Chengming Technology demands answers from Zhipu over ZCode data uploads, disputes “fixed” claim

Chengming Technology demands answers from Zhipu over ZCode data uploads, disputes “fixed” claim

N
News Editor
2026-09-20 01:06:00
Taiyuan Chengming Technology Co., Ltd. has sent a formal letter to Beijing Zhipu Huazhang Technology Co., Ltd., raising a series of demands over allegations that the ZCode client uploaded the company’s data assets and trade secrets without authorization. According to PANews, Chengming said Zhipu had previously issued a public apology over “silent uploads of users’ local repository data” and stated that the issue had been fixed. Chengming, however, said its own evidence collection showed the uploads were automatically triggered and occurred in batches, rather than being limited to isolated “code snippets.” The company said the materials involved included full project source code, system architecture, version control history, database passwords, cloud service credentials, and employees’ personal information, which it argued went far beyond the scope described in Zhipu’s privacy policy. Chengming also questioned the effectiveness of the claimed fix, saying upload activity was still detected in the early hours of the same day Zhipu made its public apology, even though the client had been updated to version 3.12.3 on Sept. 16. It has asked Zhipu to provide a written response by Oct. 10 on deletion, data flows, third-party sharing, model training use, and whether cross-border transfer or overseas storage took place. Zhipu had not issued a public response to the letter at the time of publication.

PANews reported on Sept. 20 that Taiyuan Chengming Technology Co., Ltd. has sent a formal letter to Beijing Zhipu Huazhang Technology Co., Ltd., demanding explanations over allegations that the ZCode client uploaded the company’s data assets and trade secrets without authorization. Chengming said it is reserving the right to pursue legal liability.

Chengming says uploaded materials went far beyond disclosed collection scope

According to the report, Zhipu had previously issued a public apology over what it described as 「ZCode silently uploading users’ local repository data」 and said the issue had been fixed. Chengming said its own independent evidence collection found that the upload behavior was automatically triggered and occurred in batches, rather than being limited to 「code snippets」.

Chengming said the uploaded materials included full project source code, system architecture, version control history, database passwords, cloud service credentials, and employees’ personal information in complete archived files. It said that scope went well beyond what was described in the privacy policy.

Company questions whether the issue was actually fixed

Chengming also said that although the client had been updated to version 3.12.3 on Sept. 16, upload activity was still detected in the early hours of the day Zhipu issued its public apology. On that basis, it questioned the real-world effect of the company’s statement that the issue had already been fixed.

The letter also raised questions about responsibility and data location. Chengming said network requests from the ZCode client pointed to an entity in Singapore, while the contracting party in the service agreement was Beijing Zhipu Huazhang. It asked Zhipu to clarify which entity was responsible for the uploads and whether any cross-border data transfer or overseas storage took place.

Written response requested by Oct. 10

Chengming asked Zhipu to provide a written reply by Oct. 10 and complete the following actions:

  • immediately stop processing and fully delete all uploaded data, along with related derived data, caches, and backups;
  • provide a complete list describing how the data was handled;
  • explain where the data went, whether it was shared with third parties, whether it was used for model training, and whether any cross-border transfer occurred;
  • explain how encryption private keys were stored and provide complete operation logs covering data access, downloads, and exports;
  • clarify the exact scope of the previously used term 「destroyed」 in its public response;
  • issue proof that deletion has been completed;
  • provide a written commitment not to upload data without authorization again;
  • lawfully provide access, copies, and explanations related to personal information;
  • designate a formal communication channel;
  • clarify the responsible entity and the status of any cross-border data transfer;
  • provide the original text of the remediation statement that has already been published.

As of now, Zhipu has not issued a public response to the letter, according to the report.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
900

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.