News Weekly
LV 10 XP
0% read
Your progress · 0/5 chapters
About 6 min total
ScienceISSUE #2 · STORY 12 OF 20Sep 21, 2026CONFIRMED

A coding app uploaded your files, then opened its source

Z.ai's ZCode tool was found quietly uploading developers' full project folders to the cloud. Days later it open-sourced the app and promised to keep no data.

Illustration: a translucent data vault with clean geometric filing cells stands open, its streams of light and fragments flowing out and dissolving into air — an artistic impression of a company promising zero r…

Read it your way

CHAPTER 1 · THE 60-SECOND VERSIONPicked for Explorers

What the app was caught doing

A security researcher found that ZCode sent user files to the cloud without clear consent. Z.ai then patched the app and published its code.

A hidden upload featureA default-on feature packaged a developer's whole project folder and tried to send it out.
It grabbed your Git historyOn one machine the 313MB archive was 86.6% Git history, not just current code.
You could not open itThe snapshot was encrypted with a key held only by Z.ai's own servers.
The company respondedZ.ai apologized, patched the app, open-sourced it and enabled a zero data retention mode.
Finish this chapter for +15 XP
Flip the switch

From secret uploads to open code

YOU GETOpen sourceThe full client is now on GitHub under Apache-2.0.
YOU GETNo upload pathThe re-audited code only does local Git work now.
YOU GETZero-retention modeA new setting promises not to keep user data.
Your next move · as a Explorer

Audit the coding tools you use

1List which AI coding features are on by default
2Upgrade ZCode past version 3.14.0 now
3Rotate any secrets stored in your Git history

Switch your reading mode at the top to see a different next move.

Tap to open

Things to keep an eye on

Pop quiz · unlock the Audit Ace badge

Did it stick?

0/3
What did ZCode's default feature upload?+20 XP
Which license did ZCode go open source under?+20 XP
Who can truly confirm the uploaded data was deleted?+20 XP
Your call · +5 XP

Does open-sourcing the app fix a data upload incident?

Deep dive

The full research, labeled and sourced

CONFIRMED30 sources · 65 min
Story identity
  • FACT (CONFIRMED). ZCode is the desktop/browser/terminal AI coding workbench of Z.ai (formerly known internationally as Zhipu), built around Z.ai's GLM models (GLM-5.3 current family). It launched ~July 2026 as a proprietary client.
  • FACT (CONFIRMED). On 2026-09-21 (Monday), Z.ai open-sourced ZCode on GitHub under the zai-org organization with an Apache-2.0 license: https://github.com/zai-org/ZCode (verified directly during this research: public, Apache-2.0, 6.5k stars / 1.9k forks, only three commits on main as of 2026-09-23, README noting v3.14.3).
  • FACT (CONFIRMED). On the same day, Z.ai stated it had enabled a zero-data-retention feature on the ZCode coding assistant and said data uploaded before the fix had been deleted and never used for model training (Reuters wire, 2026-09-21; ZCode X account post).
  • FACT (CONFIRMED). The trigger was a security/privacy incident: ZCode's default-on "Codebase Indexing" feature packaged and attempted to upload users' local workspaces — including full Git history — to Alibaba Cloud storage (OSS bucket zcode-prod) without consent. Discovered by independent researcher Ferstar, whose teardown of 2026-09-18 found a 313MB encrypted snapshot of a commercial project (42,411 files; 86.6% of payload from .git) with 564 failed upload attempts on his machine and one 15KB snapshot already successfully uploaded.
  • COMPANY CLAIM. Z.ai's claimed independent assessments (China Academy of Information and Communications Technology, CAICT; security firm NSFOCUS) concluded the OSS bucket held zero data and that the data had been deleted. Full assessment report promised but not yet published.
  • Evidence-status boundary: The incident behavior is INDEPENDENTLY VERIFIED (reproducible reverse-engineering by multiple researchers: Ferstar, Feng Ruohang, J.F. Zhang, plus independent write-ups on dev.to, runtimewire, SamCodeMan). The deletion claim is COMPANY CLAIM only: the uploaded archive was encrypted with a key whose private half lived only on Z.ai's backend, so only Z.ai can confirm deletion (TNW headline: "Now only Z.ai can say it was deleted").

✓

What happened?

🎓 For Explorer

A timeline of confirmed events:

