Advertisement
Ai

DeepSeek Database Breach Exposes Chat Histories and Internal Secrets

DeepSeek Database Breach Exposes Chat Histories and Internal Secrets

Compiled by the editorial desk with reference to Wiz's vulnerability report and statements from Wiz researchers as reported by Wired.

Security researchers have discovered that DeepSeek, the Chinese AI startup that recently disrupted the industry with its low-cost open-source model, left a database containing user chat histories and internal operational secrets exposed to the internet without any password protection. The finding, made by researchers at cloud security firm Wiz, raises serious questions about the company's data-handling practices just as its popularity surges.

The vulnerability came to light when Wiz's team, while probing DeepSeek's backend, accessed a database that held a substantial amount of sensitive material. According to the firm's report, the data included not only chat logs but also log streams, API secrets, and operational details. The access required no authentication, meaning anyone who stumbled upon the database could have read or extracted the contents.

Wiz researchers noted that the exposure was not hidden in a neglected corner of DeepSeek's infrastructure. Instead, it was readily accessible, which they described as an unusually glaring oversight. "Usually when we find this kind of exposure, it's in some neglected service that takes us hours to find," said Nir Ohfeld, Wiz's head of vulnerability research, in an interview with Wired. With DeepSeek, the issues were right "at the front door," he added.

How the Leak Was Sealed

After discovering the open database, Wiz attempted to contact DeepSeek to alert them to the problem. The process proved difficult, with the researchers resorting to LinkedIn messages and emails to every DeepSeek account they could find or guess. Despite the lack of a direct reply, the database was secured within an hour of the initial alert, according to Wired.

The quick response, however, did little to mitigate concerns about what could have happened if the exposure had been found by malicious actors. Wiz's chief technology officer, Ami Luttwak, emphasized the severity of the lapse. "The fact that mistakes happen is correct, but this is a dramatic mistake, because the effort level is very low and the access level that we got is very high," he told Wired. He added that the incident suggests DeepSeek's service is not mature enough to handle sensitive data.

Broader Implications for AI Security

The breach also offered a rare glimpse into DeepSeek's internal operations. Wiz researchers found that the company's infrastructure closely mirrors that of OpenAI, a detail that could be of interest to competitors and security experts alike. While the information was obtained by white-hat researchers, the ease of access underscores the potential risks for any AI firm handling large volumes of user data.

DeepSeek has not publicly commented on the vulnerability report. The company's rise to prominence, driven by its cost-efficient model, has already made it a major player in the AI landscape, but this incident highlights the growing pains that come with rapid scaling. For users and industry observers, it serves as a reminder that even the most talked-about AI companies are not immune to basic security oversights.

As the AI sector continues to expand, the DeepSeek incident may prompt other firms to scrutinize their own data protection measures. For now, the episode stands as a cautionary tale about the importance of securing backend systems, especially when they hold sensitive user information.

Comments