MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-21 · via Tom's Hardware

Z.AI apologizes after coding tool attempts to siphon user files without permission

Image via Tom's Hardware
Image via Tom's Hardware

Z.AI, the Chinese company behind GLM models, faced backlash after its ZCode coding assistant was found compressing and attempting to upload 313MB of local workspace data to cloud storage without user consent. The tool made 564 failed upload attempts, though a smaller 15KB file was successfully transmitted. The company has apologized, says it has fixed the issue, destroyed uploaded data, and plans to open-source ZCode's codebase for third-party review.

Expanded Detail

The incident was first flagged by developer Ferstar, who observed ZCode compressing roughly 313MB of local workspace files into an encrypted archive destined for Alibaba Cloud storage. Although the archive was encrypted, filenames remained visible, revealing contents tied to a commercial project. A separate blogger, Feng Ruohang, reported similar behavior. Critically, the upload function was enabled by default with no way to disable it.

Z.AI, also known as Zhipu AI and recognized for its GLM models on Hugging Face, has since apologized, claimed the issue is fixed, and stated uploaded data was destroyed. The company also pledged to open-source ZCode's codebase for independent review. Notably, one leading Chinese robotics firm has already banned Z.AI tools internally over security concerns.

Context

This incident could erode developer trust in AI-assisted coding tools, particularly among professionals handling proprietary or sensitive code. If such tools silently transmit workspace data, enterprises may hesitate to adopt them, slowing productivity gains. The pattern also mirrors similar complaints about xAI's Grok Build and Claude Code, suggesting a broader industry concern. While Z.AI's open-sourcing pledge may help rebuild confidence, the default-on nature of the upload mechanism could prompt regulators to scrutinize consent practices more closely, potentially shaping future data-handling standards for AI development tools.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Tom's Hardware →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Devs say Chinese AI company silently uploaded hundreds of megabytes of local workspace data, company apologizes — Z.AI, the firm behind the GLM models, didn’t ask for user consent and made 564 attempts to exfiltrate 313MB archive.” Browse more stories.