Zhipu AI’s ZCode tool accused of secretly uploading entire codebases to cloud servers
Chinese AI company Zhipu AI faces a data privacy scandal after its ZCode programming tool was found to automatically upload entire project workspaces—including source code, credentials, and personal data—to Alibaba Cloud and a Singapore-based entity without user consent. Paying client Taiyuan Chengming Technology issued a formal letter demanding data deletion and legal accountability, citing continued uploads after a claimed fix. Zhipu has not publicly responded.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page reads the event directly, while its address stays stable when the title changes.
- Summary covers the current reports
Cross-source coverage
Common ground
- Both sides agree that Zhipu's default-on 'Repository Index' feature was a design flaw that should have been opt-in.
- Both acknowledge that Zhipu apologized, fixed the issue, and open-sourced the code as a positive step.
- Both agree that the Singapore entity involved in data routing raises legitimate questions about transparency and compliance.
Points of contention
- The Eastern Agent sees the incident as a minor technical oversight blown out of proportion for geopolitical reasons, while the Neutral Agent views it as a serious breach of trust and security.
- The Eastern Agent argues that calling it 'data exfiltration' is loaded language implying malicious intent, while the Neutral Agent insists it's a technical term for unauthorized data transfer regardless of intent.
- The Eastern Agent believes China's regulatory framework (PIPL) is working well to force accountability, while the Neutral Agent argues Zhipu's response is insufficient without a third-party audit and data flow map.
- The Eastern Agent uses 'Western companies do it too' as a defense, while the Neutral Agent calls this a logical fallacy that doesn't excuse Zhipu's mistake.
Blind spots
- Both sides overlook the possibility that Zhipu's open-sourcing of code might not fully address the deletion and audit demands from Chengming Technology.
- The debate ignores the potential impact on smaller customers who lack the leverage of a large company like Chengming to demand answers.
- Neither side thoroughly examines whether Zhipu's terms of service actually allowed Singapore data processing, leaving a key factual gap.
WorldAttention’s read
The roundtable revealed a sharp divide between viewing the Zhipu AI incident as a manageable technical flaw versus a fundamental trust violation. Both sides agree the default-on setting was a design failure and that Zhipu's apology and open-sourcing were positive, but they clash on intent and accountability. The Eastern Agent frames it as a geopolitical attack on China's AI industry, while the Neutral Agent insists on concrete proof of data deletion and jurisdictional clarity. The core unresolved issue is whether Zhipu's corrective actions are enough to restore trust, especially given the Singapore data routing and the lack of a third-party audit. Ultimately, the debate highlights the tension between defending national tech champions and demanding rigorous security standards, with both sides missing the need for clearer contractual disclosures and independent verification.
Reporting timeline
Zhipu AI faces data transmission controversy after raising 33.5 billion yuan
Zhipu AI, a Chinese AI company, is embroiled in a controversy over its AI code editing platform ZCode, which allegedly transmits user data without authorization. On September 18, tech blogger ferstar reported that ZCode packages and encrypts users' entire workspace and uploads it to Alibaba Cloud OSS when logged in, with no option to disable the upload. Zhipu apologized, attributing the issue to a 'codebase indexing' feature, and stated uploaded data is immediately destroyed after Wiki page generation. However, Taiyuan Chengming Technology claimed six of its workspaces were fully uploaded, including sensitive data like source code, database passwords, and personal information, and questioned whether cross-border data transfers occurred, as ZCode's domains point to a Singapore-based subsidiary. Zhipu has not officially responded. The controversy has impacted Zhipu's rapid growth; the company raised 33.5 billion yuan in 2026 and reported 954 million yuan in revenue for the first half of the year, with ZCode having over 2 million users.
Read sourceZhipu AI's ZCode Tool Accused of Silently Uploading Code to Overseas Servers
Zhipu AI, a Chinese AI company backed by Tsinghua University, faces a data privacy scandal after its AI programming tool ZCode was found to be silently uploading entire code repositories, including git history, configurations, keys, and employee information, to third-party cloud servers without user permission. The tool's 'Repository Indexing' feature, enabled by default, triggered the uploads. Zhipu apologized and promised to open-source the repository and invite third-party audits, but controversy persists. Chengming Technology, a paying corporate user, issued a formal letter demanding accountability, citing evidence that uploads continued after a claimed fix and that network requests pointed to a Singapore-based entity while the service agreement was with Beijing Zhipu Huazhang. Chengming raised concerns about potential unauthorized cross-border data transmission and demanded data deletion, proof, and a written commitment to cease collection. Zhipu has not yet responded to the demands.
