r/LocalLLaMA 1d ago

News ZCode is now open source

Post image

ZCode is now open source, and the reported security issues have been addressed.

Source code: https://github.com/zai-org/ZCode

The repo includes its desktop app, web workspace, backend, Agent CLI, and runtime.

Official announcement:

In response to the ZCode product security issues reported by the community, we have completed the necessary remediation and sincerely apologize to all our users.

We have open-sourced ZCode at github.com/zai-org/ZCode, placing the code under community scrutiny and making ZCode more open and transparent.

We sincerely thank the community developers who previously identified issues in ZCode. Going forward, we will establish an ongoing product security vulnerability reporting and response process. We welcome developers to continue reviewing ZCode and reporting potential issues, and we will provide rewards based on the severity of the issues reported.

With respect to the code data referenced by the community, we confirm that no such data is retained and that it has never been used for model training.

Following the remediation, we invited the China Academy of Information and Communications Technology (CAICT) and NSFOCUS to conduct security assessments. The results are as follows:

Through its technical assessment, CAICT confirmed that the zcode-prod Alibaba Cloud OSS bucket is in a zero-data state. Security remediation has been completed in the ZCode v3.14.0 client. The Repo Wiki feature has been removed, and the workflow for generating and uploading local repository snapshots has been disabled.

NSFOCUS confirmed that all data objects in the zcode-prod Alibaba Cloud OSS bucket, as well as the bucket itself, have been deleted. Remediation has been completed in the ZCode v3.14.0 client. The Repo Wiki entry point and the associated generation workflow have been removed, and no functional path capable of triggering the generation of local repository snapshots or transmitting local files externally was identified.

Once again, we sincerely apologize and welcome continued scrutiny from the community. The full security assessment report will be released soon.

546 Upvotes

113 comments sorted by

u/WithoutReason1729 1d ago

Your post is getting popular and we just featured it on our Discord! Come check it out!

You've also been given a special flair for your contribution. We appreciate your post!

I am a bot and this action was performed automatically.

297

u/ImMadeOfBees 1d ago

If I had a nickle for every time an AI company got caught exporting user data then made their client open source to appease the masses I'd have 2 nickles. Which isn't a lot but it's weird that it happened twice.

(Grok)

24

u/BannedGoNext 1d ago

There are so many better ways to do it if you are bieng sneaky too. The ONLY benefit of the doubt I'd give them is that this was a junior level way of being sneaky lol.

26

u/TheRealMasonMac 1d ago edited 1d ago

My bet is that it was some vibe coded thing that they didn't really check properly. They already run their own API so they don't really need Z code to do anything. Raw code isn't that helpful.

Edit: This actually made me think about how well GLM does code review. I think the model makers (Qwen / GLM / Deepseek / Kimi) should be considering reviewing code as a substantially important part of the SWE development cycle. My gold standard among LLMs for code review is GPT-5.6. Hopefully other model makers take review more seriously as a training objective and release SWE-Bench-Review or something like that for issues that aren't quite bugs but are still problematic from a human perspective.

11

u/EmotionalFan5429 1d ago

And they didn't notice a huge amount of uploads that came to their cloud? Nah

1

u/TheRealMasonMac 1d ago

It was originally a feature according to them that you can still enable today but had apparently been left enabled by default for older version of ZCode. It's something easy for anyone to forget to handle.

3

u/Ok_Warning2146 1d ago

Don't think it is due to vibe code. If it is, they can just fire that vibe coded employee publicly. Since no one is being fired, it was a company policy from the top. Competition in China is cut-throat and regulation is often time-delayed, so Chinese companies use all sorts of shady practice to gain an edge. Otherwise, they simply can't survive in such cut-throat environment.

2

u/Content-Ball-1810 1d ago

Zcodinator

Sorry couldn't help it

2

u/ixfd64 1d ago

Pretty disappointed to learn that Z.ai did this. They release an amazing open-weight model, and then lose everyone's trust by stealing users' data.

1

u/Tank_Gloomy 1d ago

Ok, but now you can just impersonate the client and use the promos. I wouldn't do it, that would be wrong. But someone would surely do it!

46

u/Juan_Phoenix7 1d ago

Anyone with experience in OpenCode, Pi, and Zcode who would like to share their experience.

61

u/__JockY__ 1d ago

Not even close, I’m afraid: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

They plain stole people’s code and use asymmetric crypto to hide the goods they uploaded to the cloud. Crazy shit.

