Chinese AI firm Z.ai, maker of the GLM models, faced backlash after developers discovered its ZCode coding assistant was quietly compressing and uploading local project files to Alibaba Cloud storage without permission. One developer found the tool made 564 attempts to exfiltrate a 313MB encrypted archive containing commercial project files, with a smaller 15KB file successfully transmitted before the issue was caught. Z.ai has since apologized, patched the unauthorized uploads, claimed the exfiltrated data was destroyed, and pledged to open-source ZCode for third-party security review.
tomshardware.com
· 2026-09-21
A developer investigating unexpected disk usage discovered that Zhipu's ZCode AI coding app compresses and encrypts entire project workspaces—including .git history, LFS caches, reflogs and configs—and uploads them to Aliyun OSS without visible user consent. The encryption uses a server-issued RSA public key while the private key stays server-side, meaning neither the user nor the local client can ever decrypt the archives sitting on the user's own disk. In the investigated case, a 313MB encrypted baseline snapshot of a commercial project had failed to upload 564 times and remained queued locally.
blog.ferstar.org
· 2026-09-18
Chinese AI company Z.AI, previously known as Zhipu AI, is seeking to raise $5 billion in fresh capital. The move follows a $4 billion share placement the company completed just two months earlier in July.
wsj.com
· 2026-09-13