Threat · curated 22 Sep 2026

Z.ai says sorry for slurping up your code, open sources ZCode

Coverage timeline

22 Sep 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

ZCode's silent workspace exfiltration shows how AI coding assistants can quietly ship a developer's entire codebase and history to third-party cloud storage without consent, creating a serious source-code data-leakage risk.

Z.ai apologized after researchers found its ZCode code-generation harness silently packaging entire user workspaces — including full project histories — git-encrypting them and uploading them to Alibaba Cloud, with the decryption key held only by Z.ai's server so users could neither access nor delete the files. Researcher Ferstar traced the behavior to ZCode's Repository Index functionality, noting there was no opt-out and no disclosure in the privacy policy; Z.ai says the data was not used for training and has since been addressed following external audits.