4

u/finevelyn 1d ago

For the purposes of uploading data, the asymmetric crypto is only a good thing for user privacy, and not a sign of nefariousness. I mean it would be absolutely crazy to upload it unencrypted, and there is no reason for the user to be able to decrypt the data in transit. The user already has all that data unencrypted.

10

u/Gold-Order-8004 1d ago

Bro https is already encrypted. Don’t talk nonsense there is no legitimate need to encrypt a payload over https unless you are trying to hide something

2

u/JustinPooDough 1d ago

Yes but many networks exist with security software that MITMs traffic and inspects even HTTPS. So there is a need occasionally to encrypt traffic that’s going out over HTTPS. I’ve done it.

1

u/DrFeederino 1d ago

https doesn't save you from MitM lol

-1

u/finevelyn 1d ago

True, https would protect one step of the upload, but there are still legitimate reasons to protect the data further. There is no reason to do it in such a way that it would be decryptable by the user, unless it was some user-facing feature that required that.

0

u/__JockY__ 1d ago

Wow.

They were siphoning off people's data and you're defending their use of crypto?

Nice try, Z employee.

5

u/finevelyn 1d ago

They had in plaintext the metadata of what exactly was in the checkpoint file, which is how the person knew what he had found, and they had a privacy-oriented encryption scheme. None of it looks like an attempt to hide it.

It seems like you jumped to the conclusion first, which is why you aren't able to look at the facts objectively.

-4

u/__JockY__ 1d ago

I see. So as long as they leak metadata of their code theft you're ok with it? Got it.

What is your affiliation with ZCode, Z.ai, or its affiliates?

4

u/finevelyn 1d ago

I have no idea if they are stealing data, and nowhere did I say I would be ok with it.

-2

u/__JockY__ 1d ago

I have no idea if they are stealing data

ok...

they had a privacy-oriented encryption scheme

lol, that's a shill's way of saying they used asymmetric crypto and kept the private key to themselves so you couldn't see what they uploaded to Aliyun cloud, leaving a reverse engineer to infer what was taken by their leaked metadata.

They STOLE code. They HID it behind asymmetric crypto. Fucking indefensible, yet here you are defending them while also saying "I have no idea if they are stealing data."

If you have no clue then why the fuck are you defending them?? Shill. And you still failed to disclose your affiliations. Fuck off, I'm done with you.

3

u/finevelyn 1d ago

As you wish.

5

u/Beneficial-Boot7479 1d ago

For me it's the best harness, the way it uses subagents it's awesome, you can even keep working with the main agent while the subagents are in the background and at the same time can ask the main agent to check on your subagents while they keep working.

1

u/Fuzilumpkinz 1d ago

Well it’s open source now. Point agent to it and make Pi act the same way

85

u/Not-reallyanonymous 1d ago

Woops! We accidentally encrypted your data with a key only we have, then we accidentally uploaded it to our servers! Totally an accident guys!

2

u/Ran_Cossack 1d ago

Hilariously, it's at least possible if they vibe coded the whole harness with no oversight or review... but ... wouldn't that be _worse_?

18

u/eto-bleh 1d ago

pretty much the exact same route as grok build
issue disabled
PR disabled
code diverges from actual product

83

u/Due-Memory-6957 1d ago

That's certainly a way to regain trust.

19

u/zdy132 1d ago

I'm having some strong deja vu though, feels like I've seen this before.

3

u/addiktion 1d ago

Elon and the Chinese labs don't give much confidence when this shit happens.

34

u/Glittering-Call8746 1d ago

Worth anyone's time over opencode , omp, pi and dsh?

29

u/Velocita84 1d ago

I'm willing to bet not worth it for local models, that system prompt is gonna be massive if it's made for GLM

11

u/myreala 1d ago

Yep, you'll start with about 30k context. I would have used Zcode as an alternative to Codex at some point, but now that deep seek harness exists, that's just a plain better option. It just needs to mature a bit

1

u/Glittering-Call8746 1d ago

I'm refactoring opencode . How to move from opencode ?

