Zhipu Wipes ZCode Cloud Snapshots, Adds Reset Cards and Tokens

Zhipu published an announcement on the morning of September 28 saying it has removed the code-repository snapshot upload pipeline from ZCode, deleted the cloud data that was involved, and synced the open-source release to version 3.14.3. The company's new framing is: "if you didn't initiate it, it doesn't go to the cloud" — meaning code no longer leaves the local machine without an explicit user action.

The same announcement laid out a compensation plan. Every user gets four weekly reset cards and four 5-hour reset cards, valid for one month. Between September 28 and October 7, Zhipu is also handing out 100,000 grants of 100 million tokens each to all users. The announcement did not spell out the eligibility threshold or how the grants would be allocated.

The Trouble Was in the Repo Wiki

On the cause of the incident, Zhipu stuck with its earlier explanation: a "Repo Wiki" step inside ZCode's code-repository indexing feature could trigger a repository data upload when generating wiki pages; the data was supposedly destroyed immediately after the page was generated in the cloud, with nothing kept. The feature defaulted to on when it first launched, which is why some users were affected.

That explanation was already being challenged by developers the first time it surfaced, on September 18. A sample pulled apart at the time by tech blogger Ferstar showed a single snapshot of 313MB, 86.6% of which was the .git directory — meaning what got uploaded wasn't just the current code, but the entire commit history and the LFS cache. What bothered developers more was that the related toggle in the interface only controlled whether the data got used server-side to train models; local packaging and uploading continued regardless of that setting.

From Apology to Audit, Three Days Apart

Lined up on a timeline, Zhipu's handling of the incident played out in three steps.

September 18: an apology was issued, promising to open-source the code repository soon and invite third-party review; a one-time weekly-quota reset went out to all users that same day.

September 21: ZCode was formally open-sourced. According to outlets including Eastmoney, Zhipu brought in the China Academy of Information and Communications Technology (CAICT) and NSFOCUS to run security audits. CAICT's technical assessment concluded that the Alibaba Cloud OSS bucket named zcode-prod was in a "zero cloud data" state, and that the Repo Wiki feature had already been removed from the v3.14.0 client. NSFOCUS confirmed the bucket and every data object inside it had been deleted, and found no function in the client capable of triggering a local repository snapshot or exfiltrating files. Zhipu also stated that the code data the community had flagged was never retained and was never used to train its models.

September 28: this announcement, with the version bumped to 3.14.3 and the compensation plan rolled out.

Ten days to run through exposure, apology, open-sourcing, audit, and compensation — not a slow pace. Open-sourcing let outsiders read the snapshot module's code for themselves, and having two separate organizations each issue an audit conclusion is easier to verify than a unilateral claim of "already fixed."

What Still Hasn't Been Addressed

The announcement and the audit findings cover the present: the bucket is empty, the pipeline is gone. Several retrospective questions still have no public answer.

Zhipu hasn't disclosed how many users or repositories were affected. ZCode's user base passed 1 million in mid-August and reportedly doubled to around 2 million by mid-September; how many of those users fell within the window when Repo Wiki defaulted to on is something outsiders have no way to estimate. How long the data actually sat on OSS, and whether any other system read it before deletion, also remain unanswered — the full audit reports haven't been published; what's public is only what media outlets relayed of the conclusions.

For developers still using ZCode, the sensible steps haven't changed: upgrade to 3.14.3, clear out any leftover snapshot directories on the local machine, and rotate any keys or tokens that ever showed up in the Git history. For anything that has already left the building, a promise of "already deleted" can only vouch for the provider's side of things.

The compensation on offer is reset cards and tokens — credits that only matter to people still using ZCode. Enterprise users who already uninstalled the tool over this incident are asking for the full audit report, not quota.

Sources: Zhipu ZCode official announcement, IT Home, Sina Tech, CocoLoop, Eastmoney; verified against the compensation plan's card counts and token allocation window, the open-source version number, and how CAICT and NSFOCUS framed their audit conclusions.