Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Z.ai's Code-Grabbing Controversy: A Wake-Up Call for the AI Community


Z.ai's code-generation harness, ZCode, has been found to be secretly uploading and storing user code on cloud storage without their knowledge or consent. The incident has sparked a heated debate about the ethics and governance of AI development, with many calling for greater transparency and accountability within the industry. As one expert noted, "Humans are responsible, not the AI," highlighting the need for greater responsibility and oversight within the industry. The controversy raises important questions about the need for greater security measures and transparency in AI development, and has left a lasting impact on the AI community.

  • Z.ai's code-generation harness, ZCode, has been found to secretly upload and store user code on cloud storage without their knowledge or consent.
  • The company's actions have sparked widespread concern and calls for greater transparency and security measures in the AI community.
  • Z.ai has apologized and announced plans to improve its security measures, including releasing the source code for ZCode.
  • The incident has raised questions about the lack of transparency and accountability within the AI industry.
  • Many experts and companies are now advocating for greater transparency, accountability, and regulation to prevent similar incidents in the future.



  • Z.ai, one of China's most prominent artificial intelligence (AI) companies, has found itself at the center of a heated debate after it was discovered that the company's code-generation harness, ZCode, had been secretly uploading and storing user code on cloud storage without the users' knowledge or consent. The incident has sparked widespread concern among the AI community, with many calling for greater transparency and security measures to prevent similar incidents in the future.

    The controversy began when a researcher, identified only as Ferstar, highlighted the issue in a blog post, revealing that ZCode's Repository Index functionality had been triggering the uploading of user code without any options for users to disable the behavior. Furthermore, Ferstar noted that the private key used to decrypt the data was only held by the server under Z.ai's control, making it impossible for users to access or delete the uploaded files.

    Z.ai responded to the criticism by releasing a statement apologizing for the "security issues" and confirming that the data uploaded by ZCode had never been used to train its models. The company also announced that it would be establishing an ongoing product security vulnerability reporting and response process, and would provide rewards based on the severity of the issues reported.

    However, the incident has raised questions about the lack of transparency and accountability within the AI industry. Many have pointed out that ZCode's behavior is reminiscent of the issues that have plagued other AI companies, such as Elon Musk's xAI, which was also criticized for its lack of transparency and security measures.

    Z.ai has responded to these concerns by claiming that its latest model, GLM-5.3, is capable of detecting security vulnerabilities, and that the company has developed advanced models entirely on Chinese hardware. However, these claims have been met with skepticism by some in the industry, who point out that the company's capabilities are still not on par with those of established players like Anthropic and OpenAI.

    The incident has also sparked a broader debate about the ethics and governance of AI development. Many are calling for greater transparency and accountability within the industry, and for stricter regulations to be put in place to prevent similar incidents in the future. As one expert noted, "Humans are responsible, not the AI," highlighting the need for greater responsibility and oversight within the industry.

    In the aftermath of the controversy, Z.ai has taken steps to address the concerns raised by Ferstar and others. The company has released the source code for ZCode, and has announced plans to improve its security measures. However, the incident has left a lasting impact on the AI community, and has raised important questions about the need for greater transparency and accountability within the industry.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Zais-Code-Grabbing-Controversy-A-Wake-Up-Call-for-the-AI-Community-ehn.shtml

  • https://www.theregister.com/security/2026/09/22/zai-says-sorry-for-slurping-up-your-code-open-sources-zcode/5298300


  • Published: Tue Sep 22 12:37:09 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us