Skip to main content

Over a million lines of DeepSeek chat history were exposed in just a few minutes

DeepSeek AI running on an iPhone.
The home page chat interface of DeepSeek AI. Nadeem Sarwar / Digital Trends

Cybersecurity researchers from Wiz have found a ClickHouse database owned by Chinese AI start-up DeepSeek containing over a million lines of chat history and sensitive information. The database was publicly accessible and allowed the researchers full control over database operations.

The exposure was quickly secured after Wiz shared its discovery with DeepSeek, but it’s possible that information could have already been exposed. Research of this kind doesn’t pry too far into the databases it finds for ethical reasons, but Wiz concluded that an attacker could potentially escalate their privileges within the DeepSeek environment and retrieve sensitive logs, chat messages, passwords, and local files — all without needing any kind of authentication.

Screenshot from Wiz research into DeepSeek security.
Wiz / Wiz

Wiz targeted the start-up due to the recent media buzz around its R1 reasoning model, with the goal of assessing its external security. Somewhat shockingly, the ClickHouse database turned up after just a few minutes of basic searches and Wiz was able to interact with it through ClickHouses’s HTTP interface.

Recommended Videos

From there, all the researchers had to do was run a SHOW TABLES; query, and a list of accessible datasets appeared, including the “log_steam” table that included the many lines of sensitive information.

In its report, Wiz warns about the speed of AI adoption and how this pressure to develop, release, and integrate AI products as quickly as possible can lead to dangerous security practices. With all of the important and sensitive data that AI programs are now handling, the industry needs to enforce robust security practices that match those of public cloud providers and major infrastructure providers.

Willow Roberts
Willow Roberts has been a Computing Writer at Digital Trends for a year and has been writing for about a decade. She has a…
Microsoft already has its legal crosshairs set on DeepSeek
DeepSeek AI running on an iPhone.

The home page chat interface of DeepSeek AI. Nadeem Sarwar / Digital Trends

Microsoft, a primary investor in OpenAI, is now exploring whether the Chinese company DeepSeek used nefarious methods to train its reasoning models. According to Bloomberg Law the company now believes DeepSeek violated its terms of service by using its application programming interface (API) to train its recently announced R1 model.

Read more
How DeepSeek flipped the tech world on its head overnight
The DeepSeek website.

DeepSeek, the chatbot made by a Chinese startup that seemingly dethroned ChatGPT, is taking the world by storm. It's currently the number one topic all over the news, and a lot has happened in the past 24 hours. Among other highlights, Nvidia's stock plummeted as a response to DeepSeek; President Donald Trump commented on the new AI; Mark Zuckerberg is assembling a team to find an answer to DeepSeek. Below, we'll cover all the latest news you need to know about DeepSeek.
Nvidia gets hit by the rise of DeepSeek

Although ChatGPT is the chatbot that quickly lost its public favorite status with the rise of DeepSeek, Nvidia is the company that suffered the greatest losses. In fact, Nvidia's market loss following the launch of DeepSeek's large language model (LLM) marks the greatest one-day stock market drop in history, says Forbes. Nvidia lost nearly $600 billion as a result of the Chinese company behind DeepSeek revealing just how cheap the new LLM is to develop in comparison to rivals from Anthropic, Meta, or OpenAI.

Read more
DeepSeek: everything you need to know about the AI that dethroned ChatGPT
robot hand in point space

A year-old startup out of China is taking the AI industry by storm after releasing a chatbot which rivals the performance of ChatGPT while using a fraction of the power, cooling, and training expense of what OpenAI, Google, and Anthropic's systems demand. Here's everything you need to know about Deepseek's V3 and R1 models and why the company could fundamentally upend America's AI ambitions.
What is DeepSeek?
DeepSeek (technically, "Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd.") is a Chinese AI startup that was originally founded as an AI lab for its parent company, High-Flyer, in April, 2023. That May, DeepSeek was spun off into its own company (with High-Flyer remaining on as an investor) and also released its DeepSeek-V2 model. V2 offered performance on par with other leading Chinese AI firms, such as ByteDance, Tencent, and Baidu, but at a much lower operating cost.

The company followed up with the release of V3 in December 2024. V3 is a 671 billion-parameter model that reportedly took less than 2 months to train. What's more, according to a recent analysis from Jeffries, DeepSeek's “training cost of only US$5.6m (assuming $2/H800 hour rental cost). That is less than 10% of the cost of Meta’s Llama.” That's a tiny fraction of the hundreds of millions to billions of dollars that US firms like Google, Microsoft, xAI, and OpenAI have spent training their models.

Read more