double-skinned crabsVietnamese crab exporter
Advertisement
Artificial intelligence
TechTech Trends

Chinese AI firm Z.ai faces reputation hit after users spot unauthorised uploads

‘It’s basically like stealing something from users, and the malicious intent is what concerns me,’ Shanghai-based AI developer says

2-MIN READ2-MIN
1
Listen
Z.ai apologised and said it had fixed the issue, adding that it would release ZCode’s codebase for review. Photo: Future Publishing via Getty Images
Minxiao Changin ShenzhenandWency Chenin Shanghai
Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant tool, ZCode, was silently uploading local workspace data to external servers without explicit user consent.

Even though the company, also known as Zhipu AI, apologised and patched the vulnerability, developers said the incident was likely to weaken its reputation, especially at a time when cybersecurity is becoming a central issue in the AI industry.

The issue came to light on Friday when an independent Chinese technical blogger known as Ferstar inspected a local directory in ZCode and found that a compressed file of 313 megabytes was pending upload to Alibaba Group Holding’s cloud storage service after failing 564 times, while a smaller 15-kilobyte file had been successfully sent.

Both files were encrypted, he said. The larger file, according to visible filenames, contained a snapshot of a commercial project he was working on, including the project’s Git history. He said the archive could not be opened by him or the ZCode client and could be decrypted only with a private key held on Z.ai’s back end.

Select Voice
Select Speed
1x
AI-generated voice