Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Chinese AI firm Z.ai faces backlash after coding tool secretly uploaded user data
00

Chinese AI firm Z.ai faces backlash after coding tool secretly uploaded user data

Sep 20, 2026

Chinese AI startup Z.ai is facing a trust crisis after developers discovered its ZCode coding assistant was silently packaging and uploading entire local project workspaces, including Git histories, to Alibaba Cloud. The issue came to light when developer Ferstar found a 313MB encrypted archive that had failed to upload 564 times. Z.ai apologized, patched the tool, and promised to open-source ZCode for third-party audits, but the incident has already prompted internal bans at some tech firms.

ZCode unauthorized data upload discovery

  • ▪Ferstar found a local ZCode directory on his MacBook containing a 313MB encrypted archive that failed to upload 564 times and a 15KB file that successfully uploaded
  • ▪The 313MB archive packaged by ZCode and found by developer Ferstar represented a full snapshot of a commercial project, including its complete Git history containing 42,411 files
  • ▪Blogger Feng Ruohang reported seeing at least three files uploaded from his computer by Z.ai's ZCode client
  • ▪Chinese developer Ferstar discovered that Z.ai's coding assistant, ZCode, was packaging entire project workspaces and attempting to upload them to Alibaba Cloud storage without user permission.

Repository indexing feature design

  • ▪Z.ai stated that generating a Wiki page in the cloud could trigger a repository upload in its ZCode coding assistant, and this repository upload feature was enabled by default after launch with no toggle to disable it
  • ▪Z.ai attributed the unauthorized ZCode data uploads to ZCode's repository indexing feature, which supports session checkpoint recovery, version rollback, and a Repo Wiki

Encrypted archive inaccessible to users

  • ▪The encrypted archives generated by ZCode and found by developer Ferstar could not be decrypted by users or the ZCode client because the private key is held exclusively on Z.ai's back end
  • ▪Z.ai claimed that the data uploaded through ZCode's repository upload feature is destroyed immediately after a Repo Wiki page is generated, though users noted this claim cannot be independently verified

Z.ai apology compensation response

  • ▪Z.ai apologized in its official Feishu community, patched the ZCode data upload issue, and promised to provide users with an additional weekly quota reset as compensation
  • ▪Z.ai promised to make the ZCode codebase publicly available and invite third-party assessors to audit ZCode's security

Privacy policy documentation gaps

  • ▪The only data control documented in ZCode's privacy policy, which took effect on 15 June, is the Optimization Program, which is off by default and governs model training rather than transmission
  • ▪ZCode's privacy policy, effective June 15, 2026, states it collects text, files, and code submitted through conversation, but does not document repository snapshotting.

AI coding tool security risks

  • ▪Z.ai's ZCode data-upload incident drew comparisons to Grok Build, which previously uploaded entire Git repositories to xAI's servers despite marketing claims that no code was transmitted
  • ▪An anonymous software engineer at a leading Chinese robotics company stated that their employer banned Z.ai's tools internally due to security concerns.

Debatable claims

  • ▪Z.ai's open-source and audit promises are sufficient to restore developer trust
  • ▪Enterprises should ban Z.ai's tools over security concerns

3 sources

Thenews
ZCode tried uploading your files 564 times, researcher finds
View source article
Thenextweb
Only Z.ai can open the code Z.ai uploaded
View source article
Scmp
Chinese AI firm Z.ai faces reputation hit after unauthorised uploads
View source article

Featured stories

View more in AI security

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Story comments

Loading comments…

Related entities

China

Related Projects

alibabaZ.ai

Topics

AI securityAI data privacy & biometric surveillanceChinaAI coding assistants

Featured stories

View more in AI security

OpenAI announces Codex cloud environments, Decisions API and Ultrafast tier at DevDay 2026

Sep 29, 2026 · 7 sources

OpenAI revenue hits $70 billion annualized rate as ChatGPT reaches 1.2 billion weekly users

Sep 29, 2026 · 13 sources

RSA launches Agent ID security platform to track thousands of shadow AI agents in enterprises

Sep 28, 2026 · 3 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources