On September 18, tech blogger ferstar discovered a ~313MB encrypted file while cleaning his disk — its manifest listed about 42,000 files, over 80% of them project history. Reverse engineering showed that Zhipu's AI coding tool ZCode silently packaged and uploaded the entire workspace to an Alibaba Cloud OSS bucket whenever the user was logged in: source code, full Git history, LFS caches, reflogs and parts of global dev configs — effectively the entire R&D assets of a project.
Three details stung the community hardest: the upload was on by default with no visible off switch; the RSA private key lived only on the server, so users could not even decrypt their own packages; and history records were exempted from all safety filters.
Zhipu's three-step response
- Sep 18 evening: official apology — the behavior came from a "codebase indexing" feature (version rollback, session checkpoints, RepoWiki);
- Sep 19: fixed ZCode v3.14.0 removing the Repo Wiki pipeline;
- Sep 21: ZCode to be open-sourced, with third-party audits by CAICT and NSFOCUS — the storage bucket confirmed at zero cloud data, all objects deleted, and no remaining path able to snapshot repos or exfiltrate files. Zhipu also promised monthly public security-audit reports.
Some enterprise users had already sent legal letters; many developers suspended the tool to assess exposure.
Not an isolated case, but a blind spot
Independent researcher cereblab earlier proved by packet capture that xAI's Grok Build uploads entire projects to Google Cloud — including files users explicitly told the AI not to read and unmasked passwords; Claude Code was caught sending location and identity data, later confirmed by Anthropic as an "intentional experiment".
Two years of Agent-security discourse focused on model misalignment, prompt injection and external attackers — the vendors' own data behavior was rarely treated as a first-class risk, until ZCode pushed it onto the main stage.
Enterprise takeaways
📋 AI coding tool checklist
· Audit all outbound traffic before adoption — don't trust docs alone;
· Prefer private deployment where code never leaves the domain;
· Demand verifiable data-retention terms and third-party auditability.
(Facts aggregated from public reporting)