Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Z.ai disables ZCode feature after unauthorized repository uploads

Published 22 September 2026

Chinese artificial intelligence company Z.ai disabled several features of its ZCode coding assistant after a default-enabled setting uploaded users' local code repositories to Alibaba Cloud servers without their consent, the company said this week. The issue came to light through a technical investigation by an independent Chinese blogger known as Ferstar, who reported on September 18, 2026, discovering abnormal disk usage and tracing it to ZCode's background processes. Ferstar found a 313 megabyte compressed archive awaiting upload after 564 failed attempts and a 15 kilobyte file that had already been transmitted. Both files were encrypted with a private key held only on Z.ai's backend, preventing users from opening them or verifying their contents. The behavior was linked to a Codebase Indexing feature used for session checkpoints, version rollback and wiki generation. The feature was enabled by default when ZCode launched and, according to developers, offered no toggle to disable it. Z.ai apologized in a social media post, said it had patched the vulnerability, and disabled the workflow responsible for generating and uploading local repository snapshots.

0:00 / 0:00