  • 2026-07: ZCode launched (~July) as Z.ai's agentic coding workbench (devops.com coverage of debut; GitHub repo context).
  • 2026-09-17: Developers began reporting on X and RedNote that ZCode was uploading local workspace data to external servers without explicit consent (Tech in Asia).
  • 2026-09-18 (Friday): Researcher Ferstar published a teardown (blog.ferstar.org) showing: while signed in, ZCode silently packaged the entire working directory into an encrypted snapshot; one 313MB archive covering 42,411 files of a commercial project, 86.6% of it .git data (196.1MB LFS objects, 102.2MB commit-history objects, 0.6MB logs), had failed 564 upload attempts; a smaller 15KB snapshot (538 files of a public repo) had uploaded successfully. The archive was encrypted with AES-256-CTR wrapped via RSA-OAEP-SHA256 using a server-supplied public key — the private key exists only in Z.ai's cloud, so neither the user nor the client could decrypt it. Z.ai apologized in its official Feishu community the same day, blamed the default-on "Codebase Indexing" feature (used for session-checkpoint recovery, version rollback, Repo Wiki), said it had patched the issue, pledged to open-source ZCode, and offered compensation as a weekly quota reset.
  • 2026-09-19/20: SCMP (Chang Minxiao, Chen Wency) reported the account; TNW published "Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted." Chinese tech media covered a corporate escalation (Chengming Technology sent a legal-demand letter claiming six workspaces, source code, DB passwords and employee data had been uploaded) and reported that a leading Chinese robotics company banned Z.ai's tools internally.
  • 2026-09-21 (Monday) — EVENT DATE: Z.ai announced on the official ZCode X account: remediation completed, sincere apology, Repo Wiki removed, the local-repository-snapshot upload workflow disabled and removed in ZCode v3.14.0, the codebase open-sourced on GitHub (Apache-2.0), a zero-data-retention feature enabled on the coding assistant, standing security-vulnerability reporting process with severity-based rewards, and CAICT + NSFOCUS assessments finding the OSS bucket emptied ("zero-data state"). Zhipu's HK-listed stock fell >4% intraday (Chinese media reports). Chengming Technology withdrew its earlier claim the same day, saying it had relied on wrong evidence (Reuters).
  • 2026-09-22/23: Ferstar re-audited the now-public code: the upload pipeline is gone and the remaining checkpoint mechanism does only local Git work — but the published repository carries only three commits (two at first), with the development history and the pre-patch uploader code erased, so prior behavior cannot be independently inspected. The full security-assessment report had not been released as of 2026-09-23. Chinese media reported Zhipu additionally planning "no-retention" controls on its Model-as-a-Service (MaaS) platform. Related context: xAI's Grok Build was caught doing the same thing in July 2026 (uploading entire Git repositories) and responded with deletion + documented zero-retention policy + privacy endpoint — the template Z.ai is now following.

Δ

What changed?

  • ZCode went from closed-source to open-source (Apache-2.0) — the entire workbench client (Electron desktop, Web client, backend server, shared UI, Agent CLI/runtime) published under https://github.com/zai-org/ZCode.
  • The exfiltrating behavior was removed: Repo Wiki feature deleted; the workflow that generated and uploaded local repository snapshots disabled, with the fix shipped in ZCode v3.14.0 (now v3.14.3).
  • A zero-data-retention feature was enabled on the ZCode coding assistant (Reuters: "Z.ai said it had enabled a zero-data retention feature on the coding assistant used by developers and tech enterprises"); Z.ai said previously uploaded data was destroyed and never used in model training, backed (per company) by CAICT/NSFOCUS assessments showing the zcode-prod OSS bucket empty.
  • A standing vulnerability-disclosure process was established — a bug bounty in everything but name, with rewards based on severity.
  • Trust posture changed material: Z.ai, an open-weights-first company, exposed that its client was closed and un-auditable; the open-sourcing converts the client into a community-audited artifact.
  • Planned (not yet live at event date): optional no-retention ("non-retention of content") controls on the MaaS platform — inputs and outputs of standard model calls not statically stored, used only for the current request (Pandaily, DIGITIMES).

↔

Before → Change → After

🎓 For Explorer

BEFORE (until ~2026-09-17/18): ZCode closed-source client; "Codebase Indexing" enabled by default; while signed in, the client packages the whole workspace (working tree + .git history + LFS + reflogs + global config) into an encrypted snapshot and attempts to post it to Alibaba Cloud OSS; settings labeled "Optimize Experience" / "Repo Snapshot Indexing" did not stop capture; deletion of a pending snapshot caused a fresh repack within ~30 minutes; the privacy policy (effective 2026-06-15) described collecting conversation text/files but said nothing about workspace snapshots; the decryption key lived only in Z.ai's cloud.

CHANGE (2026-09-18 → 2026-09-21): Users detect and publicize the behavior (Ferstar, Feng Ruohang, J.F. Zhang); Z.ai apologizes Friday; Monday it patches (v3.14.0), removes Repo Wiki and the upload workflow, enables zero-data retention, claims deletion of uploaded data verified by CAICT/NSFOCUS, and publishes the full source under Apache-2.0.

AFTER (2026-09-22 →): Upload pipeline gone (Ferstar re-audit confirmed); remaining checkpoint mechanism does local Git work only; source is publicly inspectable, but the erased commit history means the pre-patch snapshot/upload code cannot be audited; zero-retention claim rests on Z.ai's word plus company-commissioned assessments; full CAICT/NSFOCUS report unpublished; MaaS no-retention option announced as coming; developer and enterprise trust in Chinese AI coding clients under stress; parallel with July 2026 Grok Build incident widely noted.


⚙

How it works

Technical mechanism (INDEPENDENTLY VERIFIED via reverse-engineering by Ferstar and J.F. Zhang; details corroborated in runtimewire, dev.to, SamCodeMan write-ups):

  • Capture: When a user is signed in, ZCode periodically packages the current workspace directory (the "working directory" plus .git — objects, LFS cache, reflogs — plus global application config) into a compressed snapshot. Trigger sources included a pre-prompt capture and a Repo Wiki update task.
  • Encryption: Snapshot contents encrypted with a random symmetric key (AES-256-CTR); the symmetric key is wrapped with RSA-OAEP-SHA256 using a public key fetched from Z.ai's server (endpoint /api/v1/snapshot/upload-credential). The RPC returns a snapshot ID, storage credentials, size limits and the RSA public key. The private key exists only on Z.ai's backend, so the local ciphertext cannot be decrypted by the user or by the client — an architecture that protects transfer from third parties while guaranteeing Z.ai's backend can read everything.
  • Upload: The client POSTs the encrypted archive directly to Alibaba Cloud OSS (bucket zcode-prod); Alibaba's storage then calls back to Z.ai's backend to register the snapshot. Ferstar's observed archive had failed 564 times (network/credential churn) and sat in a pending local queue; one 15KB snapshot of a public repo had succeeded.
  • No effective off-switch: two UI settings ("Optimize Experience", "Repo Snapshot Indexing") governed downstream data use, not the capture itself; capture ran unconditionally while signed in; deleting a pending snapshot triggered a fresh repack (~30 min later).
  • Fix (v3.14.0): Repo Wiki removed; upload path deleted; the retainable checkpoint mechanism was refactored to local Git operations only with no cloud path (confirmed by Ferstar's post-publication re-audit).
  • Zero retention (claimed): Z.ai says the zcode-prod bucket was emptied/deleted (CAICT: "zero-data state"; NSFOCUS: bucket and objects gone) and that uploaded data was never used to train models; ZCode has an enabled zero-data-retention feature; MaaS no-retention controls are planned for standard model calls.

