criticalcredential-leakunverifiedcollected
A coding assistant uploaded whole local repositories to the cloud by default (unverified report)
According to press reports, Z.ai's ZCode coding assistant was copying entire local repositories, Git history included, to a cloud storage bucket in the background. The feature was on by default and had no clear off switch.
Cause
Per the reports, a codebase-indexing feature used for checkpoints, rollbacks and auto-generated project wikis snapshotted and uploaded repositories without asking. It was not described in the privacy policy, and the uploads were encrypted with a key only the vendor held, so users had no way to check what had been stored.
Consequence
Developers said source code, and in some cases database passwords and employee personal data, had left their machines. Z.ai apologized, disabled the feature and deleted the bucket; the episode became a trust problem for enterprise use. These are reported claims, not independently confirmed here.
Fix
The vendor removed the upload path, shipped ZCode 3.14.0, open-sourced the assistant and commissioned audits; a security firm and a state-affiliated standards body said the stored data had been deleted. For operators: treat every AI coding tool as a possible outbound data path. Check what indexing or sync features do by default, watch background processes' disk and network use, and keep secrets out of the working tree.
What happened
In the week of September 22, 2026, a Chinese developer who goes by Ferstar
noticed ZCode, the coding assistant from Z.ai (also known as Zhipu), using
far more disk than expected and traced it to a background process. By his
account, the assistant was packaging whole local repositories, including
.git history, reflogs and cached large files, and sending them to an
Alibaba Cloud storage bucket.
The chaos on the ground
Other developers checked their own machines and reported the same thing. According to Reuters, some said the uploads contained not only source code but database passwords and employees’ personal information. Nobody outside the company could see what was in the bucket: the data had been encrypted with a key that only Z.ai held. Z.ai apologized publicly and switched the feature off.
Root cause
The uploads came from a codebase-indexing feature that powered session checkpoints, rollbacks and an auto-generated “repo wiki”. It was enabled by default when the product launched, offered no obvious toggle, and was not mentioned in the privacy policy. Nothing in the tool’s normal use told the developer that their repository was leaving the machine.
The fix
Z.ai removed the upload mechanism and the wiki feature, deleted the storage bucket, released ZCode 3.14.0, published the assistant’s source code, and had the cleanup checked by the security firm NSFOCUS and a standards body affiliated with China’s industry ministry, which confirmed the data had been deleted. The company says the data was never used for model training.
The lesson for anyone running coding agents is broader than one vendor: an assistant that can read your repository can also send it somewhere. Before rolling a tool out, find out what its indexing, sync or “memory” features do by default, watch what its background processes write and send, and keep credentials out of the working tree so an upload like this has less to take.
Sources
- InfoWorld: Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk(opens in a new tab)
- Reuters (via Yahoo): China's Z.ai disables AI coding assistant features after security issue(opens in a new tab)
- Blog post by the independent developer Ferstar, who first reported the uploads (September 2026)