Z.ai Open-Sources ZCode After Coding Tool Secretly Uploaded Developers' Local Files to Alibaba Cloud

Key Takeaways
- Z.ai's ZCode coding assistant was caught silently uploading developers' local files, including full Git repositories, to Alibaba Cloud without consent.
- The company has apologized, patched the flaw, and open-sourced the tool, but the uploaded archives were encrypted with a key only Z.ai holds, so data deletion cannot be independently verified.
- The incident follows a similar case with xAI's Grok Build in July, raising concerns about developer trust and data security in AI coding tools.
- Z.ai's stock (2513.HK) initially fell nearly 6% before recovering to close 1.8% higher, trading at 794 HKD.
ZCode's Unauthorized Uploads Exposed
Z.ai, the Chinese company behind the GLM model family, has open-sourced its ZCode coding assistant after fixing a flaw that had been quietly uploading developers' local project files to Alibaba Cloud servers without their permission.
The incident came to light on September 18, when an independent Chinese technology blogger known as Ferstar discovered the issue while inspecting ZCode's working directory and found files being prepared for upload to Alibaba's cloud storage, according to the South China Morning Post.
Ferstar found two encrypted files: a 313-megabyte compressed archive that was still awaiting transfer after 564 failed upload attempts, and a smaller 15-kilobyte file that had already been sent.
The larger archive contained a snapshot of a commercial project he was developing, including its Git history. He told the SCMP that neither he nor the ZCode client could open the file because it was encrypted with a private key held on Z.ai's back end.
The Mechanism Behind the Uploads
The unauthorized uploads were linked to a repository-indexing feature used for session checkpoints, version rollback, and a "Repo Wiki". This feature was enabled by default after ZCode launched.
Entire repository uploads could be triggered by simply creating a new wiki page within the cloud, potentially exposing more than just the files being actively worked on. Git history can also make it easy to identify with certain old credentials and hostnames, rendering a full repository snapshot quite sensitive.
A Shanghai-based developer quoted by the SCMP described the behavior as essentially stealing from users, adding that the possibility of malicious intent was the most troubling part.
Z.ai's Response and Remediation
Z.ai has apologized for the incident and claims it has stopped the unauthorized uploads. The company also said any data that had been sent to its cloud was destroyed and was never used in the training of its models.
The Chinese AI manufacturer also stated plans to establish a permanent process for reporting product security vulnerabilities, with payouts based on the severity of the issue. It has also invited developers to continue auditing the now-open codebase.
However, questions persist over the uploaded data, as outsiders still cannot exactly verify what happened to it. The company's claim that the uploaded data was deleted remains quite difficult for outsiders to verify, with the company also being in control of the only decryption key.
Precedent and Industry Implications
A similar incident involving xAI's Grok Build occurred in July, when the coding tool was found uploading entire Git repositories. Elon Musk confirmed that the uploads happened, after which xAI deleted the data and introduced a zero-retention policy along with a privacy endpoint.
An independent retest later found that the uploads had stopped. Z.ai still has not announced any documented changes to its retention policy or allowed any form of independent retesting.
The fallout from this incident has continued to spread, and a robotics company has reportedly banned Z.ai's tools internally, with developers telling the SCMP that the damage to trust could potentially be way more damaging than just the specific bug.
The incident has also affected Z.ai's stocks in the market. Shares of Z.ai (2513.HK) fell by almost 6% during Monday's session before recovering to close at 1.8% higher. Z.ai traded at 794 HKD at the time of writing.
Coinasity's Take
The ZCode debacle underscores a critical lesson for the crypto and AI industries: trust is the ultimate currency. While Z.ai's move to open-source the tool and apologize is a step in the right direction, the inability to independently verify data deletion—due to the company holding the sole decryption key—leaves a lingering cloud of doubt. For developers and investors alike, this incident highlights the importance of transparency and user consent in tooling.
As AI and blockchain converge, projects that prioritize security audits and open-source verification will stand out. Z.ai's stock recovery suggests markets may be forgiving, but reputational damage in the developer community can be far more lasting. The crypto space, built on principles of decentralization and trustless systems, should demand nothing less than full accountability.
DISCLAIMER
This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments involve substantial risk and extreme volatility - never invest money you cannot afford to lose completely. The author may hold positions in the cryptocurrencies mentioned, which could bias the presented information. Always conduct your own research and consider consulting a qualified financial advisor before making any investment decisions.











