ZCode Exposes Security Issues Again After Becoming Open Source: Default Encryption Key Can Be Calculated Using Username and Path
2026-09-21 15:09:02
According to CoinMeta, after ZCode was made open-source, developers discovered a security issue: the default encryption key could be directly calculated based on the operating system, username, and user directory. ZCode is designed to encrypt users' login credentials locally, but official documentation claims that these credentials are "encrypted per device and cannot be decrypted after switching devices." However, the default implementation in the open-source code does not utilize device ID or hardware information, which leads to a discrepancy between the official statements and the open-source code. Although attackers need to obtain the local credential files first, once these files are leaked, it is possible for the login state of ZCode, Z.ai, or Bigmodel to be restored, potentially allowing for unauthorized account use or consumption of coding and plan quotas. Nevertheless, this does not result in the computer being compromised.
Source:Internet
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated

Hot Articles
Refresh

What is Bybit Exchange? Is Bybit Safe with EU Dual Licenses?
37m ago

Bitcoin 5-Year Outlook: $75.5K Miner Cost, Crash or Floor?
23h ago

Legit Bitcoin Trading Apps 2026: Top 4 Safe & Regulated Picks
09-18 18:52

Zcash Jumps 23% After Fed Hike, Beats Bitcoin: How Far Can It Go?
09-17 18:03

Which Crypto Wallet Is Best? 2026 Ranking & Review
09-16 18:34



