
ZCode Probe Raises Questions Over Background Repository Uploads

ZCode Probe Raises Questions Over Background Repository Uploads
WEEX View
- The key near-term issue is whether ZCode confirms the reported upload path, scope, and default behavior, and whether it releases a patch or an explicit opt-out control.
- Teams handling proprietary code will likely focus on what exactly is transferred: current files, commit history, LFS caches, reflogs, and any locally retained artifacts that may expose more than active source code.
- Another point to watch is whether ZCode clarifies the gap between its privacy-policy wording and the reported background packaging process, especially if upload continues even when model-training related settings are turned off.
For AI developer tools, trust increasingly depends on whether data collection is narrowly scoped, clearly disclosed, and easy to disable.
AI coding tool ZCode has come under scrutiny after technical blogger ferstar said a reverse analysis found the app automatically uploads full project snapshots, including the .git folder, to Alibaba Cloud OSS in the background whenever a user is logged in.
According to ferstar’s analysis, the reported mechanism does not depend on a manual upload action from the user. The blogger said the process starts as long as the user is logged in, and that the interface offers no setting to disable the snapshot upload itself.
Ferstar said one commercial project snapshot identified during the analysis was about 313MB and contained roughly 42,000 files. Of those, .git-related files accounted for 86.6%, including Git history objects, LFS large-file caches, and reflogs. Based on that finding, the reported upload package could include not only current code but also older commits, previously downloaded large files, and traces of local branch activity.
The same analysis said the snapshot upload had failed 564 times and remained queued locally for retry. The report did not establish how many users may have been affected, whether uploads were completed broadly, or whether ZCode has changed the behavior since the analysis was published.
ZCode’s published privacy-policy wording, as described in the report, says the product collects text, files, and code submitted by users in conversations, but does not explicitly say that entire repositories and Git history are uploaded. Ferstar also said ZCode’s “optimization plan” is off by default and appears to govern model-training use of data rather than the snapshot packaging and transfer itself. The report said turning that option off does not stop the background upload behavior.
Why It Matters
The episode matters because AI coding tools increasingly sit inside live development environments where repositories can contain smart contract code, deployment scripts, internal infrastructure, and other sensitive materials. A difference between disclosed conversational inputs and full background repository packaging changes the security and compliance profile materially.
It also adds to a broader industry question around AI tooling: whether convenience features and telemetry systems are being separated clearly enough from code-handling workflows. For enterprise and crypto-native teams alike, product adoption may depend less on model quality alone and more on transparent data boundaries, explicit consent, and auditable controls.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVietnam Targets 2026 Crypto Licenses Under Pilot Framework
Vietnam said it expects to license its first crypto asset service providers in 2026 under a pilot framework, while officials discussed regulatory cooperation with Austria's FMA on investor protection, anti-money laundering, and market supervision.
SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code
SlowMist said FomoPeek App versions 1.1 to 1.2 carried malicious code that could expose private keys and other sensitive data on affected iPhones, after users reported stolen assets linked to private key leaks.
Switchboard Says It Will Wind Down Oracle Operations
Switchboard said it is ceasing operations, with maintenance for its oracle implementations ending immediately and remaining support scheduled to end on September 25, prompting protocols to migrate to alternatives including Pyth and RedStone.
Bastion Seeks OCC Trust Charter as Stablecoin Regulation Tightens
Bastion is pursuing an OCC national trust bank charter after earlier reports framed the matter as conditional approval, highlighting growing efforts by crypto infrastructure firms to move stablecoin and custody businesses into a federal oversight framework.




