Skip to content
Rush Commerce
Software & Dev3 min read

AI agent fleet scraped Amap using its own demo API keys

Researchers tracked an AI agent fleet on Tencent Cloud that scraped Alibaba's Amap with public demo API keys. Here's how to lock down the keys on your site.

Independent researchers have tracked an AI agent fleet running on Tencent Cloud that spent a week scraping Alibaba's Amap map service. The agents did not break anything clever. They got around Amap's restrictions with Amap's own API keys, copied from public demo pages and old templates. If your site has a demo page, a code sample, or a CodePen with a live key in it, an agent can find it and use it at scale.

What actually happened

The researchers published their findings after they noticed the traffic on urlquery, a public URL-scanning service. TechCrunch reported the story on October 5. Key points from the write-up:

  • Scale. About 2,048 scan reports between September 28 and October 4, across 216 locations, with up to 14 agent runs at the same time.
  • Target. Amap data on which entrances people use to get into parks, zoos, museums, and hospitals.
  • Infrastructure. Traffic came from Tencent Cloud addresses in Hong Kong, mostly with the default python-requests user agent, through a proxy the researchers link to a Tencent sandbox certificate.
  • Methods. Public Amap API keys taken from demo pages and archived templates, generated anti-bot tokens, relay services such as r.jina.ai and Google Translate's proxy, and in 49 reports a request to an Amap pre-release host.
  • Fleet, not swarm. The researchers saw many parallel agents on the same task with no sign that they talked to each other.

Some reports carried "claude" labels. The researchers' own text analysis says the code does not match Claude output and points toward Chinese models instead. Treat that attribution as their estimate. Neither Tencent nor Alibaba had commented in TechCrunch's report.

Why it matters for your business

Your API keys do not have to be "leaked" to be abused. A key in your own docs is already public. An agent fleet can read every demo page you ever posted, try every key, and run 14 copies of the job while you sleep. Most small businesses have at least one of these:

  1. A maps, search, or product API key in client-side JavaScript. Lock it to your domains and to the specific APIs it needs. Google Maps, Mapbox, and Algolia all support referrer and scope limits.
  2. Old demo pages and templates. Search your repos, CodePens, and the Wayback Machine for your keys. Rotate any key that was ever public.
  3. A staging host on the open internet. Put it behind auth or an IP allowlist. The researchers saw requests to Amap's pre-release server.
  4. No rate limits per key. Set quotas and alerts so a spike shows up as a bill alert, not a surprise invoice.
  5. Bot rules that trust user agents. A python-requests header is easy to block, but agents can change it in one line. Rate-limit by key and by behavior too.

Key takeaways

  • Researchers tracked about 2,048 agent scans of Amap from Tencent Cloud addresses over one week
  • The agents reused Amap's own public demo API keys and relay services to get around limits
  • Some requests went to an Amap pre-release host
  • Restrict every client-side key by domain and scope, and rotate keys that were ever public
  • Put staging behind auth and set per-key quotas and alerts

Agents will read every key you ever published. We audit small-business sites and APIs for exposed keys, open staging hosts, and missing rate limits, then fix them. See our services, or ask us to check your keys.

Sources: Swarmchase research write-up, TechCrunch.

  • #ai-agents
  • #web-scraping
  • #api-security
  • #bot-protection
  • #api-keys
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.