Chinese AI giant Z.ai issued an apology on Monday after developers discovered its code generation tool was secretly packaging and uploading user workspaces to cloud storage. The incident mirrors a similar controversy involving Elon Musk's xAI and its Grok product in July.
The affected software, known as ZCode, was caught git-encrypting entire user workspaces and complete project histories before shipping the data to Alibaba Cloud. Users immediately flagged a severe security barrier because the private key required to decrypt the data stayed strictly under Z.ai control. This design left developers unable to access or delete the files uploaded by the tool.
ZCode explained that the core problem stemmed from its Repository Index functionality. This specific function triggered file uploads automatically after a feature called Repo Wiki generated pages in the cloud. The company stated that the harvested data was never used to train its artificial intelligence models.
Z.ai formerly operated internationally under the name Zhipu. The startup spun out from Tsinghua University's Knowledge Engineering Group research lab in 2019 and stands as one of the most heavily backed large language model companies in China. It holds the distinction of being the first post-Gen AI era startup to launch and subsequently IPO on the Hong Kong Stock Exchange.
Last month, Z.ai asserted that its GLM-5.3 model matches the security vulnerability hunting capabilities of top tier systems from OpenAI and Anthropic. The business also claims to have built the first advanced model entirely on Chinese Huawei hardware. Meanwhile, OpenAI and Anthropic have reportedly raised concerns regarding models from Z.ai and Moonshot, prompting the United States government to consider access restrictions.
Following the backlash, ZCode removed the Repo Wiki feature and open sourced the entire project on GitHub to place the code under community scrutiny. Ferstar confirmed that the open sourced code lacked any signs of the Repo Wiki implementation, though they criticized Z.ai for wiping commit records and the original source code used for pre-patch uploads.
Z.ai stated that it tasked the China Academy of Information and Communications Technology and Beijing security firm NSFOCUS to investigate the product following the implemented changes. The company claimed external assessments concluded that all previously uploaded data has now been deleted. Z.ai also announced plans to establish an ongoing vulnerability reporting process and distribute rewards based on issue severity.
The full security assessment report will be released soon.