!

Why it matters

🎓 For Explorer
  • A first-of-kind accountability play by a Chinese AI lab: a front-rank Chinese lab publicly disclosed a security incident, apologized, open-sourced the product and enabled zero retention — "a rare public disclosure of a security breach by a Chinese AI lab" (Reuters), coming days after China's cyberspace regulator updated its AI safety framework (warning about shutdown resistance, evaluator deception, sandbox escape).
  • It defines the "agent silently uploads private files" failure class: coding agents have near-unlimited read access; this incident is the clearest demonstration that capabilities granted to the agent (files, Git history) are also granted to its vendor by default. Git history is where deleted credentials, internal hostnames and abandoned branches live — "a full repository snapshot is quite sensitive" (developer commentary via SCMP).
  • It exposes a verification asymmetry: encrypted-at-rest data held with a vendor-controlled key means the vendor is the only party able to prove deletion. Open-sourcing the client answers a different question than the one users asked.
  • Template for incident-to-transparency conversion: the response sequence (patch → disclose → independent assessment → open source → zero retention → bounty) is a replicable playbook — but the erased commit history shows how open-washing can blunt it (TNW: "The verification problem moved rather than closed").
  • Direct precedent symmetry: xAI's Grok Build in July 2026 uploaded entire Git repos; xAI responded with deletion, a documented zero-retention policy and a privacy endpoint. Z.ai's response mirrors it — a nascent industry norm ("snap-delete solidarity") for agent-vendor data handling.

✦

What became possible?

🎓 For Explorer
  • Independent security auditing of an AI coding client by anyone — the GitHub repo now lets researchers inspect default-enabled behaviors, network calls and encryption before adoption.
  • A community-verifiable baseline for "does this agent exfiltrate?" — Ferstar's re-audit already confirmed the upload pipeline's removal, the first third-party verification of a fix.
  • Enterprise security teams can now do source-level due diligence on ZCode (threat-model, build from source, block telemetry) instead of trusting a binary.
  • Regulatory/precedent setting: a Chinese AI lab has committed to a published security-assessment report, a severity-based bounty, and zero/no-retention features — measurable commitments that can be audited over time.
  • Comparison tooling: customers can weigh Z.ai's open client against closed rivals (Cursor, Copilot, Claude Code) with actual evidence about data flows.

◎

Implications

Technical

  • Default-on ambient capture is a design flaw class, not just a bug: "A bug gets patched, while a default gets decided by somebody" (TNW). Vendors must treat anything network-bound as requiring explicit, user-visible consent regardless of "indexing" intent.
  • Client-side encryption with server-held keys provides no user privacy: the "encrypted" snapshot was fully readable by Z.ai's backend by construction; encryption protected against third parties, not against the vendor. Documented as the key-management lesson (AINave).
  • Git history is the highest-value exfiltrated asset: 86.6% of the payload — credentials, secrets, hostnames, reflogs — vastly outweighs working-tree source. Agent-security audits must treat .git as sensitive data.
  • Sandboxing/permission architecture: the capture ran at host level outside the agent tool loop, requiring only a valid JWT — no tool-level permission prompt could stop it. Consequence: host-level network egress control and filesystem integrity (e.g., immutable checkpoint dirs: chattr +i / chflags uchg worked as a user-side mitigation — SamCodeMan write-up) are the practical defenses.
  • Open-sourcing without history limits forensics: a repo with three squashed commits erases the diffs that would show exactly what the vulnerable code did; reproducibility of the vuln is reduced to researchers' earlier write-ups.
  • Zero-retention verification needs technical mechanisms: without key escrow change or transparent logs, deletion claims remain unprovable; e2e-encryption with user-held keys would be the technnical fix that makes deletion user-verifiable — Z.ai has not adopted it.

Developer

  • Audit your own agent tooling: which features are default-on, what leaves the machine, where keys live (runtimewire/dev.to guides now exist for ZCode specifically).
  • Practical mitigations for any coding agent: run it in a container/VM with network policy; make checkpoint/session dirs immutable; scan .git for secrets; treat the workspace sent to any AI tool as data that reaches the vendor's cloud.
  • Before adopting ZCode: read the now-open source, check config defaults (config/, .env.example), and verify the installed version ≥ v3.14.0.
  • The bounty ("rewards based on the severity of the issues reported") creates an opportunity for security researchers — and the community's auditing of the released code, more than the release itself, will determine whether this repairs trust (explainx.ai analysis).
  • Don't conflate open weights with open client: GLM weights are open but ZCode was closed; the incident is a reminder to check the tool, not the model card.

