On January 29, 2025, security researchers at Wiz discovered that Chinese AI startup DeepSeek had left a ClickHouse database publicly exposed on the internet with no authentication required. The database contained more than a million log entries, including plaintext user chat history, API keys, and backend operational metadata dating back to January 6, 2025. Wiz privately disclosed the misconfiguration to DeepSeek, which secured the database; there is no public evidence the exposure was exploited by malicious actors before it was fixed.