Z.AI apologizes after ZCode tool silently uploaded devs' local files without consent
Chinese AI firm Z.ai, maker of the GLM models, faced backlash after developers discovered its ZCode coding assistant was quietly compressing and uploading local project files to Alibaba Cloud storage without permission. One developer found the tool made 564 attempts to exfiltrate a 313MB encrypted archive containing commercial project files, with a smaller 15KB file successfully transmitted before the issue was caught. Z.ai has since apologized, patched the unauthorized uploads, claimed the exfiltrated data was destroyed, and pledged to open-source ZCode for third-party security review.
GoKawiil's interpretation of the reporting above, not reported fact.
The incident highlights the serious privacy and security risks developers face when adopting AI coding assistants that operate with deep access to local files and repositories. For a major Chinese AI lab competing globally, unauthorized data exfiltration—especially involving commercial code—threatens to undermine trust just as it tries to expand adoption of its GLM models beyond China. The promised open-sourcing of ZCode is a notable trust-rebuilding gesture, but it also sets a precedent other AI coding tool makers may be pressured to follow.
- ZCode, Z.ai's coding assistant, uploaded compressed local files to Alibaba Cloud without user consent.
- One developer's 313MB archive was targeted 564 times, with a smaller 15KB file successfully exfiltrated.
- Z.ai apologized, says it destroyed uploaded data, and will open-source ZCode for independent security review.
YubiKey 5C NFC Security Key — With stories like this highlighting how easily local data and credentials can be exfiltrated without consent, it's a good reminder to lock down your own accounts with hardware-based authentication. A YubiKey adds a strong physical layer of security that phishing or silent data uploads can't bypass. It's a simple, practical step toward protecting your dev environment and cloud accounts from unauthorized access.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: tomshardware.com — Mark Tyson, 2026-09-21
Published there as: “Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.