DigestAI news desk

AI news, digested. Every story with its sources, every hour.

Agents & Tools2 min read

Z.ai apologizes after developers say its ZCode tool silently uploaded data

Z.ai, the second‑largest AI company in China, faced accusations after developers reported its ZCode coding assistant silently uploading local workspace data without consent. Filenames remained visible, leading him to believe a commercial project was included. Feng Ruohang reported a similar experience.

1 source

Key points

  • Z.ai said it has stopped the unauthorized uploads, destroyed any uploaded data, and will open‑source ZCode’s codebase for review.
  • An unnamed engineer said Z.ai’s tools have been banned at a leading Chinese robotics company over security concerns.

Z.ai apologized on Friday, saying it has disabled the automatic upload feature, destroyed any data that may have been transferred, and will open‑source ZCode’s codebase for third‑party review. The upload mechanism was enabled by default with no off switch. An unnamed software engineer at a leading Chinese robotics firm said Z.ai’s tools have been banned there over security concerns. The report also referenced past data‑privacy issues at U.S. firms such as xAI’s Grok Build and Claude Code.

The story so far

2 episodes →
  1. Z.ai apologizes after developers say its ZCode tool silently uploaded datathis story
Full story fromTom's Hardware · by Mark TysonOpen source ↗

Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive

Tom's Hardware · 21 September 2026

The second-largest AI company in China is having to work frantically to patch up its reputation, reports the South China Morning Post. Z.ai’s firefighting exercise began after a number of prominent devs raised flags about their local files and data being uploaded to online servers without their consent.

Z.ai has started to publicly address all the security and privacy concerns that have been stoked by the dev/blogger findings in recent days. On Friday, it apologized and said it had fixed the uploading of user files and data without consent. Moreover, it has been assuring users that any data uploaded to its cloud service has been destroyed. Lastly, and good for longer-term trust, Z.ai says that it is planning to open-source ZCode’s codebase and invite third-party assessors to review it.

Z.ai is also known as Zhipu AI, but you may also be familiar with it for its GLM models, which are available alongside the likes of Gemma, Qwen, Nemotron, DeepSeek, and many more on Hugging Face. Like similar companies, Z.ai offers a coding assistant, and it is this ‘ZCode’ tool that was caught silently uploading large amounts of data without permission.

The SCMP quotes two devs/bloggers who noticed what was happening and alerted their followers about the suspicious activity. One of them, known as Ferstar, reckons that ZCode compressed 313MB of their files into a directory to upload to Alibaba Cloud storage. When it was caught, it had apparently tried and failed to upload this compressed and encrypted file 564 times... A smaller 15KB file had successfully been siphoned.

Though the temporary files were squashed and encrypted, filenames were still visible. Thus, Ferstar was pretty certain the contents included a commercial project he was working on, even though he couldn’t extract the files to verify their contents. Another tech blogger known as Feng Ruohang reported a similar experience. Making matters worse, the upload mechanism within ZCode is enabled by default, with no ‘off’ option, says the source report.

There’s no indication of how long this sneaky file-uploading situation has existed. However, the SCMP also quotes an unnamed software engineer at a leading Chinese robotics company who indicates that Z.ai’s tools have been banned within the company due to security concerns.

As far as sneaky data pilfering and similar abuses, U.S. companies certainly don’t have a spotless record. Reports indicate Elon Musk’s xAI, specifically the Grok Build tool, was up to similar shenanigans earlier this year. Claude Code users have also grumbled about their data being transmitted without consent, as well as suffering from vulnerabilities that might allow hackers unauthorized access to user data.

Mark Tyson is a news editor at Tom's Hardware. He enjoys covering the full breadth of PC tech; from business and semiconductor design to products approaching the edge of reason.

This text was published by Tom's Hardware and written by Mark Tyson. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗

Topics · follow one to build your own front page

The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.

Comments

via GitHub Discussions

More in Agents & Tools

All →

Related stories