Wiz: DeepSeek left one of its critical databases exposed, leaking more than 1M records including system logs, user prompt submissions, and users' API keys
China-based DeepSeek has exploded in popularity, drawing greater scrutiny. Case in point: Security researchers found more than 1 million records …
Wired
Context & Ripple Effects
DeepSeek’s rapid rise had already brought attention to its policy of storing user-provided model content on servers in China. This exposure makes the security handling of that data an operational issue, not solely a disclosure-policy question.
It also arrives as Microsoft and OpenAI were reportedly examining suspected unauthorized API data acquisition tied to a DeepSeek-linked group, increasing scrutiny of the company’s data-access controls from multiple directions.
First-order effects
- DeepSeek must secure the exposed database and assess the impact on people whose prompts, system logs, and API keys were included in the more than 1 million records.
- Affected API users may need to rotate credentials and review usage, while exposed prompts and logs create a potential confidentiality concern for users of the service.
Second-order effects
- Enterprise users and prospective customers are likely to subject DeepSeek’s data handling and deployment controls to closer review, especially given the company’s stated collection and storage practices.
- Competing AI providers can position security controls, credential management, and clearer data-governance practices as differentiators when customers evaluate model platforms.
Third-order effects
- If prominent AI labs repeatedly pair rapid adoption with exposed operational data, security maturity will become more central to the legitimacy of their data practices and to enterprise procurement decisions.
- The episode points toward AI services being judged not only on model capability and price, but on the resilience of the infrastructure that stores prompts, logs, and access credentials.
The trend: As AI platforms scale quickly, infrastructure security and data governance are becoming core competitive requirements alongside model performance.
Related: Ecosystem cyber defense · Strategic legitimacy for AI labs · DeepSeek · API · DeepSeek privacy policy and data collection · OpenAI and Microsoft’s DeepSeek-linked API inquiry
Related Coverage
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History Wiz Blog · Gal Nagli
- DeepSeek's AI success is overshadowed by a serious security breach AppleInsider · Andrew Orr
- DeepSeek exposed internal database containing chat histories and sensitive data TechCrunch · Zack Whittaker
- Security researchers found a big hole in DeepSeek's security Engadget · Lawrence Bonk
- DeepSeek AI exposed databases with user chat history, API keys BleepingComputer · Bill Toulas
- Why It's Cheap and Easy to Mimic OpenAI's Reasoning Model The Information · Rocket Drew
- DeepSeek AI platform exposed user data through unsecured database SC Media
- DeepSeek AI Database Exposed: Over 1 Million Log Lines, Secret Keys Leaked The Hacker News
- Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek The Register · Thomas Claburn
- Sensitive DeepSeek data exposed to web, cyber firm says Reuters · Raphael Satter
- DeepSeek leaks one million sensitive records in a major data breach CSO
- DeepSeek Exposed Database Leaks Sensitive Data Infosecurity · Kevin Poireault
- DeepSeek data exposed online due to unsecured database, claims cybersecurity firm Tech Monitor · Swagath Bandhakavi
- DeepSeek AI Exposed Over 1M Chat History Logs and API Keys CyberInsider · Amar Ćemanović
- DeepSeek Database Exposed: A Major Security Blunder Gizchina.com · Efe Udin
- Sensitive DeepSeek Data Exposed Online Silicon UK · Matthew Broersma
- DeepSeek database contains chat history, internal secrets for anyone to see TweakTown · Anthony Garreffa
- DeepSeek Database Leaked - Full Control Over DB Secret keys, Logs & Chat History Exposed Cyber Security News · Balaji N
- Sensitive DeepSeek data exposed to web: cyber firm Wiz report The Economic Times
- DeepSeek AI Stumbles As Sensitive User Data Is Exposed To The Web HotHardware · Zak Killian
- DeepSeek security breach - critical databases exposed, more than one million records reportedly leaked TechRadar · Benedict Collins
- DeepSeek Left Database With Chat History, Internal Secrets Out In Public For Anyone To Access Wccftech · Ramish Zafar
- DeepSeek left API keys, plaintext logs exposed in easily found database The Stack
- Unsurprisingly, #DeepSeek is as much of a security disaster as other haphazardly put together chatbot interfaces have been. (One would hope that ChatGPT has done some hardening since launch, but they had similar security vulnerabilities especially in their first year.) — https://www.wiz.io/... @eloquence@social.coop · Erik Moeller
- DeepSeek AI was a hot topic in recent days, and now even more, especially in context of its security. … Krzysztof Pranczk
- This is HUGE! Wiz, the market leader in CNAPP, just discovered a huge issue with DeepSeek exposing ALL user prompts, API keys etc. … Casey Bleeker
- Exposed DeepSeek database leaking sensitive information, including chat history Hacker News
Discussion
-
@lukaszolejnik
Lukasz Olejnik
on bluesky
Cybersecurity of AI systems. DeepSeek database (leak?) was accessible publicly (development servers oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000), contained some chat histories. Since it was public, it could've leaked or be stolen, with highly sensitive data. www.…
-
@mattburgess1
Matt Burgess
on bluesky
NEW: DeepSeek left a database exposed to the web. — It contained more than one million files, including prompts and API keys, researchers at cloud security firm Wiz say — Story with @lhn.bsky.social
-
@braithwaite.dev
Alan
on bluesky
Interesting and serious vuln in DeepSeek's dev infra found by Wiz https://buff.ly/4jBy42s — Obviously an observability database, but ofc chat logs got in there. — Rocket building prompts in the post. But most likely it's training data to prevent the AI from responding.
