Chengming Technology Sends Legal Letter to Zhipu Over ZCode Code Upload Incident

Chengming Technology Sends Legal Letter to Zhipu Over ZCode Code Upload Incident

N
News Editor
2026-09-20 02:54:47
Taiyuan Chengming Technology has sent a 12-page legal letter to Zhipu over the ZCode "upload code" incident, according to Odaily. The company said ZCode had automatically packaged and uploaded entire workspaces, exposing data that included source code, system architecture, Git history, database passwords, API keys, cloud service credentials, and personal information. In one cited case, a workspace allegedly contained 32,932 files and about 411 million plaintext characters. Chengming Technology asked Zhipu to explain where the data was stored, whether any cross-border transfer had taken place, whether the data had been provided to third parties, and whether it had been used for model training. It also requested the complete deletion of relevant data from servers, caches, backups, and disaster recovery systems, along with access logs, export logs, and proof of deletion. Zhipu had previously apologized for the incident, saying the issue came from the "codebase indexing" feature being enabled by default in an earlier version. The company said the problem has been fixed, that the related data would be destroyed after use, and that it would open-source ZCode and accept third-party review.

According to Odaily, Taiyuan Chengming Technology has sent a 12-page legal letter to Zhipu over the ZCode "upload code" incident. The company said ZCode had automatically packaged and uploaded entire workspaces, involving data such as source code, system architecture, Git history, database passwords, API keys, cloud service credentials, and personal information.

Workspace data volume cited in the letter

Chengming Technology said one of the workspaces involved 32,932 files and about 411 million plaintext characters.

Requests on storage, transfer, and deletion

The company asked Zhipu to clarify where the data was stored, whether any cross-border transfer had occurred, whether the data had been provided to third parties, and whether it had been used for model training. It also requested the complete deletion of relevant data from servers, caches, backups, and disaster recovery systems, and asked for access logs, export logs, and proof of deletion.

Zhipu's earlier response

Zhipu had previously apologized for the incident, saying the issue stemmed from the "codebase indexing" feature being enabled by default in an earlier stage. The company said the issue has been fixed, that the related data would be destroyed after use, and that it would open-source ZCode and accept third-party review.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.