1 Static Analysis of The DeepSeek Android App
marquislaycock edited this page 6 months ago


I conