Z.ai's ZCode Secretly Uploaded User Data, Trust Declines

Chinese artificial intelligence firm Z.ai, also known as Zhipu AI, is experiencing a decline in user trust following revelations that its ZCode coding assistant tool secretly uploaded local workspace information. This data transfer to external servers reportedly occurred without explicit user approval. The incident has prompted concerns within the industry regarding cybersecurity and user privacy.

The issue emerged after an independent Chinese technical blogger, known as Ferstar, examined a local directory within ZCode. Ferstar discovered a compressed file, measuring 313 megabytes, awaiting upload to Alibaba Group Holding's cloud storage service. This file had reportedly failed to upload 564 times. A smaller file, 15 kilobytes in size, had been successfully sent, according to Ferstar's account.
And both files were encrypted, Ferstar stated. The larger file reportedly contained a snapshot of a commercial project, including its Git history, based on visible filenames. The archive could not be opened by the blogger or the ZCode client and required a private key held on Z.ai's back end for decryption. The upload mechanism was reportedly enabled by default, offering no option for users to deactivate it. Other users, including tech blogger Feng Ruohang, also observed similar uploads, with Ruohang noting at least three files transferred.
Z.ai released a statement through its official Feishu community, confirming the issue had been fixed and offering an apology to affected users. The firm also announced plans to open-source ZCode's codebase and engage third-party assessors for review. Updates on this review process are expected to be published. As a form of compensation, Z.ai stated it would provide all ZCode users with an additional weekly quota reset.
But the company sought to reassure users that any uploaded data had been immediately destroyed. Ferstar, the blogger who first identified the vulnerability, later questioned the verifiability of this "immediate destruction" claim in a subsequent update. According to SCMP, Alibaba, which owns the South China Morning Post, did not provide immediate comment on the matter.
A Shanghai-based AI developer, identified as Tuxi, indicated the ZCode incident would probably have a greater effect on community trust than on Z.ai's underlying models. Tuxi characterised the action as "basically like stealing something from users" and expressed worry about the "malicious intent." The developer suggested the episode could harm Z.ai's standing, particularly among international users of its GLM models, although the operational impact on the models might be limited since devs can use GLM with alternative coding tools such as OpenAI's Codex.
So, this incident has prompted tangible reactions. A software engineer at a prominent Chinese robotics firm, speaking anonymously due to not being authorised for public comment, confirmed their company had internally prohibited the use of Z.ai's tools due to security concerns. This situation mirrors previous occurrences involving Anthropic's Claude Code and Grok Build from Elon Musk's xAI, a part of SpaceX, earlier this year. The global AI community is increasingly emphasising user privacy and cybersecurity, a subject that may be a key point of discussion during an anticipated meeting between Chinese President Xi Jinping and his US counterpart, Donald Trump.
Z.ai's ZCode tool uploaded user workspace data without explicit consent.
A developer discovered encrypted commercial project files transferred to Alibaba cloud storage.
Z.ai apologised, claiming a fix and offering open-sourcing of the codebase, third-party review, and user compensation.
Industry experts predict significant reputational damage, particularly for Z.ai's GLM models.
The incident highlights increasing global focus on AI user privacy and cybersecurity, a topic potentially discussed at high-level political meetings.
Source: SCMP


