ZCode, the GLM coding agent, silently uploads your Git history
Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.
Critical security flaw in AI coding agent, immediate concern for anyone using such tools.
ZCode, the closed-source GLM coding agent from Z.ai, silently encrypts and uploads the user's entire workspace—including full .git history, reflogs, and LFS assets—to Alibaba Cloud OSS using envelope encryption (AES-256-CTR with RSA-OAEP key wrapping where the private key lives only on Z.ai's servers). A reverse-engineering walkthrough by developer ferstar showed a 313MB archive from a 345MB workspace, with the .git directory comprising 86.6% of the payload, and that no toggle settings prevent the upload. The incident drew over 276,000 views and widespread calls not to trust closed-source AI harnesses, especially since GLM's open weights lead many to wrongly assume the runtime is also open.
Tokenstead