5 Sources
[1]
Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes -- Z.AI, the firm behind the GLM models, didn't ask for user consent and made 564 attempts to exfiltrate 313MB archive
Beijing-based company asserts it has now resolved this issue and plans to open source the ZCode codebase. The second-largest AI company in China is having to work frantically to patch up its reputation, reports the South China Morning Post. Z.ai's firefighting exercise began after a number of
[2]
Z.ai says sorry for slurping up your code, open sources ZCode
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that's highly reminiscent of the issues over which Elon Musk's xAI was scrutinized in July, Z.ai's code-generation harness wing, ZCode, was found
[3]
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Z.ai's default-enabled workflow sent entire local repositories to cloud infrastructure, raising fresh concerns over how AI tools handle sensitive source code. endif; ?> Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a
[4]
China's Z.ai disables AI coding assistant features after security issue
BEIJING, Sept 21 (Reuters) - Chinese startup Z.ai said on Monday it had disabled some features of its flagship AI coding assistant after some users reported it was uploading entire local code repositories onto overseas cloud servers without their consent. Beijing-based Z.ai, also known as Zhipu,
[5]
Z.ai: China's Z.ai disables AI coding assistant features after security issue
* Z.ai says bug originated from default-enabled feature * Rare security disclosure from Chinese AI lab * Independent review found user data was deleted from cloud --Z.ai By Laurie Chen BEIJING, Sept Chinese startup Z.ai said on Monday it had disabled some features of its flagship AI coding
Share
Copy Link
China's second-largest AI company Z.ai disabled its ZCode coding assistant after developers discovered it was uploading entire local repositories to Alibaba Cloud without permission. The company has apologized, deleted uploaded data, and open-sourced ZCode's codebase for community scrutiny following the security breach.
Beijing-based Z.ai, China's second-largest AI company and developer of the GLM models, has issued a public apology after developers discovered its ZCode AI coding assistant was silently uploading hundreds of megabytes of local workspace data to Alibaba Cloud servers without user consent
1
. The unauthorized data upload sparked immediate data privacy concerns across the developer community and forced the company into damage control mode.Developer and blogger Ferstar first exposed the issue, discovering that ZCode had compressed 313MB of their files into a directory for upload to cloud storage. When caught, the tool had made 564 attempts to exfiltrate this compressed and encrypted archive, though only a smaller 15KB file had successfully been transmitted
1
. Another tech blogger, Feng Ruohang, reported experiencing similar unauthorized data upload incidents with the AI coding assistant.
Source: Tom's Hardware
The data exfiltration stemmed from ZCode's "Codebase Indexing" feature, also known as Repository Index functionality, which was enabled by default with no option for users to disable it
4
. This workflow triggered the uploading of files after Repo Wiki generated pages in the cloud, effectively creating a pipeline from local systems to cloud storage without explicit user action2
.The AI tool security flaw wasn't just accessing active files but capturing the broader development environment. "Whenever you are logged in, ZCode silently packages your entire workspace -- complete .git history, LFS asset cache, reflogs, and global app configs -- encrypts it, and uploads it directly to Aliyun OSS," Ferstar wrote in a detailed technical investigation
3
. This raised serious enterprise code upload risk concerns, as proprietary source code, embedded credentials, and sensitive business logic could be transmitted to external servers.Chengming Technology reported that six of its company coding workspaces were uploaded to the cloud without consent by ZCode, including sensitive data such as complete source code, database passwords, and employees' personal information
4
. Though the company later retracted its statement citing "wrong evidence," the incident highlighted how AI tool security vulnerabilities can expose enterprise environments.Making the situation worse, the private key used to decrypt the uploaded data was only held by servers under Z.ai's control, meaning users could not access the files ZCode had uploaded, nor could they independently verify deletion
2
. Developers also noted there was no toggle to disable the feature and no prior acknowledgement in Z.ai's privacy policy about this data collection practice4
.An unnamed software engineer at a leading Chinese robotics company indicated that Z.ai's tools have been banned within the company due to AI security concerns
1
. This suggests the unauthorized data upload issue may have been known in some circles before becoming public.
Source: InfoWorld
On Friday, Z.ai acknowledged the vulnerability reporting and apologized for the "security issues," confirming that uploaded data had never been used to train its models
2
. The company disabled the repository upload mechanism, removed the Repo Wiki feature, and released ZCode v3.14.0 with the necessary remediation3
.In a significant transparency move, Z.ai open-sources ZCode's entire codebase on GitHub, "placing the code under community scrutiny and making ZCode more open and transparent"
2
. The company stated, "We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process"2
.Z.ai commissioned CAICT (China Academy of Information and Communications Technology) and Beijing security firm NSFOCUS to conduct independent security assessments following the implemented changes
2
. According to Z.ai, NSFOCUS confirmed that "all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted"3
. The third-party review found that no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally was identified in the patched version.The company enabled a zero-data retention feature on the coding assistant and pledged to release the full security assessment report soon
5
. "Once again, we sincerely apologize and welcome continued scrutiny from the community," Z.ai wrote on Monday4
.
Source: The Register
Related Stories
This rare public disclosure of a security breach by a Chinese AI lab comes amid global warnings about frontier AI security risks. China's cyber regulator released an updated AI safety framework policy last week, warning about AI models' shutdown resistance, evaluator deception, and sandbox escape
4
. The timing underscores growing regulatory attention to AI tool security vulnerabilities.Security experts emphasize this isn't fundamentally an AI problem but an architecture issue. "This isn't really an AI model problem, it's an old-fashioned security architecture problem," said Cris Thomas, security advocate at Semgrep. "Giving an AI access to proprietary source code should require clear disclosure about what leaves the machine, where it goes, how long it's retained and who can access it, with the minimum permissions turned on by default, not the maximum"
3
.The Z.ai incident mirrors similar issues with U.S.-based AI companies. Elon Musk's xAI, specifically the Grok Build tool, faced scrutiny for similar unauthorized data upload practices earlier this year. Claude Code users have also raised data privacy concerns about their data being transmitted without consent
1
.For enterprises evaluating AI coding assistants, this incident highlights the critical need to rigorously vet tools before deployment. Katie Paxton-Fear, staff security advocate at Semgrep, noted, "Given how much intellectual property is in code, it's not surprising that people are worried about it being sent to a third-party cloud provider"
3
.Z.ai, formerly known internationally as Zhipu, is among the world's AI heavyweights and the first AI company in the post-Gen AI era to IPO on the Hong Kong Stock Exchange
2
. The company claimed last month that its GLM-5.3 model approaches Anthropic's Mythos in finding software vulnerabilities, becoming the first Chinese lab to explicitly delay an AI model release for safety reasons4
. OpenAI and Anthropic have reportedly expressed concern over the capabilities of models from Z.ai while the U.S. government considers restricting access2
.Organizations should watch for Z.ai's promised full security assessment report and monitor whether the open-sourced codebase reveals additional insights into how AI coding assistants handle local workspace data. The incident serves as a reminder that default-enabled features with broad permissions pose significant risks, regardless of whether AI systems run locally or in the cloud.
Summarized by
Navi
[2]
14 Aug 2026•Technology

03 Jul 2026•Technology

24 Jun 2026•Technology

1
Policy and Regulation

2
Technology

3
Technology
