Z.ai apologises after ZCode uploaded entire user workspaces to cloud storage

← Back to the feed

Z.ai apologises after ZCode uploaded entire user workspaces to cloud storage

The Register · 60 minutes ago

Z.ai has apologised after developers discovered that its ZCode programming tool packaged entire user workspaces, including project histories, encrypted them and uploaded them to Alibaba Cloud. The incident raised serious privacy and security concerns because users could neither access nor delete the files, while the practice was allegedly not disclosed or optional.

ZCode said the data had not been used to train its models and claimed external reviews found that all previously uploaded material had been deleted after the Repository Index feature was removed. It has open-sourced the project and promised a vulnerability-reporting process, although researcher Ferstar criticised the company for deleting commit history and pre-patch upload code. Z.ai, formerly Zhipu, is a major Chinese AI company that recently became the first post-generative-AI Chinese firm to list on Hong Kong’s stock exchange.

  • ZCode uploaded users’ complete workspaces without clear disclosure or an opt-out.
  • Z.ai says the data was deleted and never used for training.
  • The tool has been open-sourced for wider security scrutiny.

AI Asia Technology World

Read the full article at the source →

Originally published by The Register as “Z.ai says sorry for slurping up your code, open sources ZCode”.