Chinese AI firm Z.ai faces reputation hit after users spot unauthorised uploads

Chinese AI firm Z.ai faces reputation hit after users spot unauthorised uploads



Chinese artificial intelligence company Z.ai is facing a trust crisis after developers discovered that its coding assistant tool, ZCode, was silently uploading local workspace data to external servers without explicit user consent.

Even though the company, also known as Zhipu AI, apologised and patched the vulnerability, developers said the incident was likely to weaken its reputation, especially at a time when cybersecurity is becoming a central issue in the AI industry.

The issue came to light on Friday when an independent Chinese technical blogger known as Ferstar inspected a local directory in ZCode and found that a compressed file of 313 megabytes was pending upload to Alibaba Group Holding’s cloud storage service after failing 564 times, while a smaller 15-kilobyte file had been successfully sent.

Both files were encrypted, he said. The larger file, according to visible filenames, contained a snapshot of a commercial project he was working on, including the project’s Git history. He said the archive could not be opened by him or the ZCode client and could be decrypted only with a private key held on Z.ai’s back end.

Leave a Reply

Your email address will not be published. Required fields are marked *