Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

DeepSeek’s database was wide open—did hackers get in?

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI

byKerem Gülen
January 31, 2025
in News, Cybersecurity
Home News
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

DeepSeek, the trending Chinese artificial intelligence (AI) startup, recently exposed one of its databases on the internet, potentially allowing unauthorized access to sensitive data. The exposed ClickHouse database provided full control over its operations, according to Wiz security researcher Gal Nagli.

DeepSeek exposes over a million lines

The exposure included over a million lines of log streams featuring chat history, secret keys, backend details, and other critical information, such as API secrets and operational metadata. Following notification attempts from the cloud security firm, DeepSeek has since fixed the security vulnerability.

The database, which was accessible at oauth2callback.deepseek[.]com:9000 and dev.deepseek[.]com:9000, enabled unauthorized users to execute arbitrary SQL queries via the web browser without requiring authentication. It remains unclear if any malicious actors accessed or downloaded the data before the issue was resolved.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

Nagli emphasized the risks of rapid AI service adoption without adequate security measures, highlighting that real risks often stem from basic oversights like accidental database exposure. He stated, “Protecting customer data must remain the top priority for security teams, and it is crucial that security teams work closely with AI engineers to safeguard data and prevent exposure.”

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

DeepSeek has garnered significant attention for its innovative open-source AI models that aim to compete with established systems like OpenAI, positioning its reasoning model R1 as an “AI’s Sputnik moment.” Its AI chatbot rapidly climbed to the top of app store rankings across multiple markets, even as the company faced “large-scale malicious attacks,” which led to a temporary pause in new registrations.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

In a January 29, 2025 update, DeepSeek acknowledged the database issue and indicated that it is implementing a fix. Concurrently, the company faces scrutiny regarding its privacy policies, with its Chinese affiliations raising national security concerns in the United States.

In related developments, DeepSeek’s applications became unavailable in Italy after the country’s data protection regulator, the Garante, sought information regarding the startup’s data handling practices and its sources of training data. The withdrawal of apps from the Italian market may or may not have been a direct response to these inquiries, as the Irish Data Protection Commission (DPC) has also made similar information requests.

deepseeks-database-was-wide-open-did-hackers-get-in
Image: Wiz Research

OpenAI and Microsoft are investigating whether DeepSeek used OpenAI’s application programming interface (API) without authorization to train its models through a process known as distillation. An OpenAI spokesperson stated, “We know that groups in [China] are actively working to use methods, including what’s known as distillation, to try to replicate advanced US AI models.”

Tags: deepseekFeatured

Related Posts

OpenAI unveils first official partner program with 0M backing

OpenAI unveils first official partner program with $150M backing

June 15, 2026
Apple is preparing three major new features for iOS 27

Apple is preparing three major new features for iOS 27

June 15, 2026
Google files lawsuit over AI-assisted phishing operation abusing Gemini

Google files lawsuit over AI-assisted phishing operation abusing Gemini

June 15, 2026
“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

June 12, 2026
How Henrique Schmaiske led Meteor.js through its biggest transformation

How Henrique Schmaiske led Meteor.js through its biggest transformation

June 12, 2026
Proven privacy: Why ‘no-log’ claims need real evidence today

Proven privacy: Why ‘no-log’ claims need real evidence today

June 12, 2026

LATEST NEWS

OpenAI unveils first official partner program with $150M backing

Apple is preparing three major new features for iOS 27

Google files lawsuit over AI-assisted phishing operation abusing Gemini

“Free robots are an illusion”: Why we’ll pay for system intelligence, not delivery workers

How Henrique Schmaiske led Meteor.js through its biggest transformation

Proven privacy: Why ‘no-log’ claims need real evidence today

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Stratup.ai

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.