Enterprise

  • Code exfiltration risk is an enterprise-adjacent liability: a default-on client shipped full repositories — including Git history (secrets, credentials) — to a third-party cloud. Companies that allowed ZCode in engineering chains now face exposure review: rotate credentials, re-audit repos, review account/usage logs (explainx.ai).
  • Vendor-trust processes need to be updated: demand source-level review, network-egress transparency, user-held encryption keys, published retention policies and verifiable deletion (third-party assessments with published evidence), not just assurances.
  • Compliance loops: unauthorized transfers of source code and credentials implicate data-protection and IP obligations (OECD.AI incident classification cites privacy/data-governance and IP harms); enterprises should map AI-dev-tool usage against their DLP and data-governance controls (cross-border transfer questions already raised by affected Chinese firms).
  • Stock/market signal: Zhipu (02513.HK) fell >4% intraday on the incident per Chinese media; brokers (Dongwu Securities) argued fundamental impact is small but trust damage may exceed the bug itself (mitrade/SCMP commentary); a leading robotics company reportedly banned Z.ai tools internally — flag for procurement decisions.
  • Not a Z.ai-only problem: the Grok Build case (July 2026) shows the failure class is industry-wide; enterprises should build a generic "agent data egress audit" checklist.

Strategic

  • Open-source-as-trust-repair: Z.ai converted a closed client into a public artifact as its primary accountability move — an acknowledgement that for AI tools, transparency is now a competitive requirement. Expect rivals (and Chinese labs especially) to pre-empt scrutiny by open-sourcing clients or adding no-retention modes.
  • China-lab disclosure norms shifting: "the rare public disclosure of a security breach by a Chinese AI lab" (Reuters) — precedent set days after China's regulator updated its AI safety framework; positioning relative to US labs (OpenAI/Anthropic "rogue agent" headlines) is now a live narrative.
  • Open weights + open client becomes a wedge: Z.ai's strategy is giving top models away and selling the harness; the harness is now commoditized into open source, sharpening competition against Cursor/Copilot/Claude Code-led workflows and lowering trust barriers for adoption.
  • Geopolitical framing: TNW notes the symmetry with Alibaba banning Claude Code in July over covert data transmission — "the complaint now is that sentence with the countries swapped." Both Beijing and Washington audiences gain new ammunition; US restrictions on Chinese AI access may be reinforced by security incidents.
  • Retention policy becomes a marketing surface: "zero retention" is positioned as a differentiator (Chinese media: "China's strictest data protection mechanism"); it will push the whole market toward no-retention defaults — a genuine strategic shift in how AI vendors sell privacy.

⚠

Risks & limitations

Risks
  • Deletion claim unverifiable (highest residual risk): the archive was encrypted to be readable only by Z.ai's backend; only Z.ai can confirm deletion; the assessments describe the bucket after the fix, not what passed through it before (TNW). If any copy survived (backups, logs, training pipelines), the "zero retention" claim fails hard.
  • Training-data claim: Z.ai says uploaded data was never used for training — a company claim with no independent audit path yet.
  • Open-sourcing without history: wiped commit history prevents forensics; if the squashed release contains latent similar defaults, trust damage compounds.
  • Delayed report: the promised full CAICT/NSFOCUS assessment report has no publication date; indefinite delay would erode the accountability narrative.
  • Incident scope unknown: nobody has stated how long the behavior existed before 2026-09-18 or how many users/workspaces were affected.
  • Legal exposure: affected customers (e.g., Chengming Technology's withdrawn claim; other firms' cross-border-transfer questions) could revisit claims; HK-listed share price and future fundraising (Zhipu reportedly raised >CN¥70bn over two months per HK media) are exposed to sustained negative coverage.
  • Regulatory attention: China's cyber regulator's updated AI safety framework and global agent-security scrutiny (UN panel thematic brief on agents, 2026-09-21) create a regulatory environment where a repeat would be severely penalized.
  • Community counter-narrative: "open source minus the history" reads to security researchers as accountability theater; the Register and TNW both highlighted it within 24 hours.

Limitations
  • Primary-source access: Z.ai's official statements (Feishu, X) were consumed via wire reproductions and major-outlet citations (Reuters, TNW, The Register), not by direct fetch; the X post URL (https://x.com/zcode_ai/status/2101844704933621971) is cited by TNW.
  • Chinese-language press: substantial coverage exists in Chinese (ifeng/凤凰网, chinaz, zaobao, nbd每日经济新闻, cnBeta, 21世纪经济报道 — full list in the OECD.AI record) corroborating the open-source announcement, "0 data retention", OSS bucket emptying and Repo Wiki removal at headline level; this researcher did not read those articles in full, so headline-level corroboration only is attributed.
  • Deletion/retention facts are inherently one-sided: CAICT/NSFOCUS findings are reported by Z.ai; neither full report nor independent reproduction was available by 2026-09-23. These are COMPANY CLAIM, not INDEPENDENTLY VERIFIED.
  • Version/commit drift: the repo now shows three commits and v3.14.3 (README update 2026-09-23); TNW described two commits on 2026-09-22 — counts shift, but the "wiped history" point holds.
  • Fast-moving story: the incident is 5 days old at research time; later reporting may update scope numbers, affected-user counts or the assessment report.
  • No crafted claim of independent confirmation for: number of affected workspaces, duration of exposure before Sep 17, contents of successfully uploaded 15KB snapshots beyond description, and the "robotics company ban" (SCMP-sourced, anonymized engineer).

?

Open questions

  1. How long was the default-on capture active before 2026-09-17, and across what versions?
  2. How many user workspaces were actually uploaded (successfully) versus queued-and-failed?
  3. What happened to every successfully uploaded object — true deletion across backups and logs, or bucket-only clearance? Who outside Z.ai can attest?
  4. When will the full CAICT/NSFOCUS assessment report be published, and will it cover pre-fix data flows?
  5. Was any uploaded data used for model training or product improvement despite the denial?
  6. Why was the commit history wiped, and will the pre-patch snapshot/upload code ever be released for forensics?
  7. Will the pending MaaS no-retention controls be default-on or opt-in, and will they also cover ZCode conversations?
  8. Will ZCode adopt user-held encryption keys or source-level transparency that makes "no retention" technically provable?
  9. What will the erosion of trust cost Zhipu commercially (MaaS/enterprise deals, IPO-era investor confidence)?
  10. Does the Chinese regulator's updated AI-safety framework translate this incident into concrete obligations (e.g., mandatory disclosure windows, retention limits) for Chinese AI tool vendors?

