Disclosures and evidence

Revision 1 of 1 · Evidence cutoff Jan 29, 2025, 11:59 PM UTC

0 prior statements preserved · 11 statements added. Attributed source statements retain the source’s qualifications.

What the source reports

  1. Wiz Research stated: “Upon further investigation, these ports led to a publicly exposed ClickHouse database , accessible without any authentication at all – immediately raising red flags.”

Reported data impact

  1. Wiz Research stated: “This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details.”

  2. Wiz Research stated: “The log_stream table contained over 1 million log entries , with particularly revealing columns:”

  3. Wiz Research stated: “string.values – Plaintext logs , including Chat History , API Keys, backend details, and operational metadata”

  4. Wiz Research stated: “_source – Exposing the origin of log requests , containing Chat History, API Keys, directory structures, and chatbot metadata logs”

Response

  1. Wiz Research stated: “Wiz Research has identified a publicly accessible ClickHouse database belonging to DeepSeek, which allows full control over database operations, including the ability to access internal data. The exposure includes over a million lines of log streams containing chat history, secret keys, backend details, and other highly sensitive information. The Wiz Research team immediately and responsibly disclosed the issue to DeepSeek, which promptly secured the exposure.”

Dates and disclosures

  1. Wiz Research stated: “January 29, 2025 |”

  2. Wiz Research stated: “timestamp – Logs dating from January 6, 2025”

Qualifications and uncertainty

  1. Wiz Research stated: “More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.”

  2. Wiz Research stated: “This level of access posed a critical risk to DeepSeek’s own security and for its end-users. Not only an attacker could retrieve sensitive logs and actual plain-text chat messages, but they could also potentially exfiltrate plaintext passwords and local files along propriety information directly from the server using queries like: SELECT * FROM file('filename') depending on their ClickHouse configuration.”

  3. Wiz Research stated: “(Note: We did not execute intrusive queries beyond enumeration to preserve ethical research practices.)”

Disclosure sources and provenance

  • Wiz Research Publisher posted January 29, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 6:07 PM UTC · Retained Oct 7, 2026, 6:07 PM UTC
    • Current captured representation; historical byte snapshots are unknown.

Evidence limitations

  • Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
  • Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.