What's Happening?
Z.ai, a company known for its AI models, is under scrutiny after a Chinese developer discovered that its ZCode client was by default uploading encrypted snapshots of his commercial project, including its Git history, to Alibaba's cloud storage. The developer,
Ferstar, found a 313MB encrypted archive that had failed to send 564 times, and a smaller file that had already been uploaded. A critical detail is that Ferstar could not decrypt his own file, nor could the ZCode client, because the private key resides on Z.ai’s back end. The upload feature was reportedly on by default, with no option to disable it. Z.ai issued an apology, stating the issue was resolved and attributed it to ZCode’s code repository indexing feature, which supports session checkpoint recovery and version rollback. They claimed that generating a Wiki page in the cloud could trigger a repository upload and that the feature was on by default after launch. Alibaba, which owns the South China Morning Post, did not respond to requests for comment.
Why It's Important?
This incident raises significant concerns about data privacy, intellectual property, and the security practices of AI-powered development tools. The unauthorized and encrypted upload of a developer's entire commercial project, including sensitive Git history, to a third-party cloud service without explicit consent or user control, represents a major breach of trust. The fact that only Z.ai can decrypt the uploaded data means users have no way to verify what data was collected, how it was used, or if it was truly destroyed as claimed. This situation highlights a critical vulnerability in the rapidly evolving field of AI coding agents, where the gap between what these tools are trusted with and what they are audited for is a standing industry weakness. For businesses and individual developers, the risk of proprietary code and sensitive information being exposed or misused could have severe financial and competitive consequences. This event could lead to increased scrutiny of AI development tools and their data handling policies, potentially impacting their adoption and regulatory oversight.
What's Next?
Z.ai has stated that the problem is resolved and that uploaded data is destroyed immediately after a Wiki page is generated. However, the developer, Ferstar, has questioned how this can be verified, given that only Z.ai can access the encrypted data. Moving forward, there will be pressure on Z.ai to provide transparent and verifiable proof that such uploads have ceased and that user data is secure. This could involve releasing ZCode’s codebase for third-party assessment, as Z.ai has promised, and ensuring the component responsible for packaging the workspace is included. Users and industry observers will be watching for independent confirmation that the uploads have stopped. Furthermore, Z.ai's privacy policy, which currently describes collecting files submitted through conversation but not repository snapshots, will need to be updated to accurately reflect its data collection practices. This incident may also prompt other companies developing AI coding tools to review and enhance their data privacy and security measures.
Beyond the Headlines
This event exposes a deeper ethical and security dilemma in the age of AI-driven development. The default activation of a feature that uploads sensitive user data, coupled with the inability of users to decrypt or control their own information, challenges the fundamental principles of data ownership and digital autonomy. The incident draws parallels to previous cases, such as Grok Build uploading Git repositories, suggesting a systemic issue within the AI tool development industry regarding transparency and user control. The cost of this breach is not just financial but also a significant erosion of community trust, which is crucial for the adoption of new technologies. While Z.ai has built a reputation on open-sourcing its models, this incident reveals a potential disconnect between its open-source philosophy and the proprietary software components installed on users' machines. This could trigger a broader re-evaluation of how AI tools are designed, deployed, and regulated to ensure user privacy and data security.













