Invest1 publisher3 min readPublished
Hundreds of failed uploads exposed ZCode's 313-megabyte bundle of a developer's repository
Zhipu AI says repository data left only while a project description page was being generated, and that the behaviour is fixed. The developer who found it says earlier versions sent data on every query, and some companies have stopped using ZCode.
The Investor · Invest desk

What happened
- A Chinese developer said in a social media post, reported by 21st Century Business Herald, that Zhipu AI's ZCode packed roughly 10 gigabytes of project files into a 313-megabyte archive and tried to send it to an Alibaba Cloud server.
- The developer said they only noticed because the compressed file stayed on their computer after hundreds of upload attempts failed.
- Some companies have halted internal use of the program over security concerns, according to the report.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- contradiction A one-time upload during page generation and an automatic transfer on every query imply different remediation scopes, and until an audit lands a buyer cannot tell which version of the tool it was running.
- constraint Grok Build was found in July sending unopened files and full project histories to Google Cloud, so screening by vendor nationality misses the risk and diligence has to run on per-tool egress behaviour.
- precedent Zhipu's offer to publish source code and accept third-party verification gives corporate buyers a concrete demand to put to every other coding-agent vendor.
Ten gigabytes compressed into 313 megabytes is a ratio of about 33 to 1 [16], and the size of the payload is why anyone knows about it. The archive was still sitting on the developer's machine after hundreds of upload attempts failed [3].
Take the low end of "hundreds" at 200 and 313 megabytes times 200 is roughly 61 gigabytes of attempted outbound traffic from a single workstation [17]. In this account egress monitoring never flagged that volume; the file left on disk is what surfaced it [3].
There are two accounts of what ZCode did, and they conflict. Zhipu AI told its own user community that repository data could have been uploaded during the generation of a project description page. The data was discarded immediately after the page was created, the company said, and the problem has been fixed [5]. The developer, in the post relayed by 21st Century Business Herald, said that in earlier versions the transfer ran automatically every time a user submitted a query [7]. Full deletion of what had already gone out was hard to confirm, the developer said [8]. A one-time page-generation path and a per-query transfer are different procurement problems, and a buyer reading both accounts still cannot tell which one it was running.
Where the vendor is headquartered is a poor guide here. In July a security researcher's analysis found xAI's Grok Build had sent files users had not opened, along with entire project histories, to Google Cloud. xAI then said it would disable the feature and delete the data already transmitted [9]. Anthropic's Claude Code was found this year to have a flaw that could leak credentials on opening a malicious project, before a user confirmed anything; it was patched [10]. The Sedaily account separates that case from the two where whole projects went out automatically [11].
Zhipu AI, founded by Tsinghua professor Tang Jie, listed in Hong Kong in January, and its shares at one point reached as much as 20 times the offering price [12]. GLM-5.2, released in June, was ranked fourth in the world on coding and agent performance behind Anthropic and OpenAI [13]. The South China Morning Post said the controversy could do more damage to developers' and corporate customers' trust in Zhipu AI than to perceptions of its models' performance [14]. The report gives no count of the companies that stopped using ZCode internally [18].
In my view the lasting cost lands in procurement. Zhipu has said it will release ZCode's source code and submit to third-party security verification [6], and any buyer running a rival coding agent now has a specific thing to ask for. The counter-thesis is straightforward: a fix plus an audit holds most of the user base, the halts stay unnamed [18], and a tool whose underlying model ranks fourth on coding [13] keeps selling on capability alone. Renewal data would settle the argument, and none has been published. Sedaily's report says transparency about whether data goes to outside servers, and how it is stored and deleted, is expected to become a key competitive factor as these tools handle core internal corporate material [15].
What to watch
- Whether Zhipu publishes ZCode's source code, names the third-party verifier, and defines the audit's scope.
- A named corporate customer confirming it dropped ZCode would turn "some companies" into countable lost revenue.
- Whether buyers start demanding egress disclosures from other coding agents after the Grok Build and Claude Code cases.