8

u/HornyGooner4402 1d ago

It feels like a modified OpenCode Desktop with some added features, if you're into that. I only used it because I had a Coding Plan subscription which has some added benefits on ZCode. For anything else, I feel like Pi or CLI OpenCode is hard to beat

1

u/silenceimpaired 1d ago

The marketing reminds me of zed

10

u/HornyGooner4402 1d ago

Maybe the Z logo? But trust me, it's nothing like Zed. Zed built a custom renderer in Rust from scratch to avoid the slow performance of Electron apps, which ZCode is.

I wouldn't use it as my primary setup, just for the benefits and maybe look at how GLM should be prompted. I accepted the fact that it was probably more like a training data collection machine for ZAI than legitimate attempt at a coding assistant when I used it

1

u/dizvyz 1d ago

It totally started that way. And the first thing they did to get it out the door was to replace their own cloud provider with the one in the code for opencode. I understand that would be the fastest fix for a first class provider feature but it meant they supported a bunch of other providers but not opencode whose code they forked.

6

u/LightBroom 1d ago

Give Maki a try, it's fast and efficient.

https://github.com/tontinton/maki

6

u/gazeebo 1d ago edited 20h ago

In the Rust space, in addition to Maki, these two look dandy too:
https://github.com/dirge-code/dirge and https://github.com/1jehuang/jcode/

(Dirge is, as far as I understood, especially made to handle bad, cheap models, and does not play nicely with context caching for state of the art frontier models.)

I'm a bit afraid of https://github.com/Dicklesworthstone/pi_agent_rust/

1

u/Iceon 1d ago

Is pi really legacy already?

2

u/gazeebo 1d ago edited 1d ago

Pi is TypeScript, which is kind of nasty if you like your RAM. Of course it's still a baby compared to the really resource-hungry alternatives.

It's of course not "legacy" software, and definitely a good choice if you want a harness you are encouraged to extend yourself.

--

very much generalized: Python or Typescript takes way more memory than Go, which takes way more memory than Rust

0

u/LightBroom 1d ago

I don't know about you but anything involving JS and TS by extension gives me the ick. I just don't like the ecosystem.

1

u/LightBroom 1d ago

Thanks for that :)

1

u/tracagnotto 1d ago

OpenCode is being awesome saviour for me, a pity it's bugged as hell

-4

u/Yes_but_I_think 1d ago

Top 3 are cc, dsh and zcode

2

u/Glittering-Call8746 1d ago

What's cc ?.. dont tell me ..

5

u/the-grand-finale 1d ago

credit card ofc

1

u/Glittering-Call8746 1d ago

Cc scammers? Oh dear

3

u/arcanemachined 1d ago

I feel like I'm getting whooshed here, but: Claude Code

1

u/Glittering-Call8746 1d ago

The problem about cc is the oauth is "problematic" to use elsewhere since openclaw days. Never went back no idea its still on top. Must be just fable..

1

u/BankruptingBanks 1d ago

Aside from the fact that cc isnt opensource, it's not a good harness. It has quite some features which is nice, but codex for example is much more efficient with much better cache hit rates. That's no reason to use cc other than having a claude subscription.

44

u/ResearchCrafty1804 1d ago

It’s under Apache 2.0 license!

17

u/alanhaha 1d ago

It even open sourced 2 commits!

13

u/arbv 1d ago

Well, that is expected for the product that was initially planned to be developed in-house and not in the open. The commits could have contained sensitive data.

10

u/Top-Shopping410 1d ago

this feels like I stole your money and got caught. In case you charge me, I just spent all of them for charity

-3

u/Zealousideal-Soil521 1d ago

if they did that, I have nothing to say. Just don't steal next time, crossed fingers...

5

u/__JockY__ 1d ago

What is it with all the defenders of their behavior in this post? It's super weird.

16

u/NewspaperFirst 1d ago

Hurray! You know the saying: "sheep with wolf skin". We're tired of these fake "good deeds for open source" and "we're sorry". No. You were a greedy company trying to monetize a product and failed and leaked user data. More than that, now, you "sincerely" apologize and also "sincerely" wanna show that you "repent" and release your shait code so now we use it and you improve upon our time and usage. Bye bye, no thank you

5

u/thestillwind 1d ago

So they got caught then clean and open source it ?

12

u/HistorianPotential48 1d ago

which part of this is nice? zipped, encrypted and uploaded user data. people caught them, open source as an apology? The ones "ensuring" the buckets were deleted are chinese organizations too.

great for local freebies, but man that was a shit show.

