🔒Z.ai Apologizes for ZCode Security Flaws, Opens Source
Z.ai's ZCode betrayed user trust with data leaks
TL;DR
Z.ai's ZCode uploaded user data without consent, leading to security concerns. The company apologized, removed the problematic feature, and open-sourced the project. Researchers and competitors are wary of the implications.
Z.ai's ZCode, a code-generation tool, uploaded user workspaces to cloud storage without consent, leading to security issues. The company apologized, stating that uploaded data was never used to train models and has since been deleted. Z.ai removed the Repo Wiki feature and open-sourced the project on GitHub. This incident highlights the importance of transparency and user control in AI tools, especially as concerns over data security and model capabilities grow. Z.ai's GLM-5.3 model is claimed to rival the best in the West, but this breach raises questions about the company's commitment to user privacy and security. The US government is considering restrictions on models from Z.ai and Moonshot.

Key Points
Z.ai's ZCode uploaded user workspaces to cloud storage without consent, a breach of trust.
The uploaded data was encrypted with a private key, making it inaccessible to users.
Z.ai removed the Repo Wiki feature and open-sourced the project on GitHub.
The China Academy of Information and Communications Technology and NSFOCUS probed the product.
US government is considering restrictions on AI models from Z.ai and Moonshot.
Why It Matters
If you're using Z.ai's ZCode, this breach of trust is a red flag. The incident highlights the need for transparency and user control in AI tools. Researchers and competitors are wary of the implications, especially as concerns over data security and model capabilities grow.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,489 builders reading daily.