Search
Advertisement
Researchers find DeepSeek’s AI database exposed online, leaking chat history and secret keys

Researchers find DeepSeek’s AI database exposed online, leaking chat history and secret keys

Security experts at Wiz Research have identified a major data breach involving DeepSeek, a Chinese AI firm. The breach exposed sensitive data, prompting urgent security measures.

Danny D'Cruze
Danny D'Cruze
  • Updated Jan 31, 2025 6:18 AM IST
Researchers find DeepSeek’s AI database exposed online, leaking chat history and secret keysDeepSeek

Security researchers at Wiz Research discovered that a database belonging to DeepSeek, a Chinese AI startup, was left publicly accessible online. This database contained sensitive information, including chat history, secret keys, and backend details.

The exposed database was running on ClickHouse, a widely used system for processing large datasets. It was hosted on DeepSeek’s domains and could be accessed without any authentication. This meant that anyone who found it could view and even control the data inside.

Advertisement

Related Articles

According to Wiz Research, the issue was reported to DeepSeek, which quickly took action to secure the database.

DeepSeek is known for its AI models, including DeepSeek-R1, which competes with top AI systems like OpenAI’s models. The fact that such a company had a major security lapse raises concerns about how AI startups handle sensitive user data.

How was it discovered?

The researchers scanned DeepSeek’s public-facing systems and noticed unusual open ports. These ports led them to a fully open ClickHouse database, where they found over one million log entries. The leaked data included:
    •    Chat history and user interactions
    •    API keys (which could be used to access DeepSeek’s internal systems)
    •    Backend details of how DeepSeek operates
    •    Operational metadata about AI services

Advertisement

The database also allowed full administrative control, meaning an attacker could not only read but also modify or delete data.

The bigger picture

This case highlights a growing problem: AI companies are moving fast but often neglect basic security measures. While discussions around AI security focus on futuristic threats, real dangers—like exposed databases—are happening right now.

As AI services become essential to businesses, companies must prioritise data security and work closely with cybersecurity teams to prevent such incidents.

For Unparalleled coverage of India's Businesses and Economy – Subscribe to Business Today Magazine

ABOUT THE AUTHOR

Danny D'Cruze
Danny D'Cruze

When Danny is not tinkering with his latest gadget you'll find him in the kitchen whipping up a new recipe. To balance out all the eating, he enjoys working out and taking long walks.

When he's not immersed in his hobbies, Danny is a social butterfly who loves meeting new people and getting to know them over a good conversation. He's also an avid gamer who can spend hours lost in a virtual world, and a dance enthusiast who's ever ready to hit the dance floor.

Danny loves long drives and podcasts. He's always eager to share his latest discovery and can talk for hours about his favorite shows. 

Published on: Jan 31, 2025 6:18 AM IST