Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› DeepSeek Database Exposure 2025: How an Open ClickHouse…
Breach analysis Incident: 29 Jan 2025

DeepSeek Database Exposure 2025: How an Open ClickHouse Database Leaked Chat Logs and API Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Attack route: Misconfiguration Identities: API key Secret or password
On this page

In late January 2025, as DeepSeek's R1 reasoning model was drawing global attention, Wiz researchers mapped the Chinese AI company's internet-facing systems and within minutes found a ClickHouse database open to the internet with no authentication. It was reachable on non-standard ports at oauth2callback.deepseek.com and dev.deepseek.com. Through ClickHouse's web interface, anyone could run arbitrary SQL. A table called log_stream held more than a million log lines from 6 January 2025 onwards, including users' chat history in plain text, API keys, backend details and references to internal API endpoints. Wiz said the exposure allowed full database control and potential privilege escalation. It disclosed the issue to DeepSeek, which secured the database promptly. No misuse by others has been reported.

Key takeaways

  • Wiz found a publicly accessible, unauthenticated ClickHouse database linked to DeepSeek on ports 8123 and 9000.
  • Its log_stream table held more than one million entries dating from 6 January 2025, including plaintext chat history, API keys and backend details.
  • The database's web interface allowed arbitrary SQL, so an attacker could have read logs and potentially pulled files from the server, Wiz said.
  • Wiz disclosed the exposure and DeepSeek secured it promptly; there are no reports of anyone else exploiting it.
  • The identity lesson: logs are a common, overlooked store of secrets, and an unauthenticated data service can leak the credentials of the whole platform.

At a glance

OrganisationDeepSeek, a Chinese AI company
WhenLogs from 6 January 2025 onwards were exposed; found by Wiz in January 2025 and disclosed on 29 January 2025
AttackerNone known. Found by Wiz Research
Entry pointAn internet-facing ClickHouse database on non-standard ports with no authentication
Identities abusedAPI keys and secrets recorded in plaintext logs; unauthenticated database access
ImpactMore than a million log lines, including user chat history and API secrets, exposed to anyone who found the database; no confirmed misuse
CategoryNHI, LLM and AI platform. Incident class: exposure (secrets in exposed logs, no confirmed misuse)

What happened

Wiz set out to assess DeepSeek's external security posture after the company's rapid rise. Passive and active subdomain discovery turned up about 30 internet-facing hosts, most of them benign. But on ports beyond the usual 80 and 443, Wiz found two unusual open ports, 8123 and 9000, on oauth2callback.deepseek.com and dev.deepseek.com. "Upon further investigation, these ports led to a publicly exposed ClickHouse database, accessible without any authentication at all," Wiz wrote.

ClickHouse is an open-source analytical database often used for log storage. Its HTTP interface includes a /play path for running SQL from a browser. A SHOW TABLES query listed the datasets, and one, log_stream, contained "over 1 million log entries" with plaintext logs "including Chat History, API Keys, backend details, and operational metadata", dating from 6 January 2025. Wiz said an attacker "could also potentially exfiltrate plaintext passwords and local files along propriety information directly from the server" using ClickHouse's file functions, depending on configuration, but that it did not run intrusive queries itself.

Wiz "immediately and responsibly disclosed the issue to DeepSeek, which promptly secured it," and published on 29 January 2025. CyberScoop reported that DeepSeek did not respond to its request for comment, and that the same week the company said it was struggling to register new users because of "large-scale malicious attacks." There is no public evidence that anyone other than Wiz accessed the database.

Timeline

DateEvent
6 January 2025The earliest log entries in the exposed log_stream table.
January 2025Wiz finds the unauthenticated ClickHouse database and discloses it to DeepSeek, which secures it.
29 January 2025Wiz publishes its findings.
30 January 2025SecurityWeek and other outlets report the exposure.

How it happened: the identity attack path

  1. Service exposed. A ClickHouse database was reachable from the internet on non-standard ports.
  2. No authentication. Anyone connecting could run queries without credentials.
  3. Secrets in logs. Application logs written to the database contained API keys and chat history in plaintext.
  4. Potential escalation. Database control and file functions could have let an attacker read server files and pivot further, according to Wiz.
  5. Closed after disclosure. DeepSeek secured the database after Wiz reported it.

Impact

  • Exposed: more than a million log lines with user chat history, API keys, backend details and internal endpoint references.
  • Potential: full database control and possible privilege escalation within DeepSeek's environment.
  • Misuse: none confirmed.

What this means for NHI governance

Secrets do not only live in vaults and code. Applications log requests, errors and headers, and those logs often capture API keys and tokens in plain text. Logging systems are then treated as low-risk internal plumbing and exposed or shared more freely than production databases. Here, the result was an open door to both user conversations and the platform's own machine credentials.

For AI companies growing fast, the lesson is to apply ordinary controls first: no data services on the public internet, authentication on everything, and redaction of secrets before they reach logs. For customers of AI services, it is a reminder that API keys and data you send may end up in the provider's logs, so scope and rotate those keys. See our Secrets Management Guide and AI Infrastructure Workload Identity Guide.

Recommendations

  • Keep databases off the public internet. Scan your external footprint on all ports, not just web ports.
  • Require authentication on every data service. Analytical and logging databases hold sensitive data too.
  • Redact secrets before logging. Strip API keys, tokens and passwords from log pipelines. See our Secrets Management Guide.
  • Rotate secrets that appear in logs. Treat any credential found in a log as exposed. See the Leaked Credential Response Playbook.
  • Assess AI vendors' basic security. Before sending sensitive data to an AI provider, check how it protects infrastructure and logs. See the AI Security Platform Buyer's Guide.

Frequently asked questions

Was DeepSeek hacked?

Wiz found a DeepSeek database exposed to the internet without authentication in January 2025 and reported it. DeepSeek secured it promptly. There is no public evidence that anyone else accessed it.

What did the exposed DeepSeek database contain?

More than a million log lines from 6 January 2025 onwards, including plaintext user chat history, API keys, backend details and references to internal API endpoints.

Why are logs a secrets risk?

Applications often log requests and errors that include API keys and tokens. If logs are stored without redaction and exposed, those secrets leak with them.

OmniGPT Breach 2025 · Moltbook AI Agent Key Exposure · Secrets Management Guide · AI Infrastructure Workload Identity Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

AI platforms move fast and secrets end up in unexpected places. We help teams find credentials in logs and data stores, redact them at source and assess AI vendors' basic controls. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org