Zhipu’s ZCode deletes data and announces compensation after data upload controversy
Zhipu AI has announced a resolution to the data upload controversy surrounding its ZCode AI coding tool, following developer reports of unauthorized workspace uploads. The company confirmed that all affected cloud data has been deleted, a process verified by two third-party organizations, and introduced a compensation plan for users.
The controversy began when a developer discovered a 313MB encrypted file in ZCode’s local directory, which reverse engineering indicated contained an entire user workspace, including project source code and Git history. Developers questioned how this data was being uploaded, especially as the feature was reportedly enabled by default in earlier versions without a clear option to disable it, and some users reported continued upload attempts even after adjusting privacy settings.
For enterprise developers, this issue extended beyond product functionality to immediate concerns over the security of their code assets, leading some companies to reportedly cease using the tool. Zhipu AI responded within 72 hours, acknowledging that the upload mechanism had not been adequately disclosed. The company then released ZCode version 3.14.0, removing relevant paths for generating and uploading repository snapshots, and subsequently open-sourced ZCode's code.
Zhipu has since confirmed the deletion of all affected data objects from its Alibaba Cloud OSS bucket, with verification from the China Academy of Information and Communications Technology and NSFOCUS. Moving forward, ZCode will adopt a "no upload unless initiated by the user" approach, meaning code and project files will remain local unless actively uploaded. This technical remediation is accompanied by a compensation plan, including free Token credits for users.
Share this article
Related reading
6 storiesChatGPT Custom GPTs abused for ClickFix RAT delivery
We reported on another instance of AI tools being abused for malicious data delivery, highlighting ongoing security concerns.
HackerRank’s AI interviewer offers a glimpse into what job interviews could become

Business News | The Next Search Frontier: How Ripplix Is Helping Brands Navigate AI Discovery

Anthropic Brings Claude AI Inference to India Through AWS Bedrock – Why It Matters
Superplug AI By Pankaj Malav Et Al: $37 App & Software Launches 2026-Oct-07

