Skip to main content
Incident intelligence/SS-IR-056CASE FILE OPEN
Symbolic editorial illustration for SS-IR-056SERVANTSTACK // INCIDENT INTELLIGENCEFORENSIC IMAGE // VERIFIED FRAME
SS-IR-056 // INCIDENT REPORTDocumented

DeepSeek

1 Million+ Chat Logs and API Keys Left on Open Database

EXECUTIVE BRIEF

Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet .

FAILURE CHAINTRACE COMPLETE
  1. 01TRIGGERSecurity researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the…
  2. 02MACHINE ACTIONOperational automation
  3. 03MISSING GATERisk-based SME approval before execution
  4. 04IMPACTData security
01 // INCIDENT SUMMARY

The short version

Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet .

02 // KEY FACTS

Case telemetry

INCIDENT
SS-IR-056
DATE
January 2025
SYSTEM
DeepSeek
LOCATION / SCOPE
China / Global
EVIDENCE
Documented
AI ROLE
Operational automation
HARM
Data security
SOURCES
1 cited record
03ENTRY POINT // WHAT HAPPENED

The event

Security researchers at Wiz discovered that DeepSeek - the Chinese AI company whose R1 model had just shocked the industry - left a ClickHouse database completely open and unauthenticated on the public internet. The database contained over 1 million log entries including plaintext user chat histories, API secret keys, backend operational details, and internal service metadata. Anyone could execute arbitrary SQL queries against the database. The exposure was found on two public endpoints: oauth2callback.deepseek.com and dev.deepseek.com.

04CAUSAL TRACE // AI'S ACTUAL ROLE

What the machine did

DeepSeek's rapid deployment - rushing to capitalize on the viral success of its R1 model - prioritized speed over security. The automated deployment pipeline stood up production databases without authentication. No human reviewed the security configuration before the databases went live. The same "move fast" philosophy that produced a competitive AI model also exposed every conversation users had with it.

Operational automationAutomation was a causal participant—not a decorative label for the system around it.
05BLAST RADIUS // CONSEQUENCES

Where the failure landed

1 million+ user chat logs exposed, including potentially sensitive conversations with an AI assistant. API keys compromised, allowing unauthorized access to DeepSeek's infrastructure. The exposure allowed full database control - attackers could have extracted files, escalated privileges, or modified data. Wiz responsibly disclosed and DeepSeek secured the databases, but the window of exposure was unknown.

06 // EVIDENCE STATUS

Documented

Supported by a first-party disclosure, technical research, or corroborated reporting cited below.

SOURCE RECORD UPDATED 2026-07-09

07 // SOURCE LEDGER

1 cited record

  1. 01
08CONTROL FAILURE // MISSING GOVERNANCE

Risk-based SME approval before execution

The failure pattern in this case: High-stakes output had no accountable checkpoint.

09INTERVENTION POINT // HUMAN IN THE MIDDLE

The moment the path could change

The appropriate subject-matter expert reviews the evidence, exceptions, and affected people before the output becomes action.

AI PROPOSESHUMAN OWNS THE DECISIONSYSTEM EXECUTES
10CONTROL DEPLOYMENT // AUTHORITYGATE

Risk routing · named approval · audit trail

AuthorityGate's framework requires security review by an infrastructure SME before any database is exposed to the public internet. A basic pre-deployment checklist - authentication enabled? firewall rules configured? PII encrypted? - would have caught an open ClickHouse instance in seconds. The framework treats deployment speed as subordinate to security validation.

DIRECT AUTHORITYGATE ANALYSISDeepSeek's Database Had No AuthenticationThe complete analysis of the exposed ClickHouse service, live-state validation, drift, and accountable deployment approval.
12 // THE ALTERNATIVE

Autonomy is a design choice.

See the operating model that keeps AI useful while preserving human authority at consequential moments.

Compare AgenticAI and AugmentedAI →