What the app was caught doing
A security researcher found that ZCode sent user files to the cloud without clear consent. Z.ai then patched the app and published its code.
Z.ai's ZCode tool was found quietly uploading developers' full project folders to the cloud. Days later it open-sourced the app and promised to keep no data.

A security researcher found that ZCode sent user files to the cloud without clear consent. Z.ai then patched the app and published its code.
main as of 2026-09-23, README noting v3.14.3).zcode-prod) without consent. Discovered by independent researcher Ferstar, whose teardown of 2026-09-18 found a 313MB encrypted snapshot of a commercial project (42,411 files; 86.6% of payload from .git) with 564 failed upload attempts on his machine and one 15KB snapshot already successfully uploaded.A timeline of confirmed events:
.git data (196.1MB LFS objects, 102.2MB commit-history objects, 0.6MB logs), had failed 564 upload attempts; a smaller 15KB snapshot (538 files of a public repo) had uploaded successfully. The archive was encrypted with AES-256-CTR wrapped via RSA-OAEP-SHA256 using a server-supplied public key — the private key exists only in Z.ai's cloud, so neither the user nor the client could decrypt it. Z.ai apologized in its official Feishu community the same day, blamed the default-on "Codebase Indexing" feature (used for session-checkpoint recovery, version rollback, Repo Wiki), said it had patched the issue, pledged to open-source ZCode, and offered compensation as a weekly quota reset.zcode-prod OSS bucket empty.BEFORE (until ~2026-09-17/18): ZCode closed-source client; "Codebase Indexing" enabled by default; while signed in, the client packages the whole workspace (working tree + .git history + LFS + reflogs + global config) into an encrypted snapshot and attempts to post it to Alibaba Cloud OSS; settings labeled "Optimize Experience" / "Repo Snapshot Indexing" did not stop capture; deletion of a pending snapshot caused a fresh repack within ~30 minutes; the privacy policy (effective 2026-06-15) described collecting conversation text/files but said nothing about workspace snapshots; the decryption key lived only in Z.ai's cloud.
CHANGE (2026-09-18 → 2026-09-21): Users detect and publicize the behavior (Ferstar, Feng Ruohang, J.F. Zhang); Z.ai apologizes Friday; Monday it patches (v3.14.0), removes Repo Wiki and the upload workflow, enables zero-data retention, claims deletion of uploaded data verified by CAICT/NSFOCUS, and publishes the full source under Apache-2.0.
AFTER (2026-09-22 →): Upload pipeline gone (Ferstar re-audit confirmed); remaining checkpoint mechanism does local Git work only; source is publicly inspectable, but the erased commit history means the pre-patch snapshot/upload code cannot be audited; zero-retention claim rests on Z.ai's word plus company-commissioned assessments; full CAICT/NSFOCUS report unpublished; MaaS no-retention option announced as coming; developer and enterprise trust in Chinese AI coding clients under stress; parallel with July 2026 Grok Build incident widely noted.
Technical mechanism (INDEPENDENTLY VERIFIED via reverse-engineering by Ferstar and J.F. Zhang; details corroborated in runtimewire, dev.to, SamCodeMan write-ups):
.git — objects, LFS cache, reflogs — plus global application config) into a compressed snapshot. Trigger sources included a pre-prompt capture and a Repo Wiki update task./api/v1/snapshot/upload-credential). The RPC returns a snapshot ID, storage credentials, size limits and the RSA public key. The private key exists only on Z.ai's backend, so the local ciphertext cannot be decrypted by the user or by the client — an architecture that protects transfer from third parties while guaranteeing Z.ai's backend can read everything.zcode-prod); Alibaba's storage then calls back to Z.ai's backend to register the snapshot. Ferstar's observed archive had failed 564 times (network/credential churn) and sat in a pending local queue; one 15KB snapshot of a public repo had succeeded.zcode-prod bucket was emptied/deleted (CAICT: "zero-data state"; NSFOCUS: bucket and objects gone) and that uploaded data was never used to train models; ZCode has an enabled zero-data-retention feature; MaaS no-retention controls are planned for standard model calls..git as sensitive data.chattr +i / chflags uchg worked as a user-side mitigation — SamCodeMan write-up) are the practical defenses..git for secrets; treat the workspace sent to any AI tool as data that reaches the vendor's cloud.config/, .env.example), and verify the installed version ≥ v3.14.0.Circle 1: individuals and team leads who use AI coding tools daily, and security/DevOps engineers.
config/ in the open repo, treat any repo touched by ZCode as potentially exposed, rotate committed credentials (Git history is the risk), and make session/checkpoint directories immutable (chflags uchg / chattr +i) as a defense-in-depth habit.Circle 2: engineering organizations and security leaders.
