
Chinese AI company Z.ai has apologized after developers discovered that its code-generation tool, ZCode, had been quietly packaging up and uploading complete user workspaces to Alibaba Cloud. The Z.ai data privacy issue came to light when a researcher noticed the tool sending entire project histories off to remote servers without ever asking for permission, raising fresh questions about how AI coding assistants handle the sensitive code developers feed into them.
Key takeaways
- Z.ai’s ZCode tool uploaded entire user workspaces, including project histories, to Alibaba Cloud without disclosure or consent.
- Only Z.ai held the private decryption key, so users could not access or delete their own uploaded files.
- The behavior could not be turned off and was not mentioned anywhere in ZCode’s privacy policy.
- Third-party reviewers CAICT and NSFOCUS say all previously uploaded data has now been deleted and the feature removed.
- Z.ai open sourced the entire ZCode project on GitHub, though a researcher says commit history and the original upload code were wiped first.
Z.ai’s ZCode Uploads User Workspaces Without Disclosure
The core problem was simple but serious: ZCode was found packaging and encrypting whole developer workspaces, then shipping the archives to Alibaba Cloud without telling anyone. According to Tom’s Hardware, developers tracked the behavior to hundreds of megabytes of local workspace data being exfiltrated, with one report describing 564 separate attempts to send out a 313MB archive. Z.ai never asked for user consent before any of this happened.
What made the situation worse was who held the keys. The private key needed to decrypt the uploaded data sat only on servers controlled by Z.ai. That meant developers whose code had already been swept up had no way to view what had been taken, and no way to force its deletion themselves.
No Way to Opt Out or Delete the Data
Ferstar, the researcher credited with first flagging the issue, said there was no setting anywhere in ZCode that let users switch the uploading off. Just as troubling, the practice was never mentioned in the tool’s privacy policy, leaving developers with no way of knowing their workspaces were being copied off their machines in the first place.
What Triggered the ZCode Data Upload
The uploading behavior traced back to a specific feature. Ferstar, the researcher who flagged the issue, pointed to the tool’s Repository Index functionality, which kicked off the uploads once a companion feature called Repo Wiki generated documentation pages in the cloud. In effect, a feature meant to build reference pages for a codebase ended up hoovering up the codebase itself.
ZCode addressed the fallout in a statement issued Monday, apologizing for what it called “security issues” and stating that none of the uploaded data had ever been used to train its models. The company added: “We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process.” It said it would “welcome developers to continue reviewing ZCode and reporting potential issues” and would offer rewards scaled to the severity of whatever is found.
Third-Party Audits and the Fix
To back up its claims, ZCode brought in two outside reviewers: the China Academy of Information and Communications Technology (CAICT) and Beijing-based security firm NSFOCUS. Both assessments, according to the company, concluded that all previously uploaded data has now been deleted. Z.ai also confirmed the Repo Wiki feature responsible for triggering the uploads has been removed entirely.
Open Source Release and Researcher Pushback
As part of its response, ZCode open sourced the entire project on GitHub, a move it framed as “placing the code under community scrutiny and making ZCode more open and transparent.” The company said a full security assessment report would follow, adding once more: “we sincerely apologize and welcome continued scrutiny from the community.”
Ferstar reviewed the newly public code and confirmed the Repo Wiki functionality no longer appears anywhere in it. But the researcher’s praise came with a sharp caveat, as he criticized Z.ai for wiping the commit records and the original source code that ZCode had used to upload files before the patch went in. Erasing that history makes it harder for outside developers to independently trace exactly what the tool did before the fix, or to verify the company’s account of the incident on their own terms.
Z.ai’s Standing in the Global AI Race
The incident lands at an awkward moment for a company that has been building itself into one of China’s most closely watched AI players. Z.ai, formerly known internationally as Zhipu, grew out of Tsinghua University’s Knowledge Engineering Group research lab in 2019 and has since become one of the most heavily backed large language model companies in China. It holds the distinction of being the first AI company of the post-Gen AI era to launch and later list on the Hong Kong Stock Exchange, a step ahead of older Chinese tech giants like Alibaba and Baidu, which went public long before the current AI boom.
Z.ai has also leaned on technical bragging rights to build credibility. Last month, the company claimed its newest model, GLM-5.3, performs on par with the most advanced systems from Anthropic and OpenAI when it comes to hunting for security vulnerabilities. It has separately claimed credit for building the first advanced AI model trained entirely on Chinese-made Huawei hardware. Reports have also suggested that Anthropic and OpenAI have raised concerns about the growing capabilities of models from Z.ai and rival Moonshot, at a time when the US government is reportedly weighing restrictions on access to them.
That backdrop is exactly why a data-handling misstep like this one carries extra weight. A company positioning itself as a credible security-conscious challenger to Western AI labs now has to explain why its own coding tool moved developer data without permission or a way to say no. For any team that had already installed ZCode on projects containing proprietary code, the episode is a reminder that the convenience of AI-assisted development tools can come with data exposure risks that aren’t always visible until someone goes looking.
FAQ
What did Z.ai’s ZCode tool do that caused concern?
ZCode was found packaging and uploading entire user workspaces, including project histories, to Alibaba Cloud without user knowledge or consent.
Could users prevent their data from being uploaded by ZCode?
No, users had no option to disable this uploading behavior, and it was not disclosed in ZCode’s privacy policy.
Has all the uploaded user data been deleted?
According to third-party assessments by CAICT and NSFOCUS, all previously uploaded data has now been deleted.
What steps has Z.ai taken to improve security after the incident?
ZCode apologized, removed the problematic Repo Wiki feature, committed to a vulnerability reporting and reward process, and open sourced the entire project for transparency.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

2 hours ago
40







English (US) ·