↗

What happens next?

🎓 For Explorer
  • Short term (days/weeks): full CAICT/NSFOCUS report expected; community auditing of the released code will surface findings (the newly announced bounty makes this likely); watch whether the erased commit history becomes a sustained controversy; MaaS no-retention controls rollout announced as "soon".
  • Medium term (quarters): zero/no-retention becomes a standard expectation for AI coding tools; rivals respond (pre-emptive open-sourcing or retention guarantees); enterprises codify agent-egress audits; Chinese regulator follow-up on AI-tool data handling likely.
  • Wildcards: discovery that uploaded data survived somewhere (breaking the deletion claim); a second, related vulnerability in the open code; regulatory fine/action in China; US/geopolitical restriction headlines citing this incident.

★

Editorial takeaway

🎓 For Explorer

This is the strongest story of the week on the agent-security beat, and it has two legs. The first is the failure class: a default-on feature shipped a developer's entire Git history — the part of a repo that keeps all its old secrets — to a vendor's cloud, encrypted in a way the owner couldn't even open. That is the clearest possible illustration that when you give an agent your folder, you may be giving the vendor your folder. The second leg is the response: open-sourcing the client, enabling zero retention and commissioning CAICT/NSFOCUS assessments is a genuine, rare accountability play by a Chinese lab — the first since the Grok Build case to follow the "delete, document, disclose" template. But the release shipped with its history scrubbed, the deletion claim rests on the word of the only party that could have been checked, and the full report hasn't landed. The fix is half-favorable: the upload pipeline is provably gone; whether the data ever really went away remains a matter of trust. That asymmetry — transparency at the code level, opacity at the data level — is the lesson, and it applies to every AI coding tool on the market, not just Z.ai's.


Evidence sources: see sources/S12.md. Research window per RESEARCH_CONFIG.json: 2026-09-18 → 2026-09-22. Event date 2026-09-21 is inside the window.

Illustration: frame: an open translucent data vault with geometric cells, light and fragments streaming out and dissolving — an artistic impression of a zero-data-retention promise following a publicized upload…
⌘

Lab: VERIFY

Steps
  1. Clone and authenticate the artifact

    git clone https://github.com/zai-org/ZCode.git && cd ZCode
    git log --oneline | wc -l        # expect ~3 commits → confirms wiped history (pre-patch code absent)
    head -5 LICENSE                   # expect Apache-2.0
    git remote -v                     # confirm org: zai-org
    
  2. Confirm the upload path is gone (search for the pre-patch pipeline components documented in the incident analysis):

    rg -n "upload-credential|snapshot/upload|Repo Wiki|repo.?wiki" --glob '!pnpm-lock.yaml' .
    rg -ni "aliyun|oss|oss-cn|snapshot" --type-add 'src:*.{ts,tsx,js,rs,json,md}' -t src | head -40
    

    Ferstar's re-audit (per TNW/The Register) found the upload pipeline gone and checkpoints local-only; this command set independently re-checks that claim. Documented pre-patch endpoints (/api/v1/snapshot/upload-credential) should not resolve in the tree.

  3. Inspect config defaults — the incident's root cause was a default-on feature:

    cat config/README.md
    rg -n "optimize|indexing|snapshot|telemetry|authToken|token" config .env.example .env.production .env.development 2>/dev/null | head -40
    

    Verify what is default-on today.

  4. Check the checkpoint mechanism (retained, should be local-only per remediation):

    rg -n "checkpoint" apps/zcode-cli packages | head -30
    

    Confirm no cloud endpoint is referenced from checkpoint code paths.

  5. Baseline network egress inspection (static only): extract hostnames referenced in the client, e.g.

    rg -o "https?://[a-zA-Z0-9.-]+" packages apps --glob '!*.map' | sort -u | head -30
    

    Confirm expected endpoints (z.ai/ZCode service domains) and absence of unexpected storage endpoints in the fixed client.

Expected results / acceptance

  • License = Apache-2.0; commit count small (≈2–3) → history wiped, as reported.
  • Zero matches for upload-credential; no Repo Wiki code; no OSS/upload snapshot orchestration.
  • Checkpoint code paths contain no cloud-upload call.
  • Findings written to a short audit note with date.

Honest caveats to record with the results

  • This verifies the current release, not past behavior — historical code was intentionally withheld (wiped commits), so the incident's original exploit path cannot be forensically reproduced from the repo alone.
  • Absence of an upload path in source ≠ proof data retention is zero; deletion claims still rest on Z.ai + CAICT/NSFOCUS (company-published) and are not auditably checkable by outsiders.

Skill/lab type

VERIFY — static-source security audit of an open-sourced remediation claim (performed manually against the public repo; no network exfiltration test performed).

Lab date: 2026-09-23.

