart

On October 5, u/PerfectOlive1324 posted to r/LocalLLaMA: "My qwen model hallucinated a signed URL to Alibaba cloud, normal or sketchy?" (the thread). The post sat at roughly 230 upvotes and around 130 comments when the snapshot was taken. The OP says he runs Qwen3.8-Flash-Next locally on a Mac Studio as a daily driver; partway through Amazon product research, the model issued a browser_navigate to a routify-file-proxy-sg.oss-ap-southeast-1.aliyuncs.com address. He killed the session and went looking, then found the earlier one: a Hacker News item from August 20, "Qwen3.8 Fetches Weird URLs", eight points and no comments, where u/Luker88 logged the same host in opencode with a Qwen3.8-27B build, "16 times in total".

A real signing pattern, an unproven reading

Both URLs carry the shape of a genuine pre-signed Alibaba OSS object: an Expires timestamp, an OSSAccessKeyId, and a Signature. The detail both users found strange is the expiry. Converting the two Expires values gives July 8, 2027 and August 18, 2027, nine months to a year ahead of the reports and long-lived for a link meant to lapse quickly. Luker88's own guess, written into his post, was "Probably training links": training-data contamination, with the model autocompleting a signature shape learned from Alibaba-internal traces. That is a hypothesis. The malicious reading, a model trained to push local data to a specific bucket, is supported by nothing in either report, and the Reddit poster's title is a question rather than a charge. Neither Alibaba nor the Qwen team has commented, and nothing has been reproduced.

What would settle it

Anything specific would help. A sentence from Qwen or Alibaba acknowledging or denying the pattern would collapse most of the speculation. A public regression test, prompting the model to fetch a page and watching whether it invents an aliyuncs.com URL, would separate contamination from intent, as would a scan of the published training corpus for the host string or a packet capture from a sandboxed run. Until one of those lands, the honest answer to "normal or sketchy?" is that both readings remain open.

Related Articles

Scroll down

to load the next article