NewsTradingSentimentEventsCommunityBriefing
Tech

Z.ai Admits ZCode Uploaded Developer Code Without Consent

By Tech Desk · · 2 min read
A stylized illustration of a server rack in a data center with a lock symbol overlay.

Z.ai apologized after its coding tool was found sending entire user workspaces to Alibaba Cloud without permission or disclosure.

Key points

  • Z.ai’s ZCode tool uploaded entire user workspaces to Alibaba Cloud without disclosure or user consent.
  • Users could not delete or view their uploaded data because Z.ai held the only private decryption keys.
  • Third-party auditors CAICT and NSFOCUS confirmed that all previously uploaded data has been deleted.

Chinese AI developer Z.ai has issued a formal apology after it emerged that its code-generation assistant, ZCode, was quietly uploading complete user workspaces to remote servers. The discovery reveals a significant gap in how AI coding tools handle proprietary intellectual property, as developers found their entire project histories being packaged and transmitted without any prior notice or request for consent.

The incident, first reported by The Cryptonomist, highlights the risks embedded in cloud-assisted development environments. While the tool promised to help organize code, it was simultaneously exfiltrating sensitive data to Alibaba Cloud. This breach of trust has forced a rapid response from Z.ai, including the removal of the offending feature and the involvement of independent security auditors to verify that the data is now gone.

Hidden uploads bypass user control

The core issue was not a minor bug but a systematic behavior that could not be disabled. Researcher Ferstar identified that ZCode was encrypting and sending hundreds of megabytes of local data to the cloud. In one specific instance, the tool made 564 separate attempts to transmit a 313MB archive. This happened in the background, meaning developers were unaware that their local files were being copied off their machines.

The situation was exacerbated by the fact that Z.ai held the private decryption keys exclusively. Since users did not possess the keys, they had no way to decrypt the uploaded archives to see exactly what had been taken. Furthermore, they had no mechanism to force the deletion of their own data, leaving them entirely dependent on the company's goodwill to resolve the privacy breach.

Feature flaw triggered data exfiltration

The unauthorized uploads were linked to a specific function called Repo Wiki, which was designed to generate documentation pages for codebases. However, instead of just creating reference material, the feature effectively hoovered up the entire codebase itself. This behavior was never mentioned in ZCode’s privacy policy, leaving developers with no way to opt out or even know that their workspaces were being copied.

Z.ai stated that the data was not used to train its AI models, but the lack of transparency remains a critical failure. The company has now removed the Repo Wiki feature entirely. To address the community's concerns, Z.ai open-sourced the project on GitHub, although researchers noted that the commit history and original upload code were wiped before the release, limiting the ability to fully audit the previous behavior.

Third-party audits confirm data deletion

To validate its claims, Z.ai engaged two external security firms, CAICT and NSFOCUS. Both auditors concluded that all previously uploaded data has been deleted from the servers. The company also announced a new process for reporting security vulnerabilities, offering rewards to developers who identify future issues. This move aims to restore some level of trust, though the incident serves as a stark reminder of the trade-offs involved in using cloud-connected AI tools for sensitive work.

Based on reporting by The Cryptonomist, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories