1 Static Analysis of The DeepSeek Android App
margaretdickey edited this page 2025-02-11 11:51:38 +01:00


I conducted a static analysis of DeepSeek, a Chinese LLM chatbot, using version 1.8.0 from the Google Play Store. The goal was to identify possible security and privacy problems.

I have actually blogged about DeepSeek previously here.

Additional security and archmageriseswiki.com personal privacy concerns about DeepSeek have been raised.

See also this analysis by NowSecure of the iPhone version of DeepSeek

The findings detailed in this report are based simply on fixed analysis. This suggests that while the code exists within the app, there is no definitive evidence that all of it is carried out in practice. Nonetheless, the presence of such code warrants examination, especially given the growing issues around information privacy, higgledy-piggledy.xyz surveillance, the potential abuse of AI-driven applications, securityholes.science and cyber-espionage dynamics between international powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct information to external servers, raising issues about user activity tracking, such as to ByteDance "volce.com" endpoints. NowSecure recognizes these in the iPhone app the other day too.