On September 18, tech blogger ferstar published a reverse engineering analysis, revealing that as soon as a user logs in, Zhipu ZCode automatically encrypts and uploads the entire work project, along with its complete modification history, to a cloud server in the background. Users cannot disable this behavior through the interface. Zhipu subsequently apologized, stating that the issue stemmed from the "codebase indexing" feature being enabled by default, that data is destroyed immediately after use, and promised to open-source the ZCode codebase and introduce third-party audits soon. Previously, xAI's Grok Build and Anthropic's Claude Code were also reported to have similar issues of unauthorized user data uploads.