DeepSeek, the Chinese AI company that as rocked the tech world and seen tech giant’s shares tumbling, could be in sketchy waters as researchers exposed what seems to be a major security flaw.
DeepSeek rose to fame rapidly, claiming the top spot on app stores just a week after it launched its AI chatbot R1, which rivals leading AI models like OpenAI’s o1, for just a fraction of the price.
The new entrant into the AI race is not without controversy, however, as it already faced technical issues due to an onslaught of users, faced a cyber-attack, and is being questioned by the Italian data protection watchdog about its data practices.
As tech giants shuttered and the US president called the app’s launch a “wake-up call”, Wiz Researchers began assessing the novel application’s security posture to see if they could identify any vulnerabilities in the AI prodigy.
The research team claimed that “within minutes” they were able to access a publicly accessible database on ClickHouse that was linked to DeepSeek, which exposed sensitive data. This linkage was “completely open and unauthenticated,” the researchers said, and was hosted at oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000.
“This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details,” the Wiz research team said.
Further, and more alarmingly, the researchers alleged that the exposure enabled full database control and even the potential for privilege escalation, without authentication or a defence mechanism in place.
The shocking security gaps were reported immediately to DeepSeek, which Wiz claims has now secured the exposure.
Wiz researchers began their investigation looking through DeepSeeks publicaly accessible domains, where they quickly found two open ports which lead to a publicly exposed ClikcHouse database.
ClickHouse is an open0source database management system which allows users to perform quick analytical queries across large datasets. Exposure of one of these databases would be incredibly valuable as they are meant for real-time data processing and could expose sensitive data, Wiz explained.
By using the ClickHouse interface, Wiz researchers were able to directly execute SQL queries, which returned a full list of accessible datasets which contained highly sensitive data. For instance, on the log_stream table, over one million log entries could be accessed, which included a range of data including chat history, API keys, backend details, timestamped logs, and references to DeepSeek API endpoints.
Recommended reading
- Could DeepSeek Topple the US’s AI Market Dominance?
- Italian Data Protection Watchdog Seeks Answers from DeepSeek
- Trump Calls DeepSeek A “Wake-up Call” For US Tech
- Is the UK Lagging Behind in Global AI Race?
- Gartner: Global AI Chips Revenue to Total £56BN in 2024
According to Wiz, this access “posed a critical risk to DeepSeek’s own security and for its end-users.”
An attacker could not only collect sensitive logs and messages, but could even potentially retrieve passwords and files from the server using this exposure.
While the tech world postulates about the potnetial risks and threats of AI technology, the emerging innovation’s security risk tends to “stem from the infrastructure and tools supporting them,” Wiz researchers said, following their findings.
“The rapid adoption of AI services without corresponding security is inherently risky,” the Wiz research team wrote.
Basic security measures, such as protecting against the exposure of databases, is paramount to the security of AI systems that rely on and collect vast amounts of sensitive data sets.
“The rapid pace of adoption often leads to overlooking security, but protecting customer data must remain the top priority,” Wiz researchers wrote.
“It’s crucial that security teams work closely with AI engineers to ensure visibility into the architecture, tooling, and models being used, so we can safeguard data and prevent exposure.”





