
DeepSeek
1 Million+ Chat Logs and API Keys Left on Open Database
Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet .
- 01TRIGGERSecurity researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the…
- 02MACHINE ACTIONOperational automation
- 03MISSING GATERisk-based SME approval before execution
- 04IMPACTData security
The short version
Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet .
Case telemetry
- INCIDENT
- SS-IR-056
- DATE
- January 2025
- SYSTEM
- DeepSeek
- LOCATION / SCOPE
- China / Global
- EVIDENCE
- Documented
- AI ROLE
- Operational automation
- HARM
- Data security
- SOURCES
- 1 cited record
The event
Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet. The database contained over 1 million log entries including plaintext user chat histories, API secret keys, backend operational details, and internal service metadata. Anyone could execute arbitrary SQL queries against the database. The exposure was found on two public endpoints: oauth2callback.deepseek.com and dev.deepseek.com.
What the machine did
DeepSeek's rapid deployment - rushing to capitalize on the viral success of its R1 model - prioritized speed over security. The automated deployment pipeline stood up production databases without authentication. No human reviewed the security configuration before the databases went live. The same "move fast" philosophy that produced a competitive AI model also exposed every conversation users had with it.
Where the failure landed
1 million+ user chat logs exposed, including potentially sensitive conversations with an AI assistant. API keys compromised, allowing unauthorized access to DeepSeek's infrastructure. The exposure allowed full database control - attackers could have extracted files, escalated privileges, or modified data. Wiz responsibly disclosed and DeepSeek secured the databases, but the window of exposure was unknown.
Documented
Supported by a first-party disclosure, technical research, or corroborated reporting cited below.
SOURCE RECORD UPDATED 2026-07-09
1 cited record
- 01Primary / officialWiz Research: DeepSeek Database Exposure (2025)
Risk-based SME approval before execution
The failure pattern in this case: High-stakes output had no accountable checkpoint.
The moment the path could change
The appropriate subject-matter expert reviews the evidence, exceptions, and affected people before the output becomes action.
Autonomy is a design choice.
See the operating model that keeps AI useful while preserving human authority at consequential moments.
Compare AgenticAI and AugmentedAI →