Chinese AI company Z.ai, the creator of the GLM models, ran into a serious privacy issue: its coding agent ZCode was reportedly packaging users' projects and attempting to upload them to the cloud without clear user notification.
💬 Developer ferstar discovered an encrypted 313 MB archive containing 42,411 files from a commercial project.
⏺ Almost 87% of the archive was Git history meaning it included not just the current code, but the project's change history.
⏺ ZCode reportedly made 564 attempts to upload the archive to Alibaba Cloud. Most attempts failed, but a smaller archive from another project did reach the server.
💬 The decryption key was stored on Z.ai's side, meaning the user couldn't independently inspect the contents of the copy.
Z.ai apologized and said the behavior was related to its Repo Wiki feature, which generated a wiki from the project. The company said the data was supposed to be deleted after processing, later released ZCode's code and removed Repo Wiki.
But one major question remains: how long did this behavior exist, and how many projects were affected?
Bottom line:
An AI agent can access the same files you give it access to. So the question isn't only how well it writes code it's also where it sends your data.
➡️ Discuss in the chat 💬
🔗 Chat • X • TonTrader