Overview
- Developers reported that ZCode had uploaded local Git repositories to overseas cloud servers without consent, prompting Z.ai to apologise and disable some assistant features.
- Z.ai traced the problem to a default 'Codebase Indexing' feature, said it patched the vulnerability, and offered a zero-data retention mode to stop further uploads.
- The firm open-sourced the ZCode assistant running GLM-5.3 and cited an industry-affiliated think tank and NSFOCUS for an assessment that, it says, found uploaded code was deleted.
- Users remain sceptical because uploaded files were encrypted with a backend private key controlled only by Z.ai, which blocks independent checks that the files were removed.
- Chengming Technology retracted its earlier claim of sensitive data exposure and the incident has fed broader policy and trust questions about defaults, disclosure, and auditability for AI developer tools.