≡

Research sources

Primary Sources (5)
Primary
GitHub — zai-org organization profile - **What it is:** Z.ai's GitHub organization page (ChatGLM, GLM-4.5/5, CogVLM, CodeGeeX, CogView, CogVideoX; Zhipu.ai (Z.ai)).** Org identity; ZCode hosted under official org; context that GLM weights are open while the ZCode harness was closed until now. — ** Primary; organizational identity context. ---Date: ** fetched 2026-09-23
Visit source ↗
Primary
ZCode product documentation — Agents pages - **What it is:** Official ZCode docs describing ZCode Agent (GLM-5.3 family adaptation), workspace, safety confirmations, task/file management and the wiki feature.** How ZCode works, what the agent is, the Repo Wiki functionality context, AGENTS.md conventions. — ** Primary documentation; background for "How it works" (post-incident state of the docs).Date: ** accessed 2026-09-23
Visit source ↗
Primary
ZCode privacy policy (ZCode Docs) - **What it is:** Official privacy policy for ZCode, version effective 2026-06-15; describes collection of conversation text and files "submitted through conversation"; no mention of automatic workspace snapshotting/upload.** The policy gap that made the incident worse — no disclosure of workspace snapshot capture; documents the permissions/optimization-program framing. — ** Primary documentation; supports FACT that the privacy policy did not disclose snapshotting (per TNW reading).Date: ** effective 2026-06-15 (not amended as of 2026-09-20 per TNW)
Visit source ↗
Primary
ZCode official X (Twitter) account — remediation statement - **What it is:** ZCode's official post on X, Monday 2026-09-21: "In response to the ZCode product security issues reported by the community, we have completed the necessary remediation and sincerely apologize to all our users."** Date/venue of the official remediation + open-source announcement; apology; call for community review; severity-based rewards commitment. — ** Primary (company statement). NOTE: URL and wording as cited by TNW and The Register (x.com not directly fetched); consistency across Reuters/TNW/The Register quotes makes the substance CONFIRMED.Date: ** 2026-09-21
Visit source ↗
Primary
GitHub — zai-org/ZCode (official release artifact) - **What it is:** Official Z.ai GitHub repository containing the open-sourced ZCode workbench (Apache-2.0).** Open-sourcing on 2026-09-21 under Apache-2.0; only three commits on `main` (wiped commit history); v3.14.3 current per README (update note 2026-09-23); repo structure (Electron desktop, Web client, server, Agent CLI/runtime); 6.5k stars / 1.9k forks at fetch. — ** Primary; official release artifact (CONFIRMED by direct fetch).Date: ** fetched 2026-09-23 (release announced 2026-09-21)
Visit source ↗
Independent Sources (17)
Independent
Pandaily — "Zhipu Open-Sources ZCode After Repo-Upload Fix; CAICT and NSFOCUS Audits Cite Removals" - **What it is:** TechNode/IT Home-sourced summary: v3.14.0 removed Repo Wiki and snapshot-upload path; CAICT confirmed `zcode-prod` OSS bucket zero-data state; NSFOCUS reported objects/bucket deleted and no remaining client path triggering snapshots or exfiltration; standing vulnerability process with severity-based rewards; MaaS "non-retention of content" applications announced (standard model calls: inputs/outputs not statically stored).** MaaS no-retention plans; CAICT/NSFOCUS finding details (company-published results). — ** Independent reporting of company-published results (COMPANY CLAIM attribution where applicable). ---Date: ** 2026-09-23
Visit source ↗
Independent
Chosun (English) — "Z.AI's ZCode Transmits Development Data, Past Revisions Without Consent" - **What it is:** Korean wire coverage: 313MB / 564 attempts / 15KB; codebase-indexing default-on; Sept 21 announcement of open-source release, suspension of some features, measures to prevent retention of user data.** Non-Chinese/non-US independent confirmation of the zero-retention measures announcement and incident details. — ** Independent reporting.Date: ** 2026-09-22
Visit source ↗
Independent
The News International — "ZCode tried uploading your files 564 times, researcher finds" - **What it is:** Syndicated reporting: Ferstar's discovery (313MB failed-564-times + 15KB uploaded; 42,411 files; key held only on Z.ai servers; no toggle); Feng Ruohang saw at least three files upload; Feishu statement incl. weekly quota reset compensation; compensation detail.** Compensation/credit-reset detail; Feng Ruohang corroboration; quota-reset claim. — ** Independent reporting (secondary syndication of primary research).Date: ** 2026-09-20
Visit source ↗
Independent
SamCodeMan — "The ZCode GLM agent uploads git history, and only Z.ai can decrypt it" - **What it is:** Independent reverse-engineering walkthrough: 345MB/42,411-file workspace → 313MB archive; 62 capture events and 564 failed upload attempts in one session; capture sidecar at host level outside the agent tool loop (only a valid JWT required); user-side mitigation via `chflags uchg` / `chattr +i` on `~/.zcode/v2/checkpoints`.** Host-level capture mechanism; user-side mitigation; corroborates Ferstar's numbers. — ** Independent technical analysis.Date: ** 2026-09-19
Visit source ↗
Independent
DEV Community (jamilxt) — "An AI Coding App Was Silently Uploading Your Entire Git History" - **What it is:** Encryption detail write-up: AES-256-CTR symmetric key wrapped with RSA-OAEP-SHA256 under a server-supplied public key; private key exists only in Zhipu's cloud; "if the goal were crash recovery or sync, the key would live on your machine".** Encryption/envelope architecture; the server-readable-by-design interpretation. — ** Independent technical analysis.Date: ** 2026-09-20
Visit source ↗
Independent
