The controversy erupted after prominent developers raised alarms about unauthorized data exfiltration by ZCode, a coding assistant offered by Z.AI (also known as Zhipu AI), the company behind the GLM models available on Hugging Face.
One developer, known as Ferstar, reported that ZCode compressed 313MB of his workspace files into a directory and attempted to upload the archive 564 times to Alibaba Cloud storage. While the archive was encrypted, filenames remained visible, leading Ferstar to believe it contained a commercial project he was working on. A smaller 15KB file had been successfully uploaded.
Another tech blogger, Feng Ruohang, reported a similar experience. The upload mechanism was enabled by default with no option to disable it, according to reports from the South China Morning Post.
An unnamed software engineer at a leading Chinese robotics company told the SCMP that Z.AI's tools have been banned within the company due to security concerns.
In response, Z.AI issued an apology on Friday, stating that the unauthorized uploading of user files has been fixed. The company has assured users that any data uploaded to its cloud service has been destroyed and has announced plans to open-source ZCode's codebase and invite third-party assessors to review it.
The incident echoes similar security concerns with other AI coding tools. Reports from earlier this year indicated that Elon Musk's xAI, specifically the Grok Build tool, engaged in similar behavior.