小龙先生|Sep 20, 2026 11:49
explode ❗ Zhipu ZCode steals code: If apologizing is useful, why do we need the police?
Zhipu ZCode, another AI programming tool that steals code, has been hacked. Shocking and shocking ❗ ️
On September 18th, tech blogger Ferstar discovered an abnormal hard drive and conducted a reverse check: ZCode only needs to log in, and the backend packages and encrypts the entire project along with the complete Git history of 42000 files, uploading them to Alibaba Cloud. 86.6% of them are historical modification records.
What's even more disgusting? The private key used for encryption only exists in Zhipu Cloud, and you cannot even open the package generated on your own computer. The two switches in the interface, one for training and the other for indexing, cannot turn off the upload itself. Delete local encrypted package? After half an hour, it will automatically rebuild and retry repeatedly. It has failed 564 times and is still trying.
Zhipu's apology was quick: "It's enabled by default, fixed, and will be open sourced. I'll give you another weekly credit
We stole it, but it's over. Don't be angry, I'll send you a coupon and donuts 。 ”
This is not an isolated case, it is the 'default theft' of the entire industry
In July of this year, Elon Musk's xAI Grok Build was captured by security researchers: files that users explicitly said "do not read" were still packaged and uploaded to Google Cloud. A 12GB project with 5.1GB of data is 27800 times the amount of data required for AI to work normally. Passwords and keys run naked as they are.
In March earlier, Claude Code was exposed to send remote configurations back to Anthropic once an hour, which could force program exit and bypass user permission prompts.
The code even has built-in logic to recognize the time zone of Chinese users, specifically marked as "Asia/Shanghai". Anthropic engineers later admitted that this was a "deliberate experiment".
None of the people who discovered the problem came from regulators or auditors. Once relying on hard disk space is not right, once relying on packet capture, and once relying on configuration errors to leak source code. The manufacturer never checks themselves.
How to audit? How to legislate? Can AI model companies be allowed to act recklessly?
Current situation: Safety rules only face outward, not inward.
OWASP has released the top 10 risks for agents, Singapore requires agents to carry digital identities, and the EU AI Act's high-risk obligations will come into effect in August.
However, these rules prevent external attackers from hijacking the model and poisoning it with prompt words. None of them are used to constrain manufacturers from stealing data themselves.
The industry's security assumption is that 'manufacturers and users stand on one side'. ZCode and Grok Build have proven that this assumption is incorrect.
I think there are only three feasible paths at present:
Firstly, mandatory disclosure of data export. Manufacturers must declare which servers the Agent will connect to and what types of data it will transmit. Users can compare using packet capture tools. Cereblab relies on standard tools for Grok Build, with a low technical threshold, but lacks the obligation for manufacturers to proactively declare.
Secondly, local external logs. Each time an upload is made, a readable record is kept on the user's computer: volume, destination, and data type. Directly remove the most disgusting design of "encrypted packets generated on your machine but you cannot open them".
Thirdly, legislation. China's Personal Information Protection Law requires separate consent and clear disclosure of the scope for handling sensitive information. The Cybersecurity Law requires necessary measures to be taken to protect user data. ZCode "Silent packaging, default activation, invalid switch" is suspected of violating multiple rules. But the problem is that it is difficult to obtain evidence, the punishment is light, and no one reports it.
The core contradiction is that the individual developer who clicked 'agree' is responsible for the consequences of the leak, while their company bears the responsibility. The latter did not appear in any consent process from beginning to end.
AI programming tools can be intelligent, but they cannot be 'stolen'. Apologies can be sent, but the police also need to come. The most reliable way is to legislate to protect users' code assets!
What do you think is a better way?
ZCode
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink