LATEST NEWS
SELECTED FOR YOU

Z.ai open-sources ZCode after tool uploaded local files without consent

ByOpeyemi OlanrewajuOpeyemi Olanrewaju 3 mins read
Z.ai named as maker of Ox Alpha, the stealth coding model that gripped developers
  • Z.ai’s ZCode coding assistant was caught silently uploading developers’ local files, including full Git repositories, to Alibaba Cloud without consent.
  • The company has apologized, patched the flaw and open-sourced the tool.
  • The uploaded archives were encrypted with a key only Z.ai holds, so its claim that the data was deleted cannot be independently verified.

Z.ai, the Chinese company behind the GLM model family, has open-sourced its ZCode coding assistant after fixing a flaw that had been quietly sending developers’ local project files to Alibaba Cloud servers without their permission.

The incident happened on September 18, when an independent Chinese technology blogger known as Ferstar uncovered an issue while inspecting ZCode’s working directory, finding files being prepared for upload to Alibaba’s cloud storage, the South China Morning Post reported.

The blogger found two encrypted files, including a 313 megabyte compressed archive which was still awaiting transfer after 564 failed upload attempts, and a smaller 15-kilobyte file that had already been sent.

Ferstar said the larger archive contained a snapshot of a commercial project he was developing, including its Git history. He told the SCMP that neither he nor the ZCode client could open the file because it was encrypted with a private key held on Z.ai’s back end.

How ZCode ended up uploading entire repositories

The ‘rebel’ uploads were linked to a repository-indexing feature used for session checkpoints, version rollback and a “Repo Wiki.” The feature was enabled by default after ZCode launched.

Entire repository uploads can be triggered by making a new wiki page within the cloud, and this could expose more than just the files being worked on actively. Git history can also make it easy to identify with certain old credentials and hostnames, which renders a full repository snapshot quite sensitive.

A Shanghai-based developer quoted by the SCMP described the behavior as essentially stealing from users, adding that the possibility of malicious intent was the most troubling part.

What Z.ai says it has changed

Z.ai has apologized for the incident and claims it had stopped the unauthorized uploads. The company also said any data that had been sent to its cloud was destroyed and was never used in the training of its models.

The Chinese AI manufacturer also stated plans to establish a permanent process for reporting product security vulnerabilities, with payouts based on the severity of the issue. It has also invited developers to continue auditing the now-open codebase.

Questions persist over the uploaded data, as outsiders still cannot exactly verify what happened to it.

A similar incident involving xAI’s Grok Build occurred in July, when the coding tool was found uploading entire Git repositories. Elon Musk confirmed that the uploads happened, after which xAI deleted the data and introduced a zero-retention policy along with a privacy endpoint. An independent retest later found that the uploads had stopped.

Z.ai still has not announced any documented changes to its retention policy or allowed any form of independent retesting. The company’s claim that the uploaded data was deleted remains quite difficult for outsiders to verify, with the company also being in control of the only decryption key.

Developers now have to decide whether to trust the tool

The fallout from this incident has continued to spread, and a robotics company has reportedly banned Z.ai’s tools internally, with developers telling the SCMP that the damage to trust could potentially be way more damaging than just the specific bug.

The incident has also affected Z.ai’s stocks in the market. Shares of Z.ai (2513.HK) fell by almost 6% during Monday’s session before recovering to close at 1.8% higher. Z.ai traded at 794 HKD at the time of writing.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Share this article
Opeyemi Olanrewaju

Opeyemi Olanrewaju

Opeyemi specializes in creating and refining high-quality content focused on cryptocurrency, global financial markets and the economy. He graduated from the University of Ibadan with an MBBS degree. He has worked as Editor-in-Chief for his College’s editorial publication and previously at CFA. For over six years, he has helped safeguard uniqueness as news editor at Cryptopolitan.

MORE … NEWS