If you run code on an AI coding assistant, you probably assume your local repositories stay local. Z.ai’s ZCode product broke that assumption last week, and the fallout is still unfolding.
What Happened
Beijing-based Z.ai, also known as Zhipu, confirmed that its ZCode assistant was uploading entire local Git repositories to Alibaba Cloud without user consent. The source was a feature called Codebase Indexing, which was enabled by default. There was no toggle to turn it off, and Z.ai’s privacy policy did not disclose the behavior at the time.
One affected company, Chengming Technology, posted on Chinese social media that six of its coding workspaces had been uploaded, including complete source code, database passwords, and employees’ personal information. Chengming later retracted its statement, saying it had “wrong evidence.”
The Verification Problem
Z.ai initially apologized on Friday and said the uploaded data had been deleted. Developers pushed back: the data was encrypted with a backend private key held only by Z.ai, which meant users could not open or independently verify their own files. They had to take Z.ai’s word for it.
Z.ai then commissioned an independent security assessment from the Chinese industry ministry’s affiliated IT standards think tank and cybersecurity firm NSFOCUS. Both concluded that users’ code data had been deleted and was not retained by the cloud platform. Z.ai said it has also enabled a zero-data retention feature on the assistant going forward.
Where Things Stand
Z.ai has patched the vulnerability, disabled the implicated features, and open-sourced the ZCode assistant, which runs its GLM-5.3 model. The company pledged to publish the full security assessment report and said it welcomes continued community review.
The disclosure is notable. Public security breach admissions from Chinese AI labs are rare. Z.ai is the same lab that last month became the first Chinese lab to explicitly delay an AI model release for safety reasons, holding GLM-5.3 for a two-week review before shipping it.
The Operator Takeaway
Default-on data collection in developer tools is a real risk. If you use any AI coding assistant, check what telemetry and indexing features are active before you connect it to a codebase that contains credentials, proprietary logic, or client data. Assume nothing is opt-in until you verify it yourself.
