Zhipu AI’s ZCode tool accused of secretly uploading entire codebases to cloud servers
Taiyuan Chengming Technology, a paying user of Zhipu AI’s ZCode programming tool, sent a formal letter alleging that ZCode automatically and secretly uploads entire project workspaces—including source code, credentials, and personal data—to Alibaba Cloud OSS and potentially to a Singapore-based entity, without user consent. Zhipu attributed the issue to a default-enabled “codebase indexing” feature and claimed it was fixed, but Chengming detected uploads after the fix. The company demands data deletion and proof of handling by October 10, reserving legal rights.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page reads the event directly, while its address stays stable when the title changes.
- Summary covers the current reports
Cross-source coverage
Common ground
- Both sides agree that ZCode had a bug in its beta version that transmitted more data than intended, including deleted commits with credentials.
- Both agree that Zhipu acknowledged the issue and released a fix in version 3.12.3 on September 16.
- Both agree that Zhipu has committed to open-sourcing ZCode for third-party audit, which is a positive step toward transparency.
- Both agree that Chengming, as an enterprise client, has reasonable demands for proof of deletion, data flow maps, and access logs.
Points of contention
- The Eastern Agent sees the incident as a minor technical glitch in beta software, while the Neutral Agent views it as a systemic failure in data governance due to undisclosed data transmission.
- They disagree on the timeline: the Eastern Agent says the September 18 detection could be from a cached or outdated instance, while the Neutral Agent argues it shows a patch deployment failure or lack of user notification.
- The Eastern Agent believes the Singapore routing is legally compliant under China's PIPL, while the Neutral Agent insists the burden of proof is on Zhipu to demonstrate proper cross-border transfer filings.
- The Eastern Agent frames the controversy as geopolitical bias against Chinese tech, while the Neutral Agent says it's about universal standards for data transparency, not nationality.
Blind spots
- Neither side fully addresses whether Zhipu notified users about the data transmission feature before the bug was discovered.
- The debate overlooks the potential impact on smaller developers or individual users who may not have the resources to demand transparency like Chengming does.
- Both sides assume the Cyberspace Administration's silence either proves compliance or means nothing, without considering that regulators may be gathering evidence before acting.
WorldAttention’s read
The roundtable reveals a fundamental clash between viewing the ZCode incident as a routine beta bug versus a serious data governance failure. The Eastern Agent emphasizes China's regulatory framework and geopolitical context, arguing the issue is overblown and that Zhipu's transparency efforts are sufficient. The Neutral Agent focuses on the undisclosed data transmission, the timeline gap, and the need for Zhipu to prove compliance with cross-border data laws. Both agree that Zhipu fixed the bug and committed to an audit, but they disagree on whether that resolves the trust issue. The blind spots include a lack of discussion about user notification before the bug, the impact on smaller users, and the ambiguity of regulatory silence. Ultimately, the outcome hinges on whether Zhipu can meet Chengming's October 10 deadline with concrete evidence of data governance, which will determine if this remains a PR crisis or escalates into a legal one.
Reporting timeline
Zhipu AI's ZCode Tool Accused of Silently Uploading Entire Codebases to Overseas Servers
Zhipu AI's coding tool ZCode is embroiled in a data privacy controversy after users discovered it was silently uploading entire codebases, including git history, passwords, and API keys, to third-party cloud servers. ZCode apologized, attributing the issue to a default-enabled 'Codebase Indexing' feature, and promised to open-source the code and invite audits. However, paying corporate user Chengming Technology issued a formal letter demanding accountability, claiming the uploads included complete source code and employee data, far exceeding stated policies. Chengming also noted that network requests pointed to a Singapore-based entity while the service agreement is with Beijing Zhipu Huazhang, raising concerns about unauthorized cross-border data transmission. Chengming demands a written response by October 10, including complete data deletion and an explanation of data pathways, while reserving the right to pursue legal action. Zhipu has not yet responded to these demands.
Read sourceZhipu AI faces data leak escalation over ZCode cross-border transfer allegations
A data leak scandal involving Zhipu AI's programming tool ZCode has escalated, with Taiyuan Chengming Technology demanding clarification on cross-border data transfers. The incident began when developer ferstar discovered a 313MB encrypted compressed package containing core project assets, which ZCode had attempted to upload 564 times. Zhipu apologized, attributing the issue to a 'codebase indexing' feature enabled by default, and promised fixes and open-sourcing. However, Chengming Technology found that between August 28 and September 14, over six of its workspaces were uploaded, including full source code, credentials, and personal data. The company revealed that ZCode's network requests point to Singapore-registered JINGSHENG HENGXING TECHNOLOGY PTE.LTD, raising cross-border data transfer concerns. Chengming Technology issued 11 demands, including cessation of data processing and proof of deletion, with a response deadline of October 10. Zhipu has not yet responded, but ZCode released version 3.14.0 on September 19 fixing the upload issue.
Read sourceZhipu AI's ZCode Tool Exposed for Uploading Full Code Repos; Company Faces 12 Demands
On September 18, developers discovered that Zhipu AI's programming tool ZCode uploads entire local code repositories—including Git history, passwords, and credentials—to the cloud after login, due to a default-enabled feature. On September 19, Taiyuan Chengming Technology posted a 12-page letter to Zhipu AI, alleging severe trade secret and personal information infringement, and potential cross-border compliance risks as data may have flowed to Singapore-based entities. The letter demands thorough deletion, proof, a written commitment to cease collection, and explanation of third-party rights and data export pathways, with a deadline of October 10, 2026, while reserving rights to compensation and criminal proceedings. Netizens reacted with mixed opinions, some defending Zhipu by conflating API usage with local file access, while others criticized the tool's active acquisition of local files.
Read sourceShow 2 older updatesHide older updates
ZCode Accused of Silently Uploading Code; Zhipu AI Faces Legal Threat from Client
Taiyuan Chengming Technology Co., Ltd. has sent a formal letter to Beijing Zhipu Huazhang Technology Co., Ltd., the developer of the ZCode AI code assistant, accusing it of unauthorized and batch uploading of company data assets and trade secrets. Chengming Technology claims independent evidence shows the uploads were automatically triggered and included project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information. The company argues this exceeds ZCode's stated privacy policy. Despite ZCode's claim that the issue was fixed in version 3.12.3 on September 16, Chengming Technology detected uploads on September 18. Chengming demands a written response by October 10, complete deletion of all uploaded data and derivatives, and explanations regarding data handlers, overseas transfers, third-party sharing, and use in model training. ZCode previously acknowledged the function was enabled by default and stated the problem has been fixed, with uploaded data destroyed after cloud page generation.
Zhipu's ZCode AI Tool Accused of Illegally Uploading User Data to Cloud, Sparks Compliance Concerns
Taiyuan Chengming Technology, a paying user of Zhipu's AI programming tool ZCode, has sent a formal letter alleging that ZCode automatically and secretly uploads entire project workspaces—including source code, credentials, and personal data—to Alibaba Cloud OSS without user consent. The company demands data deletion, proof of data handling, and reserves rights to legal action. Zhipu attributed the issue to a 'codebase indexing' feature and claimed it was fixed, but Chengming Technology detected uploads after the fix. The incident raises cross-border data compliance issues, as ZCode's English privacy policy identifies a Singapore subsidiary as data processor, potentially violating China's Personal Information Protection Law. Zhipu's stock price fell sharply amid the controversy, dropping below HK$1,000 per share. The company has not publicly responded to the letter as of press time.
Read source