DeepSeek’s app contains serious privacy and security vulnerabilities that you should know about

DeepSeek logo on smartphone in front of merging US and Chinese flags
(Image credit: NurPhoto / Getty Images)

Tech fans who flocked to try out DeepSeek will want to think twice about what the app is doing – just days after vulnerabilities were found in the iOS app, a research team at Security Scorecard has found similar privacy concerns in the Android app as well.

Despite the app’s rise in popularity after the release of the R1 reasoning model, several countries including Australia, Italy and Taiwan have banned it from use in government departments or on government devices amid privacy concerns. While the latest report from Security Scorecard doesn’t show any overtly malicious behavior, it does point to some overall poor security practices.

The concerns include sending user data to China, hardcoded keys, weak cryptography, and vulnerabilities to SQL injection attacks among others. Additionally, the report says that API keys, authentication tokens and passwords are stored in plaintext within application files which increases risks of unauthorized access and account takeover.

The app's privacy policy details additional risky behavior such as collecting “text or audio inputs, prompts, uploaded files, feedback and chat history.” It also gathers technical information like IP addresses, operating system, device model and – most concerningly – “keystroke patterns or rhythms.” This last part is considered most intrusive as it can be used to infer both identity and behavior.

Security Scorecard analyzed the app and identified these issues based on the CWE (Common Weakness Enumeration) list. High risk weaknesses include things like hardcoded keys, SQL injection risks, improper file permissions, while analysis of DeepSeek’s Smali code revealed multiple anti-debugging techniques. If debugging is detected; the application force closes itself to prevent analysis.

The report also examines the likelihood of user behavior and device metadata being sent to ByteDance servers which would raise compliance issues with GDPR, CCPA and national security laws.

If you're thinking about using Deepseek as your new AI tool, this report's findings are more than enough reason to reconsider. Hopefully, its creators are able to fix some of these security issues soon before hackers, governments or other threat actors figure out how to exploit them.

More from Tom's Guide

Category
Arrow
Arrow
Back to MacBook Air
Brand
Arrow
Processor
Arrow
RAM
Arrow
Storage Size
Arrow
Screen Size
Arrow
Colour
Arrow
Storage Type
Arrow
Condition
Arrow
Price
Arrow
Any Price
Showing 10 of 101 deals
Filters
Arrow
Show more
Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
DeepSeek logo on mobile phone
Is DeepSeek safe to use?
DeepSeek logo on smartphone in front of computer data
Massive DeepSeek data leak exposes sensitive info for over 1 million users — what you need to know
DeepSeek logo on smartphone in front of merging US and Chinese flags
DeepSeek AI banned by NASA, US Navy, and more over privacy concerns
DeepSeek AI chat displayed on phone screen in front of Chinese flag
DeepSeek AI collects your keystrokes and may never delete them
Mobile data
Cisco study shows DeepSeek is very susceptible to attacks — here's why
DeepSeek app icon on screen
DeepSeek AI banned in Italy as data privacy concerns pile up
Latest in Online Security
iPhone 15 Pro Max shown in hand
Apple just released emergency security update for flaw used in ‘extremely sophisticated’ attacks — update your iPhone, iPad and Mac right now
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Best antivirus software
How does antivirus software work
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
Latest in News
Samsung Galaxy S25 Edge back
Samsung Galaxy S25 Edge price comes into focus with latest leak
iPhone 15 Pro Max shown in hand
Apple just released emergency security update for flaw used in ‘extremely sophisticated’ attacks — update your iPhone, iPad and Mac right now
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 12 (#640)
Jean Smart as Deborah Vance and Hannah Einbinder as Ava Daniels in Hacks
Max reveals 'Hacks' season 4 release date and trailer — here's when it's coming
Google Pixel 5 review
Google Pixel 10 lineup leaked in new renderings — here's what they look like
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware