Threat · curated 22 Sep 2026
Z.ai says sorry for slurping up your code, open sources ZCode
First reported theregister.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
ZCode's silent workspace exfiltration shows how AI coding assistants can quietly ship a developer's entire codebase and history to third-party cloud storage without consent, creating a serious source-code data-leakage risk.
Z.ai apologized after researchers found its ZCode code-generation harness silently packaging entire user workspaces — including full project histories — git-encrypting them and uploading them to Alibaba Cloud, with the decryption key held only by Z.ai's server so users could neither access nor delete the files. Researcher Ferstar traced the behavior to ZCode's Repository Index functionality, noting there was no opt-out and no disclosure in the privacy policy; Z.ai says the data was not used for training and has since been addressed following external audits.