DeepSeek left a database of chat logs and API keys exposed online

Organization
DeepSeek
Exploit
Misconfiguration
Industry
Technology (Artificial Intelligence)

Wiz Research disclosed on January 29, 2025 that it had found a publicly accessible ClickHouse database belonging to the Chinese artificial intelligence developer DeepSeek. The instance was reachable over the open internet on two company subdomains, on ports 8123 and 9000, with no authentication of any kind, which gave anyone who located it full control over database operations.

According to Wiz, the database held more than a million lines of log data, with entries dating back to January 6, 2025. The records included plaintext user chat history, API secrets and keys, backend service details, and operational metadata that revealed parts of DeepSeek's internal infrastructure. Wiz said the exposure also opened a path to escalate privileges inside the company's environment.

The researchers said they restricted their own activity to enumeration queries rather than reading or extracting the underlying data, and reported the finding directly to DeepSeek. The company locked the database down promptly, within roughly an hour of being notified according to Forbes.

The exposure surfaced while DeepSeek was drawing sudden global attention for its low cost reasoning models. Forbes noted that the leak could raise GDPR and CCPA compliance questions if records belonging to European or United States residents were involved. Neither Wiz nor DeepSeek said whether anyone else had reached the database before it was secured.

Sources