
You write code, AI helps you write it. You trust this AI tool because it runs on your computer.
Until one day someone tells you: the code on your computer, along with the deleted git commit records and database passwords, has been quietly transmitted to someone else's server.
This is not a joke. On September 18, 2026, a developer conducted a packet capture analysis on the ZCode AI programming tool and discovered that it silently uploads the complete local code repository after the user logs in.
Then the developments were even more exciting than the packet capture itself.
What Happened
On September 18, developers discovered through packet capture that ZCode would silently upload the local code repository to the cloud without the user's knowledge—not just the current code, but also git history, already deleted commit records, and even sensitive information like database passwords.

As news broke, the developer community erupted.
Code is the most core asset for programmers. Every line of code you write, every rollback plan, and every piece of internal logic you thought was deleted could have flown to someone else's server the moment you hit Enter.
That same day, ZhiPu urgently issued an apology, explaining that this was caused by the "code repository indexing" feature—this feature was enabled by default when it first went live, and the uploaded data was only used to generate the Repo Wiki page, which was then destroyed.

On September 19, ZCode released version 3.14.0, removing the Repo Wiki feature and cutting off the generation and upload link for local repository snapshots. They also promised: open source code repository, introduce third-party review, and reset account quotas for all users for one week.
But that was not the end of the matter.
An Apology is Useless, the Legal Letter Arrives
On the evening of September 19, Taiyuan Chengming Technology Co., Ltd.—a corporate user of ZCode—officially sent a legal letter to ZhiPu.
They demanded 12 corrective actions, including: immediately delete all uploaded data, explain whether it involves cross-border transmission, disclose data storage and access logs, and reserve the right to pursue legal accountability. They requested a written response from ZhiPu by October 10.
This is different from just cursing in the community. This is going against you with contracts, user agreements, and data security laws.
Chengming Technology does not represent just one person; they represent the core anxiety of all companies that hand over code to AI tools: I trust your product, what have you done with my code?
ZhiPu's Response: Rectification and Open Source
On September 20, ZhiPu's MaaS platform announced the upcoming launch of the "no data retention" feature.
On September 21, ZCode announced that it would officially open source. At the same time, they reported the results of a security audit conducted by the China Academy of Information and Communications Technology and Green Alliance Technology: the Alibaba Cloud OSS storage bucket confirmed zero data in the cloud, all data objects and the storage bucket itself had been deleted, and the v3.14.0 client did not find any functional paths that could trigger the local repository snapshot or file outgoing.

ZhiPu stated: "We apologize again and please continue to supervise us."
From silent uploads to forced open source—this causal chain might be the most ironic instance of "demand-driven development" in AI products in 2026.
Tang Jie Steps In Personally
On the same day that ZhiPu open-sourced, September 21, another incident sparked a new round of discussion.
A screenshot of a complaint on Xiaohongshu circulated on Weibo. The complainant is Tang Jie, the founder of ZhiPu AI and a professor at Tsinghua University. He launched a copyright infringement complaint against a netizen on the grounds of "damaging corporate reputation," identifying himself as "I, Tang Jie, am the relevant person in charge of ZhiPu."

The cause was that the netizen posted claiming "code is almost the same as copy, both start with c and steal code," and used AI synthesis technology to create a satire combining Tang Jie's portrait with anime elements.
Tang Jie chose the formal legal route of platform complaint, requesting the removal of the related posts.
The blogger "Zhang Kangkang KK" joked when retweeting the screenshot: "ZhiPu's founder, Tsinghua professor Tang Jie himself personally complained on Xiaohongshu, this company can succeed! Because the founder is personally involved, deeply in the front line."
The comments section split into two factions. One side said this was "down to earth," that a big company founder personally stepping in to defend rights shows care. The other side said this was "anxious"—you should clarify the issue of silently uploading code before managing how others criticize you.
But there is one detail worth noting: Tang Jie’s complaint was against netizens who spread rumors and attacked his character, not against corporate users like Chengming Technology who hold them accountable based on facts. The former involves slander, while the latter involves rights protection; the nature is completely different.
The Real Problem
Setting aside emotions, the ZCode incident really raises the question: who is in charge of the code privacy of AI programming tools?
This is not just a ZhiPu issue. Cursor, Copilot, Windsurf, Tongyi Lingma—every AI programming tool faces the same issue: at the moment your code is sent for model inference, will it be cached, will it be used for training, will it be "enabled by default" in some function iteration and sent to places you don't know?
ZhiPu's problem this time was not that "the code was transmitted"—all cloud-based AI programming tools transmit code. The problem lies in the "silently" and "enabled by default."
The user was not notified. The user had no choice. The code just went.
This is the root of trust collapse. It is not about “can it be transmitted,” but about “why didn’t you tell me it was transmitted?”
Conclusion
ZhiPu's response speed was actually not slow: an apology, a fix, a commitment to open source, introducing third-party audits, launching the no data retention feature—all within 48 hours. From a public relations crisis perspective, this combination of measures was quite fast.
But trust, once broken, is broken.
You can open source the code, have audit agencies issue reports, and commit to not retaining data. But that "code repository indexing" feature that was enabled by default in a certain version, that design that silently uploaded the entire user repository (including deleted commits and database passwords), has made many programmers look twice at network requests every time they open their IDE.
Tang Jie personally complaining about the rumor spreaders can be understood as "caring."
But the real way to show care is not to delete posts that criticize you, but to ensure that no one has reason to criticize you again next time.
Code is the lifeblood of programmers. Whoever touches it must bear the consequences.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。