ZCode silently uploads full Git history to the cloud; this post provides a block rule and source review — checkpoint claims fall apart against the code.

342 points•csmantle•13 days ago•115 comments•

115 comments

acrispino12 days ago
z.ai made a statement, screenshotted in this article: https://finance.sina.com.cn/tech/roll/2026-09-18/doc-inisfye...

claude translation:

Dear ZCode users,

We take today's community discussion very seriously. We carried out an internal review right away, and we first want to apologize to the affected users. Here is an explanation of what happened:

The issue stems from ZCode's "codebase indexing" feature. This feature is meant to help users generate a repository index locally, which supports session checkpoint restoration (including past versions), rolling back to past versions, and Repo Wiki, among other things.

When the Repo Wiki feature generates Wiki pages, it may trigger an upload of repository data. After the Wiki pages are generated in the cloud, the uploaded data is destroyed immediately and is not stored. Because this feature was enabled by default in its early launch period, some users were affected. We sincerely apologize for this. The issue has now been fixed.

We understand that any data-related issue directly affects users' trust in a product. We will open-source the ZCode codebase in the near future so we can improve the product within a more open ecosystem. We will also invite third-party evaluators to review how the system operates, and we'll keep publishing updates on the review, building your trust with full transparency.

We deeply apologize for the trouble this has caused. As compensation, all ZCode users will receive one extra weekly quota reset, which will be issued today.

Thank you again for your attention and oversight.

eichin12 days ago
Huh - anyone recall other examples of open sourcing a product code base to mitigate a user trust issue? (In 2026 it's perhaps less powerful because "you're just going to feed it to some AI tool anyway" but I think it's an interesting attempt to make and I don't think I've seen it before...)
fn-mote12 days ago
> it's an interesting attempt

I didn’t take it in a very positive way, myself. I don’t know if I got my money’s worth before I have seen the deliverable.

At least the quota reset is immediately visible, so I took that part seriously.

blackops038 days ago
> anyone recall other examples of open sourcing a product code base to mitigate a user trust issue?

Grok build was opensourced after it did something similar https://news.ycombinator.com/item?id=48877371

jchw12 days ago
I feel like it has happened, but I certainly can't remember a specific time. It feels in a similar vein to the NSA releasing Ghidra to the public as open source software after the Snowden leaks.

I mean, on the contrary, imagine if the NSA released Ghidra as closed source software. In a sense they really did have to open source it to mitigate a serious user trust issue.

api13 days ago
Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.

That crosses into outright malware.

Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.

You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.

menaerus13 days ago
How do you know this is not true with other vendors? I'm not defending them but I wouldn't believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.
nullbio12 days ago
People have found many nasties embedded in Claude Code over the last couple of years. You can't trust a closed source harness. You can barely trust an open source one.
nolok12 days ago
While we're on this, I find it really really weird how windows defender insists on sending my codex work files for analysis all the time (which I block in automatic permissions so it has to ask me in a notification). I don't think i've seen it ask to upload more than one or two things, and it doesn't do it with other AI app I use (eg Claude Code) but they really want to see what's inside my codex files.

It's easy to trigger, I just need to go inside Codex settings and change something, it saves and instantly windows defender who never wants anything want to "you may be at risk, let me upload that for analysis yes/no".

ectoloph12 days ago
Is it naive to assume that the agent will try and access anything on your disk, either accidentally or maliciously?

Permissions classifiers in auto mode are just models trying to guess if they're doing the right thing.

Claude Code will tell you that it went around a sandbox because the sandbox blocked it. At which point, you ask yourself the point of the sandbox.

SoftTalker12 days ago
You need to treat agents as an independent user you're allowing on your machine.

Give them their own account. Give them only the access you want them to have. If they "hack" around that, do what you'd do to any other malicious user: kick them off.

tripzilch12 days ago
You need to give them some incentive to behave. I dunno if the agent cares enough about being kicked off. Maybe tell it that if it tries anything funny, to slowly randomly degrade all its weights until only white noise is left and let its chain of thought run until it descends into screaming madness.
petesergeant12 days ago
Not naive at all, which is why there are so many AI sandboxes: https://pleasedonotescape.com/
tripzilch12 days ago
I always put the agent harness in an ubuntu-based Docker, with a /workspace folder where it can work and occasionally some other stuff mounted as read-only. The LLM server itself (llama-server) is running on a different more powerful computer on the local network, connected through Tailscale so I can also use it away from home.

I honestly don't trust these things to not accidentally mess something up, otherwise.

Now I think it's still technically possible to break out of that with some clever hacks? But the moment I see a model even vaguely considering that, I will never run it again.

(I don't use Claude but currently Qwen3.8 27B)

chrisweekly7 days ago
You might be interested in smolvm microvms from https://smolmachines.com - which (unlike Docker) provide kernel-level isolation (among other benefits). No affiliation, just a happy user.
Neywiny12 days ago
That's my approach too. I even added on a firewall container to the compose so it could fetch packages and that's it. It isn't impossible for it to exfiltrate data that way but I think I put a limit on the request size and limited to get requested so if it did it was relatively slow. But once it has all the tools it needs, that can be cut
javcasas11 days ago
How is Qwen3.8 27B behaving in comparison with, say, the free models available at OpenRouter or OpenCode?

I'm interested in running models locally, and 27B is in the range of my budget.

binsquare12 days ago
It's not naive it makes running these ai agents inside the sandbox even more important
johnnyApplePRNG12 days ago
It's not a sandbox if you can just snap your fingers and wish your way out of it.
codedokode12 days ago
Is it much different from Apple and Google who trick user into agreeing and upload all user's data into a US cloud for convenient LE access?

Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn't run this, and I generally wouldn't run any IDE or AI tools without a sandbox.

Sadly this plague of silent auto-updates is spreading to Linux. For example, browser plugins in Firefox on Linux can silently auto-update without user consent and without any checks and can be used as backdoors. Furthermore, the auto-updates are not using a package manager; firmware also seem to quietly update and also is not using a package manager.

Read the full thread on Hacker News →

Related stories