Editorial draft v1 · Evidence reader R1 · Evidence cutoff: January 29, 2025

Disclosures covered: Wiz Research's January 29, 2025 report. This is a researcher-attributed exposure account, not a company-authored forensic report.

Wiz Research reported finding a publicly accessible ClickHouse database belonging to DeepSeek that required no authentication. The researchers said it exposed chat history, API secrets, backend details, and operational information, with access sufficient for database control. Their report described an exposure they observed and disclosed; it did not establish that an earlier malicious actor had exploited it. Wiz report

What the researchers found

Wiz said a log table contained more than one million entries, including plaintext chat history, API keys, backend details, directory information, and chatbot operational metadata. Some logs dated from January 6, 2025. The entry count is a count of records, not unique users, accounts, or exposed credentials. The age of the logs likewise does not establish when the database first became publicly accessible or when Wiz discovered it. Wiz report

The researchers described potential privilege escalation and further access to server files or plaintext passwords, depending on the database's configuration. They also said they did not execute intrusive queries beyond enumeration. The demonstrated unauthenticated access and the additional capabilities they considered possible should remain separate. This article does not turn a configuration-dependent risk into a finding that passwords or local files were actually stolen. Wiz report

Disclosure and remediation

According to Wiz, the team immediately disclosed the issue to DeepSeek, which promptly secured the exposure. That is the researcher's account of the response. The selected source does not independently establish a company confirmation, exact duration of exposure, complete historical access log, or all downstream consequences. Wiz report

Editorial interpretation: this case is most clearly understood as a reported open-database exposure with sensitive contents and significant access capability. Neither the log volume nor the severity of possible access supplies a victim count or proof of prior malicious exploitation. The evidence also does not identify an attacker, monetary loss, or a verified total of affected people. Keeping those limits explicit preserves the difference between what Wiz observed, what it considered possible, and what remains unknown. Wiz report

Sources

Disclosure history

Article draft version 1 · Evidence reader revision 1 · Evidence cutoff Jan 29, 2025, 11:59 PM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Wiz Research Publisher posted January 29, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
    • Current captured representation; historical byte snapshots are unknown.