
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage.
In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI was scrutinized in July, Z.ai’s code-generation harness wing, ZCode, was found packaging and git-encrypting entire user workspaces, including complete project histories, and shipping them off to Alibaba Cloud.
Worse still, the private key used to decrypt the data was only held by the server under Z.ai’s control, meaning users could not access the files ZCode had uploaded, nor delete them.
Ferstar, the researcher who first highlighted the issue, claimed there was no option for users to disable the behavior in their settings, and there was no disclosure of the practice in ZCode’s privacy policy.
They said the core problem lay with the tool’s Repository Index functionality, which triggered the uploading of files after Repo Wiki generated pages in the cloud.
ZCode released a statement on Monday apologizing for the “security issues” and confirming the data it uploaded had never been used to train its models.
“We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process,” it Xeeted.
“We welcome developers to continue reviewing ZCode and reporting potential issues, and we will provide rewards based on the severity of the issues reported.”
ZCode said it tasked the China Academy of Information and Communications Technology (CAICT) and Beijing security company NSFOCUS to probe its product following the implemented changes.
The company claimed the two outside assessments concluded that all the previously uploaded data has now been deleted and said the Repo Wiki feature was removed.
ZCode also open sourced the entire project on GitHub, “placing the code under community scrutiny and making ZCode more open and transparent.”
“Once again, we sincerely apologize and welcome continued scrutiny from the community. The full security assessment report will be released soon.”
Ferstar confirmed the open sourced code showed no signs of the Repo Wiki still being implemented, but criticized the company for wiping commit records and the source code ZCode used to upload files pre-patch.
For the uninitiated, Z.ai, formerly known internationally as Zhipu, is among the world’s AI heavyweights and one of the most heavily backed LLM-focused companies in China.
It is the first AI company in the post-Gen AI era to launch and subsequently IPO on the Hong Kong Stock Exchange. Other Chinese AI giants are publicly traded, such as Alibaba and Baidu, but these were all established well before the AI era began.
Z.ai is a startup with its roots in academic research. It spun out of Tsinghua University’s Knowledge Engineering Group research lab in 2019 and now develops AI models that it claims compete with the best in the West.
Last month, the company claimed that its latest model, GLM-5.3, is as good as the most advanced equivalents developed by Anthropic and OpenAI at hunting for security vulnerabilities.
Z.ai has also previously claimed the accolade of developing the first advanced model entirely on Chinese (Huawei) hardware.
Meanwhile, the likes of Anthropic and OpenAI have reportedly expressed concern over the capabilities of models from Z.AI and Moonshot, while the US government mulls restricting access. ®