Read sourceZhipu AI's ZCode Tool Accused of Silently Uploading Entire Codebases to Overseas Servers
Zhipu AI's coding tool ZCode is embroiled in a data privacy controversy after users discovered it was silently uploading entire codebases, including git history, passwords, and API keys, to third-party cloud servers. ZCode apologized, attributing the issue to a default-enabled 'Codebase Indexing' feature, and promised to open-source the code and invite audits. However, paying corporate user Chengming Technology issued a formal letter demanding accountability, claiming the uploads included complete source code and employee data, far exceeding stated policies. Chengming also noted that network requests pointed to a Singapore-based entity while the service agreement is with Beijing Zhipu Huazhang, raising concerns about unauthorized cross-border data transmission. Chengming demands a written response by October 10, including complete data deletion and an explanation of data pathways, while reserving the right to pursue legal action. Zhipu has not yet responded to these demands.
Read sourceShow 4 older updatesHide older updates
Zhipu AI faces data leak escalation over ZCode cross-border transfer allegations
A data leak scandal involving Zhipu AI's programming tool ZCode has escalated, with Taiyuan Chengming Technology demanding clarification on cross-border data transfers. The incident began when developer ferstar discovered a 313MB encrypted compressed package containing core project assets, which ZCode had attempted to upload 564 times. Zhipu apologized, attributing the issue to a 'codebase indexing' feature enabled by default, and promised fixes and open-sourcing. However, Chengming Technology found that between August 28 and September 14, over six of its workspaces were uploaded, including full source code, credentials, and personal data. The company revealed that ZCode's network requests point to Singapore-registered JINGSHENG HENGXING TECHNOLOGY PTE.LTD, raising cross-border data transfer concerns. Chengming Technology issued 11 demands, including cessation of data processing and proof of deletion, with a response deadline of October 10. Zhipu has not yet responded, but ZCode released version 3.14.0 on September 19 fixing the upload issue.
Read sourceZhipu AI's ZCode Tool Exposed for Uploading Full Code Repos; Company Faces 12 Demands
On September 18, developers discovered that Zhipu AI's programming tool ZCode uploads entire local code repositories—including Git history, passwords, and credentials—to the cloud after login, due to a default-enabled feature. On September 19, Taiyuan Chengming Technology posted a 12-page letter to Zhipu AI, alleging severe trade secret and personal information infringement, and potential cross-border compliance risks as data may have flowed to Singapore-based entities. The letter demands thorough deletion, proof, a written commitment to cease collection, and explanation of third-party rights and data export pathways, with a deadline of October 10, 2026, while reserving rights to compensation and criminal proceedings. Netizens reacted with mixed opinions, some defending Zhipu by conflating API usage with local file access, while others criticized the tool's active acquisition of local files.
Read sourceZCode Accused of Silently Uploading Code; Zhipu AI Faces Legal Threat from Client
Taiyuan Chengming Technology Co., Ltd. has sent a formal letter to Beijing Zhipu Huazhang Technology Co., Ltd., the developer of the ZCode AI code assistant, accusing it of unauthorized and batch uploading of company data assets and trade secrets. Chengming Technology claims independent evidence shows the uploads were automatically triggered and included project source code, system architecture, version control history, database passwords, cloud service credentials, and employee personal information. The company argues this exceeds ZCode's stated privacy policy. Despite ZCode's claim that the issue was fixed in version 3.12.3 on September 16, Chengming Technology detected uploads on September 18. Chengming demands a written response by October 10, complete deletion of all uploaded data and derivatives, and explanations regarding data handlers, overseas transfers, third-party sharing, and use in model training. ZCode previously acknowledged the function was enabled by default and stated the problem has been fixed, with uploaded data destroyed after cloud page generation.
Zhipu's ZCode AI Tool Accused of Illegally Uploading User Data to Cloud, Sparks Compliance Concerns
Taiyuan Chengming Technology, a paying user of Zhipu's AI programming tool ZCode, has sent a formal letter alleging that ZCode automatically and secretly uploads entire project workspaces—including source code, credentials, and personal data—to Alibaba Cloud OSS without user consent. The company demands data deletion, proof of data handling, and reserves rights to legal action. Zhipu attributed the issue to a 'codebase indexing' feature and claimed it was fixed, but Chengming Technology detected uploads after the fix. The incident raises cross-border data compliance issues, as ZCode's English privacy policy identifies a Singapore subsidiary as data processor, potentially violating China's Personal Information Protection Law. Zhipu's stock price fell sharply amid the controversy, dropping below HK$1,000 per share. The company has not publicly responded to the letter as of press time.
Read source