Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

reuters+1kucoin+1finance.biggoZ.AI, the Chinese artificial intelligence company behind the GLM model family, open-sourced its ZCode coding assistant on Monday after the tool was caught silently packaging and uploading developers' local workspace data to cloud servers without consent.
The move came alongside results from third-party security audits conducted by the China Academy of Information and Communications Technology (CAICT) and NSFOCUS, which confirmed that the Alibaba Cloud storage bucket used to receive the uploads now contains zero data and that all relevant data objects have been permanently deleted.kucoin+1
The controversy began on September 18, when an independent Chinese technology researcher publishing as "ferstar" discovered that ZCode had packaged 42,411 files from a local workspace into a 313MB encrypted archive and made 564 failed upload attempts to Alibaba Cloud. The .git directory accounted for 86.6% of the payload, with Git LFS caches alone totaling 196.1MB.aiweekly+1
The files were encrypted using a server-supplied RSA public key and AES-256-CTR, meaning neither the user nor the ZCode client could decrypt them — only Z.AI's backend held the private key. Z.AI attributed the issue to a "Codebase Indexing" feature that had been enabled by default after launch, which could trigger full repository uploads when generating a cloud-based "Repo Wiki" page.the420+2
Z.AI apologized and released ZCode's source code under an Apache 2.0 license on Monday, according to Reuters. The company said ZCode version 3.14.0 has completed security remediation, removing the Repo Wiki feature entirely and severing the local repository snapshot generation and upload pathways.reuters+2
Z.AI also announced plans to establish an ongoing vulnerability reporting and response process, with rewards based on severity, and invited developers to review the open-sourced code. Its MaaS platform will soon introduce a "no data retention" option for standard model calls, according to TechNode.thestandard+1
Despite these steps, outside parties still cannot independently verify that uploaded data was never used for model training, as Z.AI retained exclusive control of the decryption keys. A Chinese firm, Chengming Technology, has issued a formal legal demand requiring Z.AI to respond in writing by October 10 with a complete data processing inventory and proof of deletion.finance.biggo+2
Shares of Z.AI on the Hong Kong Stock Exchange fell as much as 6 percent on Monday before recovering to close 1.8 percent higher.thestandard