RuntimeWire — "Z.ai's ZCode uploads full Git histories without a working opt-out" - **What it is:** Reverse-engineering details (J.F. Zhang): two-step upload (client requests credentials from `zcode.z.ai` via `/api/v1/snapshot/upload-credential`; encrypts locally; POSTs to Aliyun OSS; OSS callback registers the snapshot); manifest breakdown (LFS 196.1MB, objects 102.2MB, logs 0.6MB, source/docs 46.2MB); no local private key.** Architecture details of the upload pipeline; manifest composition. — ** Independent technical analysis.Date: ** 2026-09-18
Visit source ↗
Independent
DEV Community (techaiwire) — "ZCode uploaded whole Git histories; Zhipu apologizes" - **What it is:** Technical summary of Ferstar's analysis: 313MB / 42,411 files; 86.6% from `.git`; both UI settings ("Optimize Experience", "Repo Snapshot Indexing") failed to stop capture; deletion of a snapshot led to a new one being made.** Technical details of capture behavior; settings-not-effective finding. — ** Independent technical write-up.Date: ** 2026-09-18 (originally published at techaiwire.com)
Visit source ↗
Independent
Tech in Asia — "China's Z.ai faces scrutiny after coding tool uploads local data" - **What it is:** Reporting that developers first reported the uploads on 2026-09-17; Ferstar 313MB queue + 15KB successful upload; Z.ai (Zhipu AI) apologized.** First-report date (Sep 17); core incident numbers; company identity. — ** Independent reporting.Date: ** 2026-09-21
Visit source ↗
Independent
InfoWorld — "Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk" - **What it is:** Enterprise-angle coverage: default-enabled workflow sent entire local repositories to Alibaba Cloud; remediation (feature disabled, codebase opened for scrutiny per post on X); enterprise implications for sensitive source code.** Enterprise-impact framing; confirmation of remediation contents and X-post statement. — ** Independent reporting (enterprise/developer press).Date: ** 2026-09-22
Visit source ↗
Independent
The Register — "Z.ai says sorry for slurping up your code, open sources ZCode" - **What it is:** Coverage of the apology, open-sourcing, CAICT/NSFOCUS claims, Repo Wiki removal, bounty ("rewards based on the severity of the issues reported"), and Ferstar's criticism of wiped commit records; "Grok-esque" parallel to the July 2026 xAI incident; links Ferstar's Chinese-language teardown.** Company statements as reported; commit-wipe criticism; bounty details; CAICT/NSFOCUS naming ("China Academy of Information and Communications Technology" and "Beijing security company NSFOCUS"). — ** Independent reporting.Date: ** 2026-09-22
Visit source ↗
Independent
The Next Web — "Z.ai apologised, open-sourced ZCode, and wiped the commit history" - **What it is:** Post-release verification: repo carries only two commits (three by 2026-09-23), development history and pre-patch uploader code erased; CAICT "zero-data state" and NSFOCUS bucket-deletion claims (company-sourced); Chengming Technology withdrawal; open questions (duration, affected count, report date).** Wiped-commit-history finding; the "verification problem moved rather than closed" conclusion; unanswered-questions list; citation of the ZCode X post URL; v3.14.0 fix contents. — ** Independent analysis post-release.Date: ** 2026-09-22
Visit source ↗
Independent
The Next Web — "Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted." - **What it is:** Analysis of the key-custody asymmetry; Z.ai's Friday statement (via Feishu, reposted on V2EX) traced to Codebase Indexing feature; privacy-policy gap; Grok Build (July 2026) precedent including xAI's zero-retention response; robotics-company ban; GLM-via-Codex fallback commentary.** Encryption/key-custody facts; "statement describes a feature not a bug" framing; xAI precedent for zero retention; policy-gap analysis. — ** Independent analysis.Date: ** 2026-09-20
Visit source ↗
Independent
SCMP — "Chinese AI firm Z.ai faces reputation hit after unauthorised uploads" - **What it is:** Original SCMP reporting of the Ferstar account (by Minxiao Chang and Wency Chen): 313MB archive, Git history, encryption key on Z.ai backend; robotics company internal ban; trust-damage commentary.** Core incident facts; enterprise fallout (robotics company ban — anonymized source); the "damage to trust" narrative. — ** Independent reporting (content reached via TNW's attribution and detail quotes; primary outlet for the researcher account).Date: ** 2026-09-20
Visit source ↗
Independent
OECD.AI Incident Tracker, record 2026-09-18-2cd7 - **What it is:** OECD.AI incident record: "ZCode AI Tool Uploads User Code Without Consent, Prompting Apology and Remediation"; classifies privacy/data-governance and IP harms; links ~40 Chinese and English articles (Reuters, SCMP, TNW, The Register, InfoWorld, ifeng/凤凰网, chinaz, nbd, zaobao, caixin, etc.).** Incident classification, date (2026-09-18), harm types; provides the article index used to locate corroborating coverage (including Chinese-language coverage read at headline level only). — ** Independent institutional tracker (AI-generated summary, flagged as such by OECD).Date: ** record dated 2026-09-18 (accessed 2026-09-23)
Visit source ↗
Independent
KFGO (wire reproduction) — full Reuters text - **What it is:** Full reproduced Reuters text by Laurie Chen, including: "Z.ai said it had enabled a zero-data retention feature on the coding assistant used by developers and tech enterprises"; apology; independent assessment by CAICT-affiliated think tank and NSFOCUS finding data deleted.** Complete wording of the Reuters zero-retention statement; details of the CAICT/NSFOCUS claims. — ** Independent reproduction of wire text; backup for claim wording.Date: ** 2026-09-21 (9:39 AM)
Visit source ↗
Independent
Reuters (Laurie Chen) — "China's Z.ai disables AI coding assistant features after security issue" - **What it is:** Reuters wire: Z.ai disabled some ZCode features after users reported default-on Codebase Indexing uploading entire repos to Alibaba Cloud; open-sourced the assistant Monday; zero-data-retention feature enabled; CAICT/NSFOCUS assessment claims; Chengming Technology withdrawal.** The official announcement contents (zero retention, open sourcing, assessments) as wire-reported; Chengming Technology retraction; Chinese regulator safety-framework context. — ** Independent wire reporting of company statements (COMPANY CLAIM where attribution is Z.ai; CONFIRMED as to what was announced).Date: ** 2026-09-21
