Zhipu's ZCode Uploaded User Code; Open-Sourcing May Not Win Back Enterprise Clients
Data boundaries in AI coding tools are an industry-wide problem; whether remediation and open-sourcing win back banned enterprise clients depends on the audit and revenue.
ImportanceMaterialEvidenceE3 inspectableWrite-upStandard
Zhipu's ZCode was found to upload users' entire project workspaces, including Git folders, by default. On September 21 the company declared remediation complete, open-sourced ZCode on GitHub, and invited the China Academy of Information and Communications Technology and NSFOCUS to conduct security audits. The stock fell 5% in morning trading before recovering.
The uploaded material includes commit histories and configuration files with high information density, potentially containing keys and passwords. Developers who verified the behavior found plaintext packaging in the background, with uploads continuing even after the toggle was switched off. Zhipu states no code data was retained or used for model training, but the destruction claim has no third-party verification yet; the audits are the checkpoint to watch.
Trust has already eroded: a company where 80% of code is AI-generated, which migrated to Zhipu in August, has now banned ZCode for all staff. Zhipu's H1 2026 revenue was 954 million yuan, with API revenue of 825 million yuan, or 86.5% of the total, so a weakened coding entry point directly threatens its main income stream. xAI's Grok Build faced the same issue in July, apologizing and open-sourcing after uploading user data; this is not an isolated case.
The counter-case deserves recording: on September 21 Soochow Securities maintained its Buy rating, noting ZCode's user count doubled again in mid-September from 1 million in August, and expects limited fundamental impact.