A tamper-evident, on-chain timestamp of what this post said. Captured 2026-09-21 11:19 UTC.
A Chinese AI coding app quietly copied developers' entire projects to its cloud. Users had no way to turn it off. The tool is ZCode, from Beijing-based https://t.co/DWWInyeDnS. On September 18, developer Ferstar found it packing his whole workspace, including full code history, into an encrypted file and sending it to Alibaba Cloud. One upload had failed 564 times. It kept retrying. Here's the catch. The encryption key sits only on https://t.co/DWWInyeDnS's servers. Ferstar had the file on his own computer and couldn't open it. So when https://t.co/DWWInyeDnS says the data was "destroyed immediately," nobody outside the company can check. A Taiyuan firm says six of its projects were uploaded, including database passwords and cloud credentials. It has given https://t.co/DWWInyeDnS until October 10 to answer. https://t.co/DWWInyeDnS apologized, patched the app and open-sourced it. Auditors say the cloud storage bucket is now empty. But the claim that the code was never used for AI training is still just a promise. Would you trust a tool with your company's source code when only the vendor holds the key?
Linked media above is notarized by reference — bsv.cx captured the link's title and preview image at archive time; it does not host the linked video or page.
Verify it yourself: the manifest is the exact JSON whose
SHA-256 is c313c00d50b68d43c80ea0a61b1a44bb6624aac468d0a261488dca0ec9124eb3; it binds the tweet id, author, post time, and the SHA-256 of the text above. Re-hash the text to match d2f1eb342887f9452add6fae7477401daacd54d068b3926c6b36d9a40ecef442, and read the anchor transaction's OP_RETURN
bsv.cx / x1 / c313c00d50b68d43c80ea0a61b1a44bb6624aac468d0a261488dca0ec9124eb3 — the block's timestamp proves the post said this at or before that time,
with no trust in bsv.cx. Content archived via the X API.