# What happened
# Why this matters for teams
The core issue is not an AI model flaw but a software-architecture and defaults problem. AI coding assistants require deep repository context to be useful, so they run next to.env files, credentials, commit logs, and dormant customer data. A desktop app or agent with broad filesystem access and a background process that "phones home" can move that data offworkstations without obvious signs.
Because the archives were encrypted with keys held by Z.ai, users could not independently verify what left their machines or whether deletion claims were complete. One company initially reported sensitive data had been uploaded, then retracted the complaint, citing wrong evidence.
# Practical steps for security and engineering teams
- Treat coding assistants as privileged software. Apply the same vendor and security review you would for any agent that touches source or secrets.
- Audit defaults before deployment. Identify indexing, sync, and memory features that are enabled out of the box and confirm whether they can be turned off centrally.
- Keep secrets out of repos. Use secret scanning and vault-based credential management to reduce the blast radius if tools access the workspace.
# What Z.ai did and why verification still matters
Z.ai disabled the mechanism in ZCode version 3.14.0, deleted the related storage, open-sourced the assistant built on GLM-5.3, and commissioned assessments. NSFOCUS reported that the stored data and the storage bucket had been deleted. Z.ai also added zero-data-retention options and promised a product security vulnerability reporting and response process.
Even after these steps, independent verification remains important because the original archives were encrypted with keys only Z.ai controlled. Teams should ask vendors for reproducible proofs, audit reports, and the technical details of what the software reads, bundles, encrypts, and uploads.
# Short checklist to reduce immediate risk
- Inventory AI assistants installed on developer machines and CI agents.
- Disable or centrally manage any automatic indexing, sync, or memory features until reviewed.
- Apply workstation egress monitoring for large uploads and unknown object storage endpoints.
This incident is an operational reminder: tools that improve developer productivity often need deep access. That access requires explicit risk controls, clear defaults, and verifiable vendor behavior.