🐦 Archived X post

A tamper-evident, on-chain timestamp of what this post said. Captured 2026-09-21 11:19 UTC.

@Unveiled_ChinaXon X · 2026-09-21

archived media

A Chinese AI coding app quietly copied developers' entire projects to its cloud. Users had no way to turn it off. The tool is ZCode, from Beijing-based https://t.co/DWWInyeDnS. On September 18, developer Ferstar found it packing his whole workspace, including full code history, into an encrypted file and sending it to Alibaba Cloud. One upload had failed 564 times. It kept retrying. Here's the catch. The encryption key sits only on https://t.co/DWWInyeDnS's servers. Ferstar had the file on his own computer and couldn't open it. So when https://t.co/DWWInyeDnS says the data was "destroyed immediately," nobody outside the company can check. A Taiyuan firm says six of its projects were uploaded, including database passwords and cloud credentials. It has given https://t.co/DWWInyeDnS until October 10 to answer. https://t.co/DWWInyeDnS apologized, patched the app and open-sourced it. Auditors say the cloud storage bucket is now empty. But the claim that the code was never used for AI training is still just a promise. Would you trust a tool with your company's source code when only the vendor holds the key?
🔗 linkZ.ai - Advanced AI Chatbot & Agent powered by GLM-5.3-Flash (chat.z.ai)
descriptionMeet Z.ai, the AI assistant powered by GLM-5.3-Flash. Build websites, write code, handle long-horizon tasks, and get instant answers. Fast, smart, and reliable.

Linked media above is notarized by reference — bsv.cx captured the link's title and preview image at archive time; it does not host the linked video or page.

posthttps://x.com/Unveiled_ChinaX/status/2101875354285592905
author id1963746417283047424
posted2026-09-21T03:25:10.000Z
manifest sha256c313c00d50b68d43c80ea0a61b1a44bb6624aac468d0a261488dca0ec9124eb3
text sha256d2f1eb342887f9452add6fae7477401daacd54d068b3926c6b36d9a40ecef442
media sha25666855cfd0d535521207080539c815475ce97c23b9d63ec76fb1901850222f89a (photo, 114224 bytes)
on-chain⛓ anchored — 331119164a51e9c7470976d843e588a2387a1642c700c706e1fc3299288881b4

Verify it yourself: the manifest is the exact JSON whose SHA-256 is c313c00d50b68d43c80ea0a61b1a44bb6624aac468d0a261488dca0ec9124eb3; it binds the tweet id, author, post time, and the SHA-256 of the text above. Re-hash the text to match d2f1eb342887f9452add6fae7477401daacd54d068b3926c6b36d9a40ecef442, and read the anchor transaction's OP_RETURN bsv.cx / x1 / c313c00d50b68d43c80ea0a61b1a44bb6624aac468d0a261488dca0ec9124eb3 — the block's timestamp proves the post said this at or before that time, with no trust in bsv.cx. Content archived via the X API.

← bsv.cx · JSON · ⚠ Report