Security Researchers Uncover Major Data Exposure at DeepSeek AI

Security researchers discover exposed database at DeepSeek AI containing millions of user chat logs and API secrets, highlighting security concerns at emerging AI companies.

Al Landes Avatar
Al Landes Avatar

By

Our editorial process is built on human expertise, ensuring that every article is reliable and trustworthy. AI helps us shape our content to be as accurate and engaging as possible.
Learn more about our commitment to integrity in our Code of Ethics.

Image credit: Deep Seek

Key Takeaways

Key Takeaways

Security researchers at cloud security firm Wiz revealed today that DeepSeek, the Chinese AI startup making headlines for its cost-efficient models, left a database containing millions of user chat logs and API secrets publicly accessible without any authentication requirements.

Why it matters: The exposure of DeepSeek‘s internal database fundamentally challenges the company’s security practices at a crucial moment when it’s gaining prominence in the global AI race and facing increased regulatory scrutiny.

Technical Details: The security flaw centered on an exposed ClickHouse database accessible through two company subdomains:

  • No authentication required
  • Over 1 million lines of sensitive data
  • Plaintext chat histories exposed

Security Impact: The exposed database contained critical information:

  • API keys and secrets
  • Backend operational details
  • Server directory structures

Amit Luttwak, Wiz CTO: Luttwak said, “They took it down in less than an hour. But this was so simple to find, we believe we’re not the only ones who found it.”

Looking Forward: While DeepSeek secured the database within an hour of notification, the incident raises questions about security practices at rapidly growing AI companies. 

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →