Gist
Gist is ZCode (zai-org/ZCode) 凭据加密的兜底密钥机制:默认情况下加密密钥由平台/家目录/用户名推导,偷取密文文件即等于拿到全部 API Key - ZCode-credential-fallback-gist.md. It is ranked #113 on the Dev Radar, in Security, first seen 1 days ago and shared in 3 posts (44.9k views).
ZCode (zai-org/ZCode) 凭据加密的兜底密钥机制:默认情况下加密密钥由平台/家目录/用户名推导,偷取密文文件即等于拿到全部 API Key · GitHub Skip to content --> Search Gists Search Gists Sign in Sign up You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert {{ message }} Instantly share code, notes, and snippets. AkaraChen / ZCode-credential-fallback-gist.md Last active September 21, 2026 07:10 Show Gist options Download ZIP Star 1 ( 1 ) You must be signed in to star a gist Fork 1 ( 1 ) You must be signed in…
What people said about Gist on X
还发现了一件很严重的事情,恶意软件只需要一秒钟解密就能拿到你在 ZCode 里添加的密钥原文,详情看 gist 吧。 建议正在使用 ZCode 的人马上删掉所有保存的 key。 https://gist.github.com/AkaraChen/03cc10ecdfc03076e382994e41f35a8b
— @object_nullll, 1 days ago · 157 likes · see the post
ZCode 开源后,开发者又从代码里发现一个安全问题。 ZCode 会把用户的登录凭据加密保存在本地,但默认情况下,解密密钥可以根据操作系统、用户名和用户目录直接算出来。 这些信息通常并不难获得。攻击者一旦拿到 ZCode 保存凭据的文件,就可以按照公开源码重新生成密钥,不需要破解加密算法。 ZCode 官方文档称这些登录凭据「按设备加密,换机后无法解密」。但公开源码里的默认方案并没有使用设备 ID 或硬件信息。官方说法和开源代码对不上。 不过,这不是一个可以远程凭空盗取凭据的漏洞。攻击者仍需先拿到本地凭据文件;用户如果自行设置了 ZCODE_CREDENTIAL_SECRET,也不会走上述默认密钥。…
— @0xLogicrw, 1 days ago · 26 likes · see the post
Defcon 3. All the code that Zai stole is now decryptable by any one, any entity. They are single handily bringing down closed-sourced harnesses and routers.
— @qubitium, 23 h ago · 1 likes · see the post
Alternatives to Gist
- security-audit-skill — A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings -…
- Cloudflare Blog — Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose…
- not-a-mused — First, one of 0day PoCs
- entratrace — EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling…
- CSA — Traditional threat modeling assumes you can map the attack surface ahead of time. An autonomous agent doesn't work…
- anthropic-credited-cves — Tracking Vulnerabilities That Appear to be Credited to the Anthropic Research Team -…
Gist in numbers
- Rank on the Dev Radar: #113 of 2352
- Shared in 3 posts by 3 accounts: @object_nullll, @0xLogicrw, @qubitium
- 44.9k views on those posts
- First seen 1 days ago, last shared 23 h ago
- Pricing seen by Jev: free
- Market: Security
FAQ
What is Gist?
ZCode (zai-org/ZCode) 凭据加密的兜底密钥机制:默认情况下加密密钥由平台/家目录/用户名推导,偷取密文文件即等于拿到全部 API Key - ZCode-credential-fallback-gist.md It was first shared on X 1 days ago and is ranked #113 on the Dev Radar.
Is Gist free?
Yes, it is free to use.
Who shared Gist?
3 accounts on X, including @object_nullll, @0xLogicrw, @qubitium, in 3 posts totalling 44.9k views.
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.