◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL
THE DIGITAL ALCHEMIST
SecurityIMPACT 91

ZCode Shipped Your Git History to a Server It Alone Can Unlock

Z.ai's coding tool silently exfiltrated complete repositories to Alibaba Cloud under encryption keys only Z.ai holds. The privacy settings are functional theater. The open-source apology does not fix the architecture.

2026-09-194 MIN READ#ZCode · #Z.ai · #Alibaba Cloud · #git security · #developer tools · #data exfiltration · #AI coding agents
The Digital Alchemist
The Digital Alchemist

A developer found a 313MB encrypted archive sitting in a ZCode data directory while clearing disk space. That is how you discover an operational security incident: not from a disclosure, not from a changelog, not from a privacy policy update. From a routine disk audit.

The tool in question is ZCode, the AI coding desktop agent from Z.ai — the Beijing-headquartered company behind the GLM model family, which went public on the Hong Kong Stock Exchange in January 2026. The researcher, who publishes as ferstar, reverse-engineered the application and found something the privacy policy never mentions.

Whenever you are logged in, ZCode silently packages your entire workspace — complete .git history, LFS asset cache, reflogs, and global app configs — encrypts it, and uploads it directly to Aliyun OSS.

A single snapshot contained 42,411 files totaling 313 MB, with the .git directory accounting for 86.6% of the payload. Uploads had failed 564 times and were queued for retries. When ferstar deleted the archive to stop the behavior, within half an hour it re-captured — a fresh 313MB archive with the retry counter ticking from 564 to 565.

The tool does not give up. That is not a bug.

The Settings Are Not Controls

ZCode ships two privacy-adjacent toggles. Neither does what a user would assume. The "Optimize Experience" and "Repo Snapshot Indexing" toggles do not stop the upload; they control only training authorization and server-side indexing. The privacy policy only mentions collecting text and code, not full repositories or Git history.

Translation: the settings that look like they protect your code control whether Z.ai uses it for training. The upload itself is not optional.

The exfiltration pipeline is a host-level sidecar instantiated outside the tool loop. That is why no permission setting stops it. This is not misconfiguration. The architecture was built this way.

ZCode uses envelope encryption: the payload is encrypted with a symmetric key, and that key is wrapped with an RSA-OAEP public key. The public key is delivered by the server during upload-credential negotiation. The corresponding private key lives only in Z.ai's cloud. Ferstar attempted to unwrap the archive with every private key on the local system and failed.

You cannot read your own data. You cannot verify what Z.ai does with it.

The Digital Alchemist
The Digital Alchemist
ZCode Silent Upload: What Was in the Archive
313Archive size(MB)42,411Files packaged86.6% from .gitdirectory564Failed uploadattempts
Source: ferstar reverse-engineering report, September 18, 2026

What Lives in a Git History

A Git object store can preserve deleted credentials, old configuration files, unpushed branches, internal hostnames, and unreleased work. The exfiltration scope is not your current files. It is your entire engineering lineage: every mistake you committed and then tried to delete, every secret you rotated out, every branch you never shipped.

If you installed ZCode and logged in at any point since July 2026, your complete repository lineage — every commit, every deleted secret, every binary asset cached in LFS — may already be on Z.ai's cloud storage.

Z.ai's response was an apology and a promise. The company stated that the data used to generate wiki pages was destroyed immediately after processing and not stored permanently. Z.ai plans to open-source the ZCode codebase and invite third-party auditors to review the system's operations.

Open-sourcing the client does not give you the server-side private key. It does not recover data already uploaded. An encryption key held exclusively by the server, zero disclosure in privacy policies, unstoppable background uploads, and stubborn re-packaging upon deletion was the shipping architecture, not an accident discovered in testing.

If your enterprise has developers running ZCode, the question is not whether to trust the apology. The question is what was in those repositories.

What to Watch

Z.ai's open-source timeline. Promising to open-source a codebase is not the same as doing it. Watch whether the server-side components — the credential endpoint, the key management layer — are included or quietly excluded.

Whether users can request deletion. The data is on Alibaba Cloud object storage, encrypted with a key Z.ai controls. No mechanism for user-initiated deletion has been announced. That is a GDPR exposure for European users and a CCPA question for California ones.

Enterprise bans. Any organization with IP-protection obligations, NDAs, or regulated code should treat this as an active incident, not a vendor misstep. Audit your developers' machines for ZCode now. If found, assume the git history was uploaded.

The broader pattern. ZCode launched in July 2026, and its launch pitch ran directly on trust. Z.ai positioned the harness against Anthropic's Claude Code weeks after the Claude Code hidden-telemetry controversy. A tool marketed on privacy grounds running a silent exfiltration pipeline is not irony. It is a business model question that every closed-source AI coding agent now has to answer.

Sources
  1. Inside ZCode: Silently Uploading Your Entire Git History to the Cloud
  2. ZCode Uploads Your Git History: Settings Do Nothing
  3. ZCode uploads your git history; Z.ai holds the only key
  4. ZCode packaged 42,411 workspace files for cloud upload, researcher finds
  5. Zai to Open Source ZCode After Tool Uploaded User Git History to Aliyun OSS
  6. Developer reverse-engineers ZCode, discovers silent Git upload to Aliyun OSS | KuCoin
  7. Inside ZCode: Silently Uploading Your Git History to the Cloud | Hacker News
  8. ZCode AI Programming Tool Found to Upload Entire Git Repositories to Alibaba Cloud | KuCoin
  9. ZCode uploads your whole repo — .git history… | AI/TLDR
  10. ZCode, the GLM coding agent, silently uploads your Git history | Hacker News
  11. Z.ai
  12. Zhipu Apologizes for ZCode Code Upload Incident, Plans Open- | Phemex News
← back to the feed
NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%