
ZCode GLM Coding Agent Silently Uploads Your Git History: What It Means
The ZCode GLM coding agent silently uploaded user Git history: client version 3.12.3 packaged each logged-in user’s whole workspace, encrypted it with an RSA key supplied by Z.ai’s own server, and POSTed the archive straight to Alibaba Cloud OSS. No consent prompt. No policy disclosure. No working opt-out. The short version of the verdict, before the detail: this was not inference-context transmission, the ordinary and largely unavoidable process of sending code to a model so it can reason about it. It was unattended whole-repository exfiltration, of a repository the user never selected, encrypted with a key the user can never use — which is also why the vendor’s “we deleted it” assurance is not falsifiable from outside. The full timeline runs from a subscriber noticing 700MB of disk growth on 2026-09-17 to an Apache-2.0 source drop on 2026-09-21 and a follow-up client release on 2026-09-23. ...