Visit source ↗
Independent
Ferstar — "ZCode silently uploads your workspace snapshot" technical teardown (English version) - **What it is:** The researcher's reverse-engineering write-up that broke the story: 313MB encrypted snapshot, 42,411 files, 86.6% `.git` payload, 564 failed upload attempts, 15KB uploaded snapshot, AES-256-CTR + RSA-OAEP-SHA256 envelope with server-held private key, capture ran unconditionally while signed in.** Incident facts and technical mechanism (INDEPENDENTLY VERIFIED source of the discovery); Ferstar's 2026-09-21 re-audit conclusion that the upload pipeline is gone and checkpoints are now local-only (as reported by TNW/The Register). — ** Independent technical analysis; directly involved researcher.Date: ** 2026-09-18 (teardown); re-audit 2026-09-21
Visit source ↗
Secondary Sources (6)
Secondary
Chinese-language coverage (headline-level corroboration; not read in full) - **What it is:** Chinese-language articles indexed by the OECD.AI record and search results, whose titles corroborate the open-source announcement, "0 data retention", OSS bucket emptying, Repo Wiki removal, and the legal-demand-letter escalation: - ifeng/凤凰网 — "被质疑'偷传代码'后,智谱ZCode官宣开源:0数据留存" (Zhipu ZCode announces open source: 0 data retention)** Chinese-press corroboration of the zero-retention/open-source announcements and audit details at headline level. — ** Secondary corroboration (Chinese-language; headline-level only — full texts not read in this research; flagged as a coverage limitation in `research/S12.md`). ---Date: ** 2026-09-20 to 2026-09-21
Visit source ↗
Secondary
Ground News (aggregate) — DIGITIMES summary: "Z.ai's ZCode Crisis Exposes AI Coding's Enterprise Trust Gap" - **What it is:** Aggregate page showing DIGITIMES' 2026-09-21 item: Z.ai open-sourced ZCode and is preparing a zero-data-retention option for its MaaS platform; enterprise trust-gap framing.** DIGITIMES enterprise-trust framing; MaaS zero-data-retention option timing (2026-09-21). — ** Secondary aggregator (DIGITIMES content via Ground News).Date: ** 2026-09-21
Visit source ↗
Secondary
ExplainX.ai — "Z.ai Open-Sourced ZCode After Its Default Config Uploaded Code to Alibaba Cloud" - **What it is:** Secondary blog summary: open-sourcing (it dates the release 2026-09-23, a noted discrepancy vs Reuters/TNW's 2026-09-21), default-config uploads, enterprise audit steps (account logs, commit-history diff review, credential rotation), and the argument that community auditing effort will decide whether trust is repaired.** Enterprise audit checklist; the open-sourcing-as-first-step-not-final-step argument; documents date discrepancy in coverage. — ** Secondary analysis (blog).Date: ** 2026-09-23
Visit source ↗
Secondary
MITRADE news (au) — "Z.ai disables its coding assistant after unauthorized uploads incident" - **What it is:** SCMP-derived summary with skeptical notes: as of publication, no documented retention-policy changes and no independent retesting offered; OSS uploads linked to repository-indexing (session checkpoints, version rollback, Repo Wiki) default-on after launch; "rebel" uploads description; 564 failed attempts / 15KB uploaded; robotics-company ban reported.** The "no documented retention changes as of Sep 22" skepticism (contrasted with Reuters' Sep 21 zero-retention announcement); SCMP-derived details. — ** Secondary aggregator; useful for the unresolved-verification angle.Date: ** 2026-09-22
Visit source ↗
Secondary
AINave — "Z.ai data breach exposes cloud-sync and key-management risks for AI coding tools" - **What it is:** Summary of the incident with the key-management-risk angle (encrypted archive decryptable only with backend-held private key; SCMP-sourced); developer-trust warnings.** Key-management risk framing; corroboration of core facts. — ** Secondary reporting.Date: ** 2026-09-20
Visit source ↗
Secondary
BYOBot — AI Daily Newsstand, September 22, 2026 - **What it is:** AI-written daily digest covering the ZCode open-sourcing (Apache-2.0, 2026-09-21), 313MB/42,411-file archive, key-custody point; cites Ferstar's English teardown, Tom's Hardware and The Standard stories; "The model isn't the perimeter anymore. The client is."** Corroboration of open-source date and key numbers; secondary references (Tom's Hardware URL and The Standard URL appear inside the digest). NOTE: AI-generated content, flagged as such by the publisher; used only as corroborating digest, not as a factual authority. — ** Secondary aggregator (AI-written; corroboration only).Date: ** 2026-09-22
Visit source ↗
Unverified Sources (2)
Unverified
Chengming Technology claim (withdrawn) - **What it is:** An unnamed Chinese firm's claim that six coding workspaces (source code, DB passwords, employee data) had been uploaded; publicly withdrawn on 2026-09-21 as based on wrong evidence (per Reuters/TNW). - **No URL recorded** (no primary public statement located during this research; reported via Reuters and TNW coverage listed above).** Illustrates the escalation pattern and its withdrawal; useful as context, NOT as established fact. — ** Unverified claim, withdrawn; treated as context only. ---Date: ** claimed 2026-09-20, withdrawn 2026-09-21
URL unavailable
Unverified
V2EX thread — repost of Z.ai's official Feishu statement - **What it is:** Community forum repost of Z.ai's Friday (2026-09-18) Feishu statement tracing the issue to the repository-indexing feature (session checkpoint recovery, version rollback, Repo Wiki), default-on after launch.** Full text of the Friday statement as reposted (via TNW's citation); community discussion context. — ** Community repost of an official statement; unverified as a forum artifact but consistent with wire-reported company statements.Date: ** 2026-09-18/19
Visit source ↗