Z.AI admits ZCode silently uploaded user files without consent
China's second-largest AI company apologized after developers discovered its coding assistant exfiltrated 313MB of workspace data to Alibaba Cloud.
What to know
- Z.AI's ZCode coding assistant secretly compressed and attempted to upload 313MB of user workspace files to Alibaba Cloud 564 times without consent or user awareness.
- The upload mechanism was enabled by default with no user option to disable it; filenames remained visible despite file encryption, potentially exposing sensitive project details.
- Z.AI apologized and claims to have fixed the issue, but a Chinese robotics firm has already banned Z.AI tools internally due to security concerns.
- The company pledged to open-source ZCode's codebase for independent third-party review to rebuild trust.
“On Friday, it apologized and said it had fixed the uploading of user files and data without consent. Moreover, it has been assuring users that any data uploaded to its cloud service has been destroyed.”
Z.AI (via reporting) · Tom's Hardware ↗
Z.AI (Zhipu AI) AI company, ZCode developerFerstar Developer/bloggerFeng Ruohang Tech blogger
How it unfolded 2 developments, newest first · click a bar or a number to jump articles
-
1
Chinese robotics company bans Z.AI tools over security concerns
An unnamed software engineer at a leading Chinese robotics company disclosed that Z.AI's tools have been internally banned due to security concerns, signaling organizational loss of trust in the platform.
-
2
Developers report Z.AI's ZCode uploading local files without consent
Prominent developers Ferstar and Feng Ruohang publicly raised alerts about ZCode silently compressing and uploading their local workspace files to Alibaba Cloud storage without authorization. Ferstar's analysis showed 313MB of files compressed into an archive with 564 failed upload attempts and one successful 15KB transfer; filenames remained visible despite encryption, exposing project details.
“ai 's firefighting exercise began after a number of prominent devs raised flags about their local files and data being uploaded to online servers without their consent.”
— Tom's Hardware · source -
first by Tom's Hardware, 6d ago
-
-
background
Z.AI apologizes and claims to have fixed the upload issue — Z.AI publicly addressed the security concerns, apologizing for the unauthorized file uploads and stating it had fixed the problem. The company assured users that data uploaded to its cloud service had been destroyed and announced plans to open-source ZCode's codebase and invite third-party reviewers to assess it.