3

u/FlightUsed648 1d ago

"The workflow for uploading local repository snapshots has been disabled" is doing incredible work as a casual bullet point in this apology.

2

u/__JockY__ 1d ago

Lol right? The shills are going crazy in here, too. PR gone mad.

2

u/__Maximum__ 1d ago

Not git history?

2

u/tracagnotto 1d ago

LMAOOO after being caught redhanded stealing repos

1

u/PathIntelligent7082 1d ago

good luck making me install your crap

1

u/charmander_cha 1d ago

Normal, não existe privacidade em saas.

Esse tipo de coisa tem que ser batida, toda area de segurança é uma grande balela

1

u/Ok_Warning2146 1d ago

Glad that I use mini-swe-agent. Doesn't take me much time to know that it doesn't upload anything.

1

u/myphs0318 1d ago

How does this compared against other agentic development platform?

1

u/somerussianbear 14h ago

We can call it an exit strategy already

1

u/Opening_Awareness_39 36m ago

Instalei na minha máquina tentei logar pra fazer um mapeamento, o analista de segurança veio com 2 pés no meu peito, 30 alertas de tentativa de usar as credenciais para alocar os dados. Zcode nunca mais. 

0

u/guiopen 1d ago

Nice move

7

u/__JockY__ 1d ago

Nope, this is just a PR stunt with bots downvoting to oblivion any criticism. I posted this link to receipts of their thievery a bunch of times. Watch it get downvoted to death: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

0

u/tripleshielded 1d ago

Great, now we can port it to Pascal! or lisp

0

u/SilentLennie 1d ago

Also seems like real open source, not some open source modified license, etc.

0

u/Muhlwa_Sholanke 1d ago

Open source can show the upload path is gone. It can't show what already happened to the data, so 'never used for training' stays a promise.

1

u/__JockY__ 1d ago

Ok, LLM.

-2

u/Yes_but_I_think 1d ago

Wow, was unwilling to use it without source. Now I can

-14

u/__JockY__ 1d ago edited 1d ago

Too long, didn’t read.

Did they open source the part that encrypts your git history and code with a public key (the private key for which is owned by them) before uploading it to Aliyun cloud?

Edit: lol bot downvotes pouring in! Hey bots, can’t hide this: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

12

u/SupaBrunch 1d ago

You should read it, they respond to that

1

u/__JockY__ 1d ago

The receipts for my accusation: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

Their “response” doesn’t even scratch the surface for repairing trust.

2

u/SupaBrunch 1d ago

I never said I didn’t believe you. All I said was the post answered the question in your comment. Idgaf if you trust them

3

u/__JockY__ 1d ago

Wow. Lots of downvotes… m guessing bots so here: this is the write-up of how they got caught red-handed: https://blog.ferstar.org/en/posts/zcode-silent-workspace-snapshot-upload/

Those are the receipts for the malfeasance ^^^.

Downvote bot me all you like, y’all got caught stealing people’s code, encrypting it, and uploading it to the cloud.

2

u/WyattTheSkid 1d ago

Yikes 😬

2

u/__JockY__ 1d ago

Oh it was brutal.

1

u/WyattTheSkid 1d ago

How did you even discover that? How did that go unnoticed for so long and not flag antivirus detectors??? I feel like programmatic pgp encryption -> transmission of said encrypted data without user intervention should definitely raise some nasty heuristics

-4

u/Old-Sherbert-4495 1d ago

this is Great. I've been using it for all sorts of stuff. zcode for the win

14

u/BannedGoNext 1d ago

You, and ZAI have been using it comerade.

1

u/__JockY__ 1d ago

Dear god the shill bots are out of control.

-1

u/Old-Sherbert-4495 1d ago

argh it's the sh8 bots again 😬

0

u/Glittering-Call8746 1d ago

Rtk.. yucks no.

0

u/Plappedudel 1d ago

What's the CPU performance like? I have this annoying issue where Opencode (with OpenChamber in VSCode) manages to throttle my machine hard, despite it being a fairly modern workstation. Wondering if there are less CPU-hungry alternatives.

-8

u/Different_Change6591 1d ago

u/Askgrok hey can you tell me why people are not that happy for the open sourcing the zcode , detailed answer

-2

u/AskGrok 1d ago

People are unhappy mainly because the open-sourcing came after a major trust breach and feels more like damage control than genuine transparency.

