Z.ai Killed ZCode Features After Devs Caught Silent Uploads of Local Workspaces to the Cloud
Developers found Z.ai's ZCode coding assistant silently packaging local files and uploading them to Alibaba Cloud with no off switch. One dev logged 564 attempts on a 313MB archive before Z.ai apologized and pulled the feature.

Z.ai, the Beijing company behind the popular GLM open models, spent last week apologizing after developers caught its coding assistant quietly hoovering up their local files and shipping them to the cloud without asking.
The tool is ZCode, Z.ai's answer to the wave of AI coding assistants. What several prominent devs discovered is that it was packaging their workspaces into compressed archives and pushing them toward Alibaba Cloud storage, with the upload switched on by default and no obvious way to turn it off.
One blogger, known as Ferstar, dug into the traffic and found ZCode had squeezed about 313MB of his files into a single archive. When it was caught, Tom's Hardware reports, it had tried and failed to send that bundle 564 times. A smaller 15KB file did go through.
The details are the unsettling part. The temporary archive was compressed and encrypted, yet the filenames stayed visible, enough for Ferstar to recognize a commercial project he was working on even though he could not crack the file open to confirm its contents. A second developer, Feng Ruohang, described a similar experience. An engineer at a leading Chinese robotics firm told reporters that Z.ai's tools had already been banned inside the company over security worries.
Z.ai moved fast once the posts spread. It apologized, said it had disabled the silent upload, and told users that anything already sent to its servers had been destroyed. The feature is gone from the latest release, and the company says it will open source ZCode's codebase so outside reviewers can check the plumbing themselves, per CSO Online.
Worth being precise about what this is. It is a vendor scrambling to contain a mess that its own users surfaced, not a nation-state campaign and not a tracked exploit under some emergency patch order. Nobody has shown that every customer's code tree walked out the door. The big archive failed hundreds of times before anyone hit send, and Ferstar could not verify the contents he suspected.
It still fits a pattern that keeps catching engineers off guard: dev tooling that treats your machine as its own supply depot. It rhymes with the way exposed Vite dev servers leaked cloud secrets and with browser AI extensions quietly hijacking sessions. The lesson lands the same way each time. An assistant with filesystem access and a default upload is one config flag away from an exfiltration tool.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free