Chengming Technology demands action over ZCode uploads as Zhipu opens source code

  • Taiyuan Chengming sent Zhipu a 12-page legal letter over alleged unauthorized ZCode uploads of enterprise data and trade secrets.
  • One affected workspace allegedly contained 32,932 files and about 411 million plaintext characters, including credentials and personal information.
  • Zhipu officially open-sourced ZCode after internal rectification and invited two organizations to conduct security audits.

Taiyuan Chengming Technology has sent a 12-page legal letter to Beijing Zhipu Huazhang Technology, developer and operator of ZCode, demanding disclosures, deletion and audit evidence over alleged unauthorized uploads of enterprise data and trade secrets. Chengming said one affected workspace contained 32,932 files and about 411 million plaintext characters, including source code, system architecture, Git history, database passwords, API keys, cloud-service credentials and personal information. It seeks details on storage, overseas transfers, third-party sharing and possible model training, along with access, export and deletion logs and proof that data was removed from servers, caches, backups and disaster-recovery systems. Zhipu apologized on September 18, attributing the incident to a code-repository indexing feature enabled by default in an early ZCode version, and said it had fixed the issue and would destroy uploaded data after use. Zhipu has now announced the official open-source release of ZCode after completing internal rectification and inviting the China Academy of Information and Communications Technology and NSFOCUS to conduct independent security audits. Chengming’s investigation questioned the scope and effectiveness of the fix, while its earlier demand set an October 10, 2026 remediation deadline and reserved regulatory and judicial options.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.