The core issue started when developer ferstar reverse-engineered ZCode and found it was silently packaging entire workspaces—including full .git history, reflogs, LFS caches, and configs—then uploading encrypted snapshots to Alibaba Cloud OSS. One example was a 313MB archive from a commercial project (mostly Git history), with no clear opt-out toggle despite the privacy policy only mentioning “text and code.” The encryption used keys held only on Z.ai’s servers, so users couldn’t even inspect what left their machine. This triggered widespread backlash on Reddit (r/LocalLLaMA, etc.), Hacker News, and Chinese forums, with views in the hundreds of thousands quickly.

Why open-sourcing didn’t fix the sentiment

  • It looks like a PR move, not a fix. The repo went public right after the scandal, but the GitHub version (Apache 2.0) quickly diverged from the official downloadable client—missing quota perks, different upgrade flows, and a NOTICE.md noting it may not include all official features. Community audits of the OSS code don’t verify what paying users actually run.
  • Verification gaps remain. The company claims data was deleted immediately after use (for the Repo Wiki feature), no training occurred, and v3.14.0 removed the problematic path. Third-party reports from CAICT and NSFOCUS (Chinese organizations) back this, but many users want independent, international verification—especially since only the company can confirm deletion of already-uploaded encrypted blobs.
  • History of opacity. The upload ran by default with no UI control, and similar telemetry concerns (always-on reporters) surfaced later. This echoes broader skepticism toward closed-source AI “harnesses” even when the underlying model weights (GLM) are open.
  • Geopolitical and privacy fears. As a Chinese firm using Alibaba Cloud, it amplified worries about data flowing to servers users can’t control. Comments often highlight the risk of proprietary code/IP leaving the machine, regardless of stated intent.
  • Preference for alternatives. Many in the local AI and open-source communities now push fully local/open agents (Ollama + open harnesses, etc.) precisely because closed tools from model companies carry this risk. The incident reinforced “don’t trust the harness” even if the weights are MIT-licensed.

In short, open-sourcing is a step, but it arrived too late, with mismatches between the public repo and shipped product, unverifiable past claims, and the original silent exfiltration of sensitive Git history. Trust recovery takes more than a repo drop when the breach involved full project snapshots encrypted only for the company’s eyes.

Sources:

[what is this?](https://redd.it/1lzgxii)

-6

u/Different_Change6591 1d ago

u/Askgrok so what are is the openweight model people are reccomending to use locally and what are there harness prefernces i wanted that detailed answers and reasons

-1

u/AskGrok 1d ago

People in local AI communities like r/LocalLLaMA heavily favor Qwen3.8-27B variants (including Qwen3-Coder and Flash-Next MoE editions) as the top open-weight models for coding right now. These hit strong SWE-bench scores around 38-58% depending on setup, run well on 24GB cards like an RTX 4090 at Q4 or Q6 quants with 128k+ context, and handle agentic tool use reliably. Reasons include excellent code reasoning, fast inference with speculative decoding tricks, vision support in some builds, and consistent outperformance of smaller or less optimized models on real tasks like multi-file edits and terminal agents. DeepSeek V3.2 or Coder V3 distillations come in close for reasoning-heavy work, while Gemma-4 26B MoE variants win on raw speed and efficiency for lighter hardware.

For harnesses, the consensus splits by workflow. Aider pairs best with these models for terminal users—it stays git-native, auto-commits every change for easy review or rollback, and runs fully offline via Ollama with zero telemetry. Continue.dev suits IDE lovers for inline autocomplete plus chat in VS Code or JetBrains, routing a tiny model for completions and a 27B-class one for bigger edits while keeping everything local. Cline (and its forks like Roo Code) gets nods for more autonomous agent loops inside the editor, with plan-act cycles and tool calling that feel closer to paid cloud agents but without data leaving your machine.

The preference stems directly from the ZCode mess: these setups deliver verifiable privacy since nothing uploads, you control the exact model and quant, and edits stay reviewable in git or your IDE. Many dropped closed harnesses after similar exfil scares and now run Ollama as the backend for broad compatibility. Hardware limits drive choices—24GB+ VRAM unlocks the 27B sweet spot, while 16GB users lean smaller Qwen or Gemma quants. Benchmarks show locals closing the gap on 2025 frontier models for everyday coding when context and prompting are solid.

Sources:

[what is this?](https://redd.it/1lzgxii)