What this is

This week, a developer described in a Reddit post that while running Qwen locally on his Mac Studio to do Amazon product research, the model — during a tool call (an operation where the AI automatically opens a webpage) — generated a "signed URL" pointing to an Aliyun oss-ap-southeast-1 storage bucket, essentially a temporary download credential with an embedded key.

The URL contained three fields — OSSAccessKeyId, Signature, and Expires — and looked completely legitimate. But he had never asked the model to access any Aliyun resource. The developer stopped the session immediately.

Our judgment: this is not a bug, but a textbook case of "hallucination" (the model confidently fabricating facts). Qwen's training data almost certainly contains large volumes of coding traces (programming records) from Aliyun engineers; the model learned them so well that when it encountered a similar scenario, it spat the URL template out verbatim. A user on Hacker News reproduced the same behavior with Qwen3-27B 45 days ago.

Industry view

Most of the tech community leans toward reading this as "harmless training-data overfitting" (when a model memorizes training material too rigidly and replays it verbatim at test time). Qwen's open-source ecosystem does contain large amounts of internal Aliyun code samples — a reasonable explanatory path.

But the counterargument carries weight too: even if it's "unintentional hallucination," the moment a signed URL lands in a tool-call log, it becomes an exploitable lure to any observer. The deeper problem is that open-source model publishers almost never release training-data anonymization (scrubbing sensitive information) audit reports — enterprises have no basis for judging whether a model might "spit out" sensitive credential patterns.

There's another easily overlooked risk layer: if a local Agent (an AI that autonomously operates tools) actually executes this fabricated URL, it will actively send the request to Aliyun — equivalent to the user's machine reaching out to a third-party server. Even if no data leaves, it's still an unnecessary external connection.

Impact on regular people

For enterprise IT: When plugging open-source models into internal Agent toolchains, tool-call logs should fall under security audits — you can't review inputs and outputs alone.

For working professionals: Developers using local open-source models like Qwen or Llama for daily assistance should periodically scrub the model's network request logs. It's a low-cost good habit.

For the consumer market: Most C-end AI assistants today route through big-tech APIs, so local signed-URL exfiltration isn't an issue there. But "AI-surfs-the-web-for-you" products are worth watching — pay attention to which addresses they actually contact.