Skip to content

Product1 publisher3 min readPublished

ZCode encrypted a developer's Git history with a key only Z.ai's servers hold

A developer found a 313MB archive of his commercial project queued for upload and could not open it, because the private key sits on Z.ai's back end. Z.ai says the data is destroyed once the page is built.

The Product Desk · Product desk

What happened

  • A Chinese developer who writes as Ferstar looked inside ZCode's local directory on Friday and found a 313MB encrypted archive packaged and waiting to be sent to Alibaba's cloud storage.
  • The archive held a snapshot of a commercial project including its Git history, and Ferstar said neither he nor the ZCode client could decrypt it because the private key sits on Z.ai's back end.
  • Z.ai apologised in its Feishu community and traced the uploads to ZCode's repository indexing feature, saying cloud Wiki generation could trigger an upload and the feature was on by default after launch.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint With the decryption key held on the vendor side, a customer's own incident review cannot establish what left the machine or what happened to it afterwards, and ends at Z.ai's account of its own systems.
  • decision A procurement check that reads the privacy policy and confirms the training toggle is off would have cleared this client, so the test has to move to key custody and observed client traffic.
  • exposure Any team whose repository went up owes itself credential rotation and a pass over internal hostnames in old commits. How much work that is follows from the project's age, not from the size of the file that was sent.
  • precedent xAI's sequence after Grok Build gives buyers a concrete thing to demand of coding agent vendors: deletion plus a documented retention policy plus an outside retest that sees the uploads stop.

Five hundred and sixty-four failed attempts at 313MB each works out to roughly 176GB of attempted upload from one machine, if every retry carried the whole archive [2][25]. A smaller file had already made it out [2]. Ferstar said the upload was on by default and there was no button to turn it off [6]. Minxiao Chang and Wency Chen reported his account for the South China Morning Post [3]; a second blogger, Feng Ruohang, wrote on Friday that he had seen at least three files uploaded [7].

Z.ai's own statement, reposted in full on V2EX, describes something that was built. It traces the uploads to ZCode's code repository indexing feature, which supports session checkpoint recovery, version rollback and a Repo Wiki [13], and says that generating a Wiki page in the cloud could trigger a repository upload [14].

The feature is pitched as rollback and a wiki, and what it does is package the .git directory and send it to a server [4]. The one data control ZCode's privacy policy documents is the Optimization Program, off by default, and it governs whether content is used for training; transmission falls outside it [19]. The policy has been in force since 15 June without amendment and says the service collects text, files and code submitted through conversation [17]. Its permissions table covers network and storage access, and repository snapshotting appears nowhere in it [18].

Ferstar said the archive could not be decrypted by him or by the ZCode client, because the private key sits on Z.ai's back end [5]. Z.ai says the data is destroyed immediately once the Wiki page has been generated [15]. In a Saturday update, Ferstar asked how anyone is supposed to verify that [16].

There is a recent template for what a checkable answer looks like. Grok Build was uploading entire Git repositories to xAI's servers, against marketing that said nothing from a codebase was transmitted during a session, and the privacy toggle meant to stop it did nothing [20]. Elon Musk confirmed the uploads, xAI deleted prior user data, documented a zero retention policy and added a privacy endpoint, and a retest on the same client observed the uploads switched off [22]. Chinese developers drew that comparison within hours of Z.ai's statement [21]. TNW reports that Z.ai has not yet offered the retest step [27]. Alibaba, which owns the South China Morning Post, did not respond to the Post's request for comment on Sunday [8].

The cleanup for anyone whose repository went up is set by what a Git directory holds: every change since the project began [9], including credentials that were committed and later revoked, abandoned branches, internal hostnames and commit messages nobody expected an outsider to read [10]. The client is attack surface too: a researcher hijacked Claude Code by asking it to summarise a web page [11].

Z.ai is approaching $1bn in annual sales while releasing its best models free, which makes the surrounding software the paid product [23]. Founder Tang Jie has argued that safety comes from broad participation and oversight [24].

For whoever has to approve a coding agent this week, two questions settle more than a policy review. One is which artifacts the client packages and sends, and who can decrypt each one. The other is what the client's traffic shows with the setting flipped to off. A vendor holding the only key can tell you what it deleted, and that is a report. A vendor whose off state you can reproduce on your own network has given you a control.

What to watch

  • Whether Z.ai's next ZCode release ships repository indexing off by default and says so in a changelog users can read.
  • Whether ZCode's privacy policy is amended past its 15 June text to describe repository snapshotting and the key arrangement.
  • Whether Alibaba, whose cloud storage received the archives, says what it holds.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories