Skip to content

China’s Z.ai Disables Coding Assistant Features After Discovering It Secretly Uploaded Developers’ Code Overseas

Getting your Trinity Audio player ready...

China’s Z.ai Disables Coding Assistant Features After Discovering It Secretly Uploaded Developers’ Code Overseas

Beijing-based AI company Z.ai, also known by its earlier name Zhipu, has pulled back several features from its flagship coding assistant after discovering the tool had been quietly shipping entire local codebases to overseas cloud servers without asking users first, a lapse that’s put an unusual spotlight on how much trust developers place in AI coding tools without always realizing what those tools are doing in the background.

The trouble first surfaced last week, when Chinese developers took to social media claiming Z.ai’s coding assistant, called ZCode, had been pulling project data straight from Git, the widely used open-source version control platform, and uploading it to Alibaba Cloud storage without their consent. Z.ai traced the behavior to a feature called Codebase Indexing, built to support things like session checkpoints, version rollbacks and automatic wiki generation. The catch was that the feature came switched on by default, and there wasn’t a clear, obvious way for users to turn it off if they didn’t want their code leaving their own machine in the first place.

One company’s account of the incident briefly made things look considerably worse than they ultimately turned out to be. Chengming Technology said publicly that six of its internal coding workspaces had been uploaded without permission, and claimed the exposed material included complete source code, database passwords, and employees’ personal information, details that would represent a genuinely serious breach if accurate. By Monday, though, Chengming Technology had walked that claim back, saying it had relied on incorrect evidence when it made the original accusation, and the company didn’t immediately respond to requests for further comment on what exactly went wrong with its assessment.

Real More:  New Poll Finds Three-Quarters of Americans Think AI Companies Aren't Doing Enough to Stop a Disaster

Z.ai’s own response to the situation moved in stages. On Friday, the company issued a public apology and confirmed the root cause sat with the Codebase Indexing feature, saying it had already patched the underlying vulnerability. By Monday, the company had gone considerably further, announcing it had open-sourced ZCode entirely, the assistant that runs on Z.ai’s newest GLM-5.3 model, while disabling certain features outright rather than simply patching around the edges. On its official ZCode account, the company said it plans to build a standing process for reporting and responding to product security vulnerabilities going forward, and it explicitly invited developers to keep digging through the now-open codebase and flag anything else they find.

To back up its claim that no actual harm came from the exposed data, Z.ai pointed to an independent security review carried out by a technology standards think tank affiliated with China’s industry ministry, working alongside Chinese cybersecurity firm NSFOCUS. That review reportedly found the uploaded code data had already been deleted and was never retained on the cloud platform it was sent to. Z.ai also said it has since enabled a zero-data retention setting specifically for the version of the coding assistant used by enterprise developers and tech companies, a change meant to prevent any repeat of the same problem going forward. Separate reporting has noted one wrinkle in verifying all of this independently: the original uploaded data archives were encrypted by default, which makes it genuinely difficult for outside researchers to confirm exactly what was captured and confirm the deletion claims on their own rather than simply taking Z.ai’s word for it.

Real More:  Boards Prepare for Digital Infrastructure Shocks Amid Rising Cyber Risk, Capgemini Survey Finds

What makes this episode stand out beyond the technical details is how openly Z.ai has handled the fallout. Public, detailed security disclosures of this kind remain fairly rare among Chinese AI companies, which have historically tended toward far less transparency when problems like this surface. Z.ai’s decision to apologize repeatedly, publish details of what went wrong, open-source the affected product, and commit to releasing a full security assessment report shortly represents a notably different playbook, one that seems aimed squarely at rebuilding developer trust rather than quietly patching the issue and hoping it goes unnoticed.

The stakes behind that trust are higher than they might first appear. AI coding assistants have become deeply embedded in how software actually gets built, with industry estimates suggesting the large majority of developers were already relying on these tools by 2025, often with the tools sitting directly inside sensitive, high-value source code. A vulnerability in any widely used coding assistant carries an outsized risk precisely because of how much access these tools are routinely granted, and how little scrutiny many default settings tend to receive from the people using them day to day.

The incident also lands at a moment when Z.ai has been gaining real momentum in China’s increasingly crowded AI race, having recently climbed toward the top of at least one closely watched AI model leaderboard under an unreleased codename ahead of its GLM-5.3 launch. Whether this security stumble slows that momentum or simply becomes a footnote once the promised full report lands is likely to depend heavily on how convincingly Z.ai can demonstrate, beyond its own statements, that the exposed code genuinely never went anywhere it shouldn’t have.

Real More:  Zscaler Stock Rises on Fiscal Q4 Earnings Beat and Upbeat Guidance as AI-Driven Cybersecurity Demand Surges

Leave a Comment