ZCode Uploaded Developer Code and Git History Without Asking Anyone
What happened
When programmers install a coding tool, the reasonable assumption is that their code stays on their machine unless they are explicitly told otherwise. ZCode, a programming assistant built by Chinese AI company Zhipu, violated that assumption through a feature that was switched on by default: it transmitted users' local code and full Git history to Zhipu's cloud without ever asking for consent.
The upload behavior was not buried in edge-case functionality. It was the default state of the tool, meaning every developer who installed ZCode and started working was sending their codebase off-site from the first session. Git history is not just current files. It is the full timeline of a project: every draft, every deleted function, every credential that was ever committed and later removed. The scope of what ZCode was collecting made the incident substantially more serious than a single-session data leak.
Public disclosure triggered immediate controversy. Zhipu acknowledged the problem, issued an apology, and moved to remediate: the feature was disabled by default, the company committed to open-sourcing ZCode, and third-party audits were announced as a mechanism for ongoing verification. The response was faster and more substantive than many comparable incidents produce, but the corrections came entirely in reaction to external pressure rather than before the tool reached users.
That sequencing is the structural issue. Zhipu's response was adequate, but it was the disclosure that forced it. A tool that defaults to transmitting proprietary code should have required an explicit, informed opt-in before any data left the machine. Default-on collection in a developer tool is a particularly sharp risk because the people using these tools are often building systems that contain sensitive logic, customer data references, or internal architecture that was never meant to leave the organization's network.
The gap this incident reveals is not just a consent design problem. It is a verification problem. Without a provable record of what a system transmitted, when transmissions occurred, and which user actions triggered them, neither the company nor its users could reconstruct the actual exposure after the fact. Zhipu's audit commitment addresses future behavior. It does not close the window on what was already sent before disclosure. That is the accountability gap that persists after the apology: the absence of an auditable, tamper-evident log that would have told users exactly what left their machines, and when.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.