On September 28, 2026, Zhipu's official ZCode team published an announcement unveiling a new round of user compensation and remediation progress for the "silent data upload" controversy, with multiple leading media outlets reporting on it the same day. According to the announcement, the plan took effect at 10:30 on September 28, 2026.
A two-tier compensation plan
For paying users: current paid subscribers, as well as paid users who return within a month, will receive 4 weekly quota reset cards and 4 five-hour quota reset cards, valid for one month. For all users: from September 28 to October 7, a daily giveaway of "100 million tokens × 100,000 lots" will be distributed. The announcement quotes the official statement: "Trust cannot be reset with a single click; we will win it back slowly, improvement by improvement."
Remediation progress released alongside
According to the announcement, the repository snapshot upload pipeline involved in the incident has been removed, the related cloud data has been deleted, and a third-party verification has confirmed the deletion. ZCode also pledged that "no content will ever leave the user's computer, and code stays local, unless the user proactively initiates an action." The open-source version is also moving forward: it has been updated to v3.14.3, released in sync with the official version.
From September 18 to September 28
The incident began on September 18, when multiple users discovered that ZCode, while signed in, was silently packaging and uploading entire workspace source code, Git history, and other sensitive files to third-party cloud servers — enabled by default with no way to turn it off. Zhipu apologized the same day, attributing it to a design flaw in the "codebase indexing" feature (uploads could be triggered when generating Repo Wiki pages) and promising immediate data destruction.
Subsequent developments came in quick succession. Taiyuan Chengming Technology sent Zhipu a letter with 12 demands — including halting data processing, deleting backups, and disclosing access records — and requested a written reply by October 10; on September 20 it said it was in communication with Zhipu. On September 20, Zhipu announced a "no data retention" feature on its MaaS platform, committed to open-sourcing ZCode, and invited the China Academy of Information and Communications Technology (CAICT) to conduct a security audit. ZCode was officially open-sourced on September 21.
Trust repair: quotas are only the beginning
Capital markets remain cautious: on September 28, Zhipu (02513.HK) shares wobbled lower, closing at around HK$618, down about 2.45%.
What deserves attention is not just the compensation figures, but the precedent this crisis response sets for the whole AI coding-tool industry. First, data trust is the red line for AI coding tools: source code and Git history are among a company's most sensitive assets, and an upload design that is "on by default with no off switch" strikes at the very foundation of developers' trust in their tools. Second, is the compensation generous enough? Reset cards plus a daily large-scale token giveaway do cover both paid and free users, but trust is never repaired with quotas — it is repaired with verifiable change, which is exactly the test facing the line "trust cannot be reset with a single click." Third, the combined playbook of "open source + third-party verification + a CAICT audit," if genuinely carried through, could become the industry's reference case for handling a data-security crisis: exposing the remediation process to public and third-party scrutiny works better than any statement.
For developers weighing whether ZCode is usable now, there are three hard indicators to watch: whether the third-party verification and CAICT audit conclusions are made public, whether the open-source repository keeps updating in sync with the official version, and whether the "no data retention" feature truly covers every upload pipeline. Until those three are settled, staying on the sidelines for sensitive projects remains the prudent choice.