Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant, ZCode, was silently uploading local workspace data to external servers without explicit user consent.
On Friday an independent Chinese technical blogger known as Ferstar inspected a local directory in ZCode and found a compressed file of 313 megabytes pending upload to Alibaba Group Holding’s cloud storage service after failing 564 times, while a smaller 15-kilobyte file had been successfully sent.
ZCode data and encryption
Both files were encrypted, Ferstar said. According to visible filenames, the larger archive contained a snapshot of a commercial project he was working on, including the project’s Git history. He reported that the archive could not be opened by him or by the ZCode client and could be decrypted only with a private key held on Z.ai’s back end.
Company response and reputational impact
Z.ai, also known as Zhipu AI, apologised and patched the vulnerability. Developers said the incident was likely to weaken the company’s reputation, especially at a time when cybersecurity is becoming a central issue in the AI industry.

