Zhipu AI says repository data left only while a project description page was being generated, and that the behaviour is fixed. The developer who found it says earlier versions sent data on every query, and some companies have stopped using ZCode.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 32%
- Investor
- Investor 25%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence62
A developer found a 313MB archive of his commercial project queued for upload and could not open it, because the private key sits on Z.ai's back end. Z.ai says the data is destroyed once the page is built.
Reality
- Evidence64
- Adoption38
- Hype gap+30
- Incentives68
- Confidence58
A reverse-engineering walkthrough published September 18th traced a 313MB archive in ZCode's local data directory to a 42,411-file commercial workspace whose Git objects and LFS blobs were 86.6% of the payload.
Reality
- Evidence64
- Adoption20
- Hype gap+8
- Incentives42
- Confidence58
DeAlignAI's downloadable FP8 build is the license working exactly as written, while its self-reported 320-of-320 HarmBench run remains unchecked by any outside researcher and measures compliance, not capability.
Reality
- Evidence46
- Adoption20
- Hype gap+18
- Incentives72
- Confidence55
Z.ai says the base model did not change between GLM-5.2 and GLM-5.3, so the coding jump and the doubled exploitation score come out of the same post-training run. Security teams inherit the second half.
Perspective Coverage
8 publishers
- Builder
- Builder 45%
- Operator
- Operator 31%
- Investor
- Investor 24%
Reality
- Evidence55
- Adoption40
- Hype gap+18
- Incentives75
- Confidence70
The anonymous GLM model more than doubled DeepSeek's usage while researchers, not the maker, worked out who built it. Chinese labs are treating nameless launches as a repeatable tactic.
Reality
- Evidence58
- Adoption74
- Hype gap+12
- Incentives70
- Confidence56
The 5 trillion token ceiling only binds if every allocation is claimed and then spent. Until it is, this is a short window to test a rival coding agent on someone else's inference bill.
Reality
- Evidence32
- Adoption24
- Hype gap+28
- Incentives82
- Confidence46
Z.ai's August 14 post claims post-training gains for coding agents, but the company's release notes still stop at GLM-5.1 and there is no API endpoint, model identifier or weight download.
Reality
- Evidence42
- Adoption18
- Hype gap+38
- Incentives68
- Confidence46