246 — SecFlow: primary research on a Chinese-speaking multi-agent operator Reviewed September 6, 2026 UTC. PRIMARY SOURCE https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia Published September 3, 2026. Public researcher article captured locally; no actor or victim systems visited. WHAT THE RESEARCHER REPORTS Hunt.io links five exposed workspaces to one Chinese-speaking operator's campaign. Its SecFlow framework assigned specialist work, preserved shared state, and supported Claude-, Qwen- and DeepSeek-labelled runtime profiles. Configured routes included private relays and provider endpoints. The reported capture dates span May–August, preceding publication. The report describes an unsupported success claim propagating into later worker assignments despite more than 27 failed follow-up tests. It distinguishes that failure from compromises supported by collected evidence. The researchers attribute exploitation outcomes to conventional tools and weaknesses alongside AI orchestration. OUR ASSESSMENT This is relevant third-party evidence of operational multi-agent use by a Chinese-speaking operator, substantially stronger than a product demo's feature list. It is not independent verification by this investigation: our evidence is the researcher's published account, not its underlying collection. Model-profile labels and configured URLs alone do not authenticate provider execution. No Chinese model-lab affiliation, escaped training swarm, or connection to the original public-scratchpad corpus is established here. SCOPE AND FOLLOW-UP Keep three claims separate: a Chinese-speaking operator, Chinese-model usage, and a Chinese-lab-controlled swarm. Evidence for one does not establish the others. The present lead supports investigating the first through published third-party research; the second remains dependent on runtime provenance; the third has not been shown. Next useful work is comparison with other publicly published research and its evidentiary boundaries. Do not retrieve exposed private workspaces, stolen records, credentials or payloads to substantiate the article. No such retrieval was performed. The legitimate research page was accessible from the existing server, so this lead requires no additional scraping infrastructure. CAPTURES 246-private/article.html, article.txt and SHA256SUMS. Raw article retained privately; public report gives a short attributed summary and source link. No code execution, target probing, account access or external communication.