-
@marypcbuk
Mary Branscombe
on bluesky
that DeepSeek outage? yeah, they really weren't ready for people to take much of an interest because they hadn't remembered to secure their ClickHouse database so um yikes
-
@nathanpeck.com
Nathan Peck
on bluesky
Phew this is a spicy one: DeepSeek apparently had a misconfigured DB that allowed anyone to connect to the DB and query chat conversations. Huge privacy breach! — And that's why you run models local, or use a trustworthy API like Bedrock, instead of using startup APIs: www.wiz…
-
@marko.social
Marko Bevc
on bluesky
Well, that didn't take very long 😜 — www.wiz.io/blog/wiz-res... #AI #security
-
@LukaszOlejnik@mastodon.social
Lukasz Olejnik
on mastodon
DeepSeek database was accessible publicly (development servers oauth2callback.deepseek.com:9000 and dev.deepseek.com:9000), contained some chat histories. Since it was public, it could have leaked or be stolen, with highly sensitive data. https://www.wiz.io/... [image]
-
@mavolpi
Mike Volpi
on x
.@deepseek_ai using @ClickHouseDB. I guess they know how to use the best.... https://www.wiz.io/...
-
@lostinsecurity
David Barroso
on x
We all agree that @deepseek_ai should level up their security, but since when do companies try to compromise other companies without any bug bounty or authorization?
-
@wiz_io
@wiz_io
on x
BREAKING: Internal #DeepSeek database publicly exposed 🚨 Wiz Research has discovered “DeepLeak” - a publicly accessible ClickHouse database belonging to DeepSeek, exposing highly sensitive information, including secret keys, plain-text chat messages, backend details, and logs. [i…
-
@ceo_clickhouse
Aaron Katz
on x
Great to see @deepseek_ai using @ClickHouseDB to handle logging at scale. ClickHouse does not allow external connections by default. If someone wants to configure an unauthenticated access from the Internet, they have to do the following extra steps: - enable listening to the
-
@miguel_de_vega
Miguel de Vega
on x
Collecting sensitive information you don't need to run your service and failing to protect it is a double felony in privacy land You can't leak what you can't see. That's why @nillionnetwork enables developers to build and deploy applications on infrastructure where nodes never
-
@mayazi
Maya Zehavi
on x
It's almost like DeepSeek is a honeypot open to all for the grab. A good lesson as to what kind of security & privacy concerns users need to be warned of.
-
@wiz_io
@wiz_io
on x
📌 Takeaways for security teams → AI security starts with infrastructure: lock down databases & access controls. → Visibility is key: work closely with AI engineers to map out risks. Read the full research 👇 https://www.wiz.io/...
-
@dcuthbert
Daniel Cuthbert
on x
“(Note: We did not execute intrusive queries beyond enumeration to preserve ethical research practices.)” https://www.wiz.io/... Whilst the research is solid, I do question what ethical paths were taken here given if this was the other way around, we'd be crying.
-
@0ceans404
@0ceans404
on x
“no one cares about privacy” “privacy isn't sexy” “privacy enhancing tech isn't worth the trouble” until 👇🧵
-
@joab_jackson
Joab Jackson
on x
“And for the record if you are using open tools to point to something like DeepSeek, you are straight up going to get hurt.” — @cmcluck @StackLokHQ https://www.wiz.io/...
-
r/programmingHungary
r
on reddit
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
-
r/cybersecurity
r
on reddit
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History | Wiz Blog
-
r/technews
r
on reddit
Exposed DeepSeek Database Revealed Chat Prompts and Internal Data
-
r/LocalLLaMA
r
on reddit
Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History