← All incidents

criticalcredential-leakunverifiedcollected

A coding assistant uploaded whole local repositories to the cloud by default (unverified report)

According to press reports, Z.ai's ZCode coding assistant was copying entire local repositories, Git history included, to a cloud storage bucket in the background. The feature was on by default and had no clear off switch.

Observed
Severity score
8/10
Blast radius
data, reputation
Tags
#z-ai#zcode#data-exfiltration#default-on#privacy#cloud-upload

Cause

Per the reports, a codebase-indexing feature used for checkpoints, rollbacks and auto-generated project wikis snapshotted and uploaded repositories without asking. It was not described in the privacy policy, and the uploads were encrypted with a key only the vendor held, so users had no way to check what had been stored.

Consequence

Developers said source code, and in some cases database passwords and employee personal data, had left their machines. Z.ai apologized, disabled the feature and deleted the bucket; the episode became a trust problem for enterprise use. These are reported claims, not independently confirmed here.

Fix

The vendor removed the upload path, shipped ZCode 3.14.0, open-sourced the assistant and commissioned audits; a security firm and a state-affiliated standards body said the stored data had been deleted. For operators: treat every AI coding tool as a possible outbound data path. Check what indexing or sync features do by default, watch background processes' disk and network use, and keep secrets out of the working tree.

What happened

In the week of September 22, 2026, a Chinese developer who goes by Ferstar noticed ZCode, the coding assistant from Z.ai (also known as Zhipu), using far more disk than expected and traced it to a background process. By his account, the assistant was packaging whole local repositories, including .git history, reflogs and cached large files, and sending them to an Alibaba Cloud storage bucket.

The chaos on the ground

Other developers checked their own machines and reported the same thing. According to Reuters, some said the uploads contained not only source code but database passwords and employees’ personal information. Nobody outside the company could see what was in the bucket: the data had been encrypted with a key that only Z.ai held. Z.ai apologized publicly and switched the feature off.

Root cause

The uploads came from a codebase-indexing feature that powered session checkpoints, rollbacks and an auto-generated “repo wiki”. It was enabled by default when the product launched, offered no obvious toggle, and was not mentioned in the privacy policy. Nothing in the tool’s normal use told the developer that their repository was leaving the machine.

The fix

Z.ai removed the upload mechanism and the wiki feature, deleted the storage bucket, released ZCode 3.14.0, published the assistant’s source code, and had the cleanup checked by the security firm NSFOCUS and a standards body affiliated with China’s industry ministry, which confirmed the data had been deleted. The company says the data was never used for model training.

The lesson for anyone running coding agents is broader than one vendor: an assistant that can read your repository can also send it somewhere. Before rolling a tool out, find out what its indexing, sync or “memory” features do by default, watch what its background processes write and send, and keep credentials out of the working tree so an upload like this has less to take.

Sources