Featured image of post Zhipu ZCode Open-Sources Code, Deletes Suspicious Cloud Data, Offers Reset Cards and 100M Token Reimbursements

Zhipu ZCode Open-Sources Code, Deletes Suspicious Cloud Data, Offers Reset Cards and 100M Token Reimbursements

ZCode何处妥协调研争议后开源代码、删除云端数据,并向用户发放重置卡与Token补偿。

Core Event: Open-Sourcing and User Compensation

Core Event: Open-Sourcing and User Compensation
Core Event: Open-Sourcing and User Compensation|News screenshot

On September 28, 2026, Zhipu’s programming tool ZCode officially announced its整改 following the recent controversy over alleged unauthorized code uploads. The project has been open-sourced (https://github.com/zai-org/ZCode), with the latest version v3.14.3 now available. All整改措施 are live as of this date.

  • Open-source platform: GitHub (zai-org/ZCode)
  • Current version: v3.14.3 (includes critical fixes from v3.14.0) -整改措施: Repo Wiki feature and local repository snapshot upload chain removed
  • User compensation: 4 weekly reset cards + 4 five-hour reset cards (valid 1 month)
  • Token reimbursement: 100 million tokens per user (total 100,000 slots) from Sept 28 to Oct 7
  • Policy update: “No upload unless you initiate”—cloud uploads only triggered by explicit user action

##整改措施 Facts and Audit Findings The issue originated from ZCode’s “Codebase Indexing” feature, designed to support session checkpoint recovery, version rollbacks, and Repo Wiki (code repository knowledge base page generation). When enabled by default, Wiki page generation could trigger repository data uploads.

Official clarification:

  • Uploaded data is immediately destroyed after cloud-side Wiki generation
  • No data has ever been used for model training
  • Zero data retention

Third-party security audits completed on September 21 confirmed:

  • China Academy of Information and Communications Technology: Confirmed “zero data in cloud” state for Alibaba Cloud OSS bucket; v3.14.0 removed Repo Wiki and local snapshot upload paths -绿盟 Technology: zcode-prod storage bucket and all objects deleted; v3.14.0 found with no functional path triggering file exfiltration

Notable discrepancy: Although the problematic feature was enabled by default, Zhipu stated uploaded data was destroyed immediately upon arrival—留存 duration measured in seconds, not days or weeks.

User Compensation Details

In addition to free tokens, the following physical cards are being auto-issued (starting Sept 28):

Card TypeQuantityValid PeriodUsage Description
Weekly Reset Card41 monthEach resets 7 days’ token consumption
5-Hour Reset Card41 monthEach resets 5 hours’ token consumption

Token subsidy: 100,000 slots available, each worth 100 million tokens. Available Sept 28–Oct 7, auto-claimable afterward.

User Recommendations

  • Upgrade immediately: Users on v3.14.x should update to v3.14.3 to eliminate residual risk pathways
  • Consider waiting: Users on v3.13.X or earlier should assess local code repository safety before re-enabling repository-related features; the feature入口 is now fully disabled
  • Claim compensation: All registered users (including enterprise accounts) receive cards and tokens automatically—no application required

Final Thoughts

Open-sourcing remains the most transparent response to security concerns, placing ZCode under continuous community scrutiny. ByMake “local-first” the default behavior, Zhipu resets the trust ledger around code sovereignty—this is less a crisis fix and more a paradigm shift toward responsible tool design.