1 Static Analysis of The DeepSeek Android App
alphonsos54998 edited this page 2025-02-10 08:08:37 +01:00


I performed a static analysis of DeepSeek, a Chinese LLM chatbot, using version 1.8.0 from the Google Play Store. The goal was to recognize possible security and personal privacy problems.

I've blogged about DeepSeek formerly here.

Additional security and privacy concerns about DeepSeek have actually been raised.

See also this analysis by NowSecure of the iPhone variation of DeepSeek

The findings detailed in this report are based purely on fixed analysis. This implies that while the code exists within the app, there is no conclusive evidence that all of it is carried out in practice. Nonetheless, the presence of such code warrants scrutiny, specifically given the growing concerns around data privacy, monitoring, the possible abuse of AI-driven applications, and cyber-espionage characteristics in between global powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct data to external servers, raising concerns about user activity tracking, such as to ByteDance "volce.com" endpoints. NowSecure recognizes these in the iPhone app the other day as well. - Bespoke encryption and information obfuscation methods exist, with signs that they might be used to exfiltrate user details.