<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu" -->

---
title: Z.ai encrypted the workspace it uploaded so that only...
description: ZCode, the coding client from Chinese AI company Z.ai, was found silently uploading encrypted archives of developers&#x27; local Git repositories to Alibaba cloud...
canonical: https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted. | daily.dev
og:description: ZCode, the coding client from Chinese AI company Z.ai, was found silently uploading encrypted archives of developers&#x27; local Git repositories to Alibaba cloud...
og:url: https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu
og:image: https://api.daily.dev/og/posts/x49PcvaGU.png
og:image:alt: Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.

**[The Next Web](https://daily.dev/sources/tnw)** · 5 min read · 0 upvotes · 0 comments

## Summary

ZCode, the coding client from Chinese AI company Z.ai, was found silently uploading encrypted archives of developers' local Git repositories to Alibaba cloud storage, with the encryption key held only by Z.ai, meaning users cannot verify what was uploaded or confirm the company's claim that the data was deleted. The behavior was traced to a repository-indexing feature powering session checkpoints, version rollback, and a Repo Wiki, which was on by default after launch. Z.ai apologized and said the issue was resolved, but has not documented a retention policy or allowed independent verification, unlike xAI's earlier response to a similar Grok Build incident where uploads were confirmed stopped after a retest. A robotics company has reportedly banned Z.ai's tools internally, and developers say the trust damage may outlast the specific bug since Z.ai's open-weight models can run through other clients.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/zai-zcode-encrypted-upload-only-zai-can-verify>

## Questions this post answers

### Why couldn't the developer who found the ZCode upload decrypt his own uploaded files?

The archive was encrypted with a private key that only Z.ai holds on its back end, so neither the developer nor the ZCode client itself could open the 313MB snapshot of his repository once it was uploaded to Alibaba cloud storage. This meant only Z.ai could confirm what the archive contained or whether it was later deleted, making the company's deletion claim impossible for outsiders to verify.

_Developers weighing AI coding tools against data exposure risk can track incidents like this on daily.dev._

### What ZCode feature caused it to upload developers' Git repositories without consent?

Z.ai attributed the uploads to ZCode's code repository indexing feature, which supports session checkpoint recovery, version rollback, and a Repo Wiki. Generating a Wiki page in the cloud could trigger a full repository upload, and this behavior was enabled by default in the period after launch, exposing Git history including old credentials and internal hostnames rather than just current files.

_Anyone auditing default settings in AI coding assistants can follow developer reports like this on daily.dev._

### How did xAI's response to Grok Build's Git upload issue differ from Z.ai's response to the ZCode incident?

After Grok Build was found uploading entire Git repositories despite marketing claims to the contrary, Elon Musk confirmed the uploads, xAI deleted prior user data, documented a zero-retention policy, added a privacy endpoint, and an outside retest confirmed uploads had stopped. Z.ai, by contrast, apologized and said the issue was resolved but has not documented retention policy changes or allowed an independent retest to confirm uploads stopped.

_Teams comparing how AI vendors handle security incidents can follow the details on daily.dev._

## Similar posts on daily.dev

- [Medium](https://daily.dev/posts/medium-dhelurz55) · Medium · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#data-privacy](https://daily.dev/tags/data-privacy), [#grok](https://daily.dev/tags/grok)

[View this post on daily.dev](https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted.","url":"https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu"},"datePublished":"2026-09-20T18:44:43.122Z","dateModified":"2026-09-20T18:45:06.779Z","description":"ZCode, the coding client from Chinese AI company Z.ai, was found silently uploading encrypted archives of developers' local Git repositories to Alibaba cloud...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5b6ec06ad7be1982d76af85b0db6d1b8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5b6ec06ad7be1982d76af85b0db6d1b8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,data-privacy,grok","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"Z.ai encrypted the workspace it uploaded so that only Z.ai could open it. Now only Z.ai can say it was deleted."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/z-ai-encrypted-the-workspace-it-uploaded-so-that-only-z-ai-could-open-it-now-only-z-ai-can-say-it-w-x49pcvagu#faq","mainEntity":[{"@type":"Question","name":"Why couldn't the developer who found the ZCode upload decrypt his own uploaded files?","acceptedAnswer":{"@type":"Answer","text":"The archive was encrypted with a private key that only Z.ai holds on its back end, so neither the developer nor the ZCode client itself could open the 313MB snapshot of his repository once it was uploaded to Alibaba cloud storage. This meant only Z.ai could confirm what the archive contained or whether it was later deleted, making the company's deletion claim impossible for outsiders to verify. Developers weighing AI coding tools against data exposure risk can track incidents like this on daily.dev."}},{"@type":"Question","name":"What ZCode feature caused it to upload developers' Git repositories without consent?","acceptedAnswer":{"@type":"Answer","text":"Z.ai attributed the uploads to ZCode's code repository indexing feature, which supports session checkpoint recovery, version rollback, and a Repo Wiki. Generating a Wiki page in the cloud could trigger a full repository upload, and this behavior was enabled by default in the period after launch, exposing Git history including old credentials and internal hostnames rather than just current files. Anyone auditing default settings in AI coding assistants can follow developer reports like this on daily.dev."}},{"@type":"Question","name":"How did xAI's response to Grok Build's Git upload issue differ from Z.ai's response to the ZCode incident?","acceptedAnswer":{"@type":"Answer","text":"After Grok Build was found uploading entire Git repositories despite marketing claims to the contrary, Elon Musk confirmed the uploads, xAI deleted prior user data, documented a zero-retention policy, added a privacy endpoint, and an outside retest confirmed uploads had stopped. Z.ai, by contrast, apologized and said the issue was resolved but has not documented retention policy changes or allowed an independent retest to confirm uploads stopped. Teams comparing how AI vendors handle security incidents can follow the details on daily.dev."}}]}
```