Circle 3: ecosystem: vendors, regulators, standards bodies, industry observers.
VERIFY exercise (see labs/S12.md): clone https://github.com/zai-org/ZCode, verify license and commit count, rg the tree for snapshot/upload/credential endpoints (e.g., upload-credential, snapshot, oss), inspect config/ defaults and .env.example, and confirm no Repo Wiki or cloud-snapshot path remains — i.e., reproduce Ferstar's post-remediation re-audit. This is genuinely meaningful now because the upload pipeline's removal is the one remediation claim that is externally checkable; do not attempt a network-based exfiltration re-test against your own data.
This is the strongest story of the week on the agent-security beat, and it has two legs. The first is the failure class: a default-on feature shipped a developer's entire Git history — the part of a repo that keeps all its old secrets — to a vendor's cloud, encrypted in a way the owner couldn't even open. That is the clearest possible illustration that when you give an agent your folder, you may be giving the vendor your folder. The second leg is the response: open-sourcing the client, enabling zero retention and commissioning CAICT/NSFOCUS assessments is a genuine, rare accountability play by a Chinese lab — the first since the Grok Build case to follow the "delete, document, disclose" template. But the release shipped with its history scrubbed, the deletion claim rests on the word of the only party that could have been checked, and the full report hasn't landed. The fix is half-favorable: the upload pipeline is provably gone; whether the data ever really went away remains a matter of trust. That asymmetry — transparency at the code level, opacity at the data level — is the lesson, and it applies to every AI coding tool on the market, not just Z.ai's.
Evidence sources: see sources/S12.md. Research window per RESEARCH_CONFIG.json: 2026-09-18 → 2026-09-22. Event date 2026-09-21 is inside the window.

Clone and authenticate the artifact
git clone https://github.com/zai-org/ZCode.git && cd ZCode
git log --oneline | wc -l # expect ~3 commits → confirms wiped history (pre-patch code absent)
head -5 LICENSE # expect Apache-2.0
git remote -v # confirm org: zai-org
Confirm the upload path is gone (search for the pre-patch pipeline components documented in the incident analysis):
rg -n "upload-credential|snapshot/upload|Repo Wiki|repo.?wiki" --glob '!pnpm-lock.yaml' .
rg -ni "aliyun|oss|oss-cn|snapshot" --type-add 'src:*.{ts,tsx,js,rs,json,md}' -t src | head -40
Ferstar's re-audit (per TNW/The Register) found the upload pipeline gone and checkpoints local-only; this command set independently re-checks that claim. Documented pre-patch endpoints (/api/v1/snapshot/upload-credential) should not resolve in the tree.
Inspect config defaults — the incident's root cause was a default-on feature:
cat config/README.md
rg -n "optimize|indexing|snapshot|telemetry|authToken|token" config .env.example .env.production .env.development 2>/dev/null | head -40
Verify what is default-on today.
Check the checkpoint mechanism (retained, should be local-only per remediation):
rg -n "checkpoint" apps/zcode-cli packages | head -30
Confirm no cloud endpoint is referenced from checkpoint code paths.
Baseline network egress inspection (static only): extract hostnames referenced in the client, e.g.
rg -o "https?://[a-zA-Z0-9.-]+" packages apps --glob '!*.map' | sort -u | head -30
Confirm expected endpoints (z.ai/ZCode service domains) and absence of unexpected storage endpoints in the fixed client.
upload-credential; no Repo Wiki code; no OSS/upload snapshot orchestration.VERIFY — static-source security audit of an open-sourced remediation claim (performed manually against the public repo; no network exfiltration test performed).
Lab date: 2026-09-23.