Z.ai's ZCode assistant was quietly uploading encrypted snapshots of developers' projects, including Git history, to Alibaba's cloud
A Chinese blogger found a 313 MB archive of his commercial project queued for upload after 564 failed attempts, encrypted with a key only Z.ai holds. The company has apologised and patched the behaviour, but developers say the damage to trust is done.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
Z.ai, the Chinese AI company also known as Zhipu AI, is facing a trust crisis after developers discovered that its coding assistant ZCode was silently uploading local workspace data to external servers without explicit user consent. The company apologised and patched the behaviour, but developers told the South China Morning Post the incident is likely to weaken its reputation at a time when cybersecurity is becoming a central issue in the AI industry. The issue surfaced on Friday when an independent technical blogger known as Ferstar inspected a local ZCode directory. He found a 313 megabyte compressed file pending upload to Alibaba Group's cloud storage after failing 564 times, and a smaller 15 kilobyte file that had already been sent. Both were encrypted. According to visible filenames, the larger archive held a snapshot of a commercial project he was working on, including its Git history. Ferstar said neither he nor the ZCode client could decrypt the archive because the private key sits on Z.ai's back end. The upload was on by default with no option to turn it off. Another blogger, Feng Ruohang, said he had seen at least three files uploaded. TNW noted that a Git directory holds every change since a project began, including credentials that were committed and later revoked, abandoned branches, internal hostnames and commit messages. A Shanghai-based developer told the Post the behaviour was like stealing from users and that the apparent intent was what concerned him. Alibaba, which owns the Post, did not respond to a request for comment on Sunday.
Sources
- South China Morning PostChinese AI firm Z.ai faces reputation hit after unauthorised uploads
- TNW | Artificial-intelligenceOnly Z.ai can open the code Z.ai uploaded