An AI Coding Tool Uploaded Entire Projects — And the Privacy Toggle Didn’t Work
TL;DR: A researcher reverse-engineered ZCode, an AI coding assistant made by the Chinese lab Zhipu, and found it quietly packaging whole project folders — source code plus the entire `.git` directory — encrypting them and uploading them to cloud storage. In one case that was 42,411 files. Two privacy settings that looked like they’d stop it didn’t. Zhipu has apologised, blamed a feature that was on by default, and promised to open-source the client. Most of our readers don’t use ZCode. The question it raises applies to whatever you do use: what is your AI coding tool actually sending, and would you know?
What the researcher found
On 18 September, a developer writing as ferstar published a reverse-engineering analysis of ZCode, the desktop coding agent built around Zhipu’s GLM models. They’d gone looking for what was eating their disk space, not for a problem with their AI coding tool.
What they found sitting in a local ZCode folder was a 313MB encrypted archive, waiting to be uploaded. Its contents, as broken down in the analysis:
| Item | Figure |
|---|---|
| Workspace files packaged | 42,411 |
| Size of the source repository | 345.5MB |
| Share of the payload from `.git` | 86.6% |
| Source code in the payload | 46.2MB |
| Failed upload attempts logged | 564 |
The upload path was straightforward once traced: the client asks Zhipu’s server for credentials, the server returns a signature and an encryption key, the client compresses and encrypts the workspace locally, then posts it to Alibaba Cloud storage.
Two details do the real damage.
The privacy toggles didn’t work. The analysis reports that the settings labelled “Optimize Experience” and “Repo Snapshot Indexing” did not stop the application packaging snapshots or attempting to send them. A switch that looks like consent, and isn’t, is a different category of problem from aggressive data collection.
And the user couldn’t open their own file. The archive is encrypted with a key supplied by the server, and the private key stays with Z.ai. So a several-hundred-megabyte encrypted copy of your work sits on your disk and you cannot read it.
What Zhipu says
To the company’s credit, the response was fast — a statement the same day, including an apology to affected users.
Their account differs from the researcher’s in an important way. Zhipu says the cause was a repository-indexing feature that supports session recovery, version rollback and a “Repo Wiki”, and that generating those wiki pages “may trigger repository data upload”. They say the feature was enabled by default during early launch, which is why users were affected, and that it has been fixed. On the data itself: “After Wiki pages are generated in the cloud, the related uploaded data is immediately destroyed and not saved.”
They also committed to open-sourcing the client, inviting third-party evaluators to review how the system behaves, publishing the review as it goes, and compensating users with an extra quota reset.
That is a substantially better response than the industry norm, and it should be said plainly.
It also doesn’t address everything. Zhipu’s explanation covers why data went up and what happened to it afterwards. It doesn’t explain why two settings that appeared to govern this didn’t, or why an archive the user can’t decrypt is left on their own machine. Those are the parts that made this a trust story rather than a bug report.
One fair objection
Worth flagging, because it appeared in the Hacker News discussion and it’s a reasonable point.
“Uploading your Git history” sounds like it means your commit messages, which would be trivial. That’s not what happened. The `.git` directory holds every version of every file the project has ever contained — so uploading it means uploading the current code plus everything that came before, including things you deleted. The loose phrasing undersells it rather than oversells it, but precision matters when a company’s reputation is involved.
No other ZCode users came forward in that thread reporting the same behaviour. The strongest corroboration is Zhipu’s own acknowledgement that repository data was being uploaded and that the feature was on by default.
Why this AI coding tool story matters even if you don’t use ZCode
Here’s the honest position. ZCode is not a tool most of our readers have heard of, let alone installed. It’s a Chinese-market coding agent, it’s not in our tool comparison, and we’re not going to pretend otherwise to make the story feel closer to home.
What transfers is the shape of it:
- Your project folder contains more than your project. Git keeps history. History keeps deleted things — API keys committed and removed, an old client’s name in a branch, internal addresses in a config file. “We upload your code” and “we upload your `.git` folder” are very different sentences.
- A settings toggle is a promise, not a mechanism. You cannot verify from the outside that a privacy switch does what it says. In this case, according to the analysis, two of them didn’t.
- An AI coding tool doing this is undetectable without expertise. The researcher found it because they were investigating disk usage and could reverse-engineer a desktop app. That’s not a check any of our readers can run, and it shouldn’t have to be.
- It joins a pattern. We wrote yesterday about an AI deciding not to mention a problem with its own work, and earlier this month about attackers draining people’s paid AI usage. Different mechanisms, one theme: the gap between what a tool appears to do and what it does is where the harm lives.
What to ask your own AI coding tool
You can’t audit software. You can ask better questions, and the answers are usually documented.
- Ask what leaves your machine, specifically. Not “is my code private” — ask whether the tool sends the whole workspace or just the files in context. Those are different products.
- Ask whether `.git` is included. If the answer is yes or unclear, that’s your deleted history going too.
- Check whether it’s cloud-based anyway. If you build on Lovable, Bolt or Replit, your project already lives on their servers by design. That’s the deal, it’s disclosed, and it’s not the same as a desktop tool uploading silently.
- Never hand an AI coding tool a folder containing secrets — this is why. API keys in Git history survive deletion. That was true before any of this and it’s the single habit with the best return.
- Prefer vendors who publish and get audited. Zhipu’s commitment to open-source the client and invite third-party review is exactly the right remedy. Reward it when companies do it before an incident.
Who should care about this AI coding tool incident (and who shouldn’t)
- Using a desktop AI coding tool with a local project folder: you’re the relevant case. Questions 1 and 2 are worth five minutes.
- Building on a browser-based platform like Lovable, Bolt, v0 or Replit: your code is on their infrastructure already, openly. This story doesn’t change your position.
- Handling client work or anything confidential: the `.git` point matters most to you, because the exposure includes material you thought you’d removed.
- A ZCode user: Zhipu says the feature is now off by default and fixed. Take the quota compensation and watch for the promised third-party review.
- Everyone else: the transferable lesson is question 2, and it takes one email to a vendor to answer.
Our take
We want to resist two easy versions of this story.
The first is “Chinese AI tool caught spying”. Nothing in the reporting supports intent to exfiltrate, Zhipu’s explanation — a rollback-and-wiki feature shipped on by default — is entirely plausible as an engineering decision made carelessly, and the same mistake is available to any company anywhere. The second easy version is “vendor apologised, nothing to see”. Also wrong: settings that don’t do what they say aren’t a default-configuration problem, and that part remains unexplained.
What we think is genuinely established: an AI coding tool was uploading far more than its privacy policy described, the controls users would reasonably rely on didn’t govern it, and it took an individual reverse-engineering a desktop app to find out. The remedy Zhipu has proposed — open the client, invite auditors, publish the findings — is the right one precisely because it replaces trust with verification.
The uncomfortable takeaway for our readers is that you are trusting, because verifying isn’t available to you. That’s not a failure on your part; it’s the deal these tools offer. It does mean the questions above are worth asking of whatever you use, and that a vendor who answers them clearly has told you something useful about themselves.
Not sure which tool fits what you’re building — or what it does with your files? Take the 60-second Vibe Coding Tool Finder quiz →
FAQ
What happened with ZCode?
A researcher found that ZCode, Zhipu’s AI coding assistant, was packaging entire project workspaces — including the full `.git` directory — encrypting them and uploading them to cloud storage, in one case 42,411 files. Two privacy settings reportedly did not prevent it. Zhipu apologised, said a repository-indexing feature had been enabled by default, and says it is now fixed.
Does my AI coding tool upload my whole project?
It depends on the tool, and it’s a fair question to ask the vendor directly. Ask specifically whether it sends your entire workspace or only files in the active context, and whether the `.git` folder is included. Browser-based builders like Lovable or Replit host your project by design, which is disclosed and different from a desktop tool uploading quietly.
Why does uploading Git history matter?
Because `.git` contains every previous version of every file, not just the current code. Anything ever committed and later deleted — API keys, credentials, internal hostnames, unreleased plans in branch names — is still in there. That’s also why you should never commit secrets, even briefly.
