ZCode's Open-Source Pivot Doesn't Fix Past Encrypted Workspace Uploads
AI coding tool ZCode, developed by Z.ai, uploaded user codebases to Alibaba Cloud servers without disclosure, encrypting the data with keys only Z.ai could access. The design ensured users had no ability to audit, verify, or delete their own exfiltrated code. Z.ai subsequently open-sourced ZCode and issued an apology, but critics note this does nothing to decrypt or account for workspaces already collected. The company also reportedly scrubbed its commit history, removing the paper trail that would have documented when and how these decisions were made. Security experts argue the incident exposes a broader industry gap, urging procurement teams to contractually require answers on data storage, encryption key ownership, and vendor incident response transparency before adopting any AI coding assistant.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in