Within minutes, we found a publicly accessible ClickHouse database linked to DeepSeek, completely open and unauthenticated, exposing sensitive data. [...] This database contained a significant volume of chat history, backend data and sensitive information, including log streams, API Secrets, and operational details. [...] More critically, the exposure allowed for full database control and potential privilege escalation within the DeepSeek environment, without any authentication or defense mechanism to the outside world.
DeepSeek had reached the top of the app stores in the week Wiz went looking. What Wiz found was not a flaw in the model but an open door beside it: a ClickHouse database on two DeepSeek subdomains, reachable over the public internet with no password, holding more than a million log lines including plaintext chat history and API keys, and accepting arbitrary SQL. Wiz disclosed it and DeepSeek closed it quickly. The case is here because the failure was ordinary infrastructure hygiene at a company moving faster than its own operations, which is the shape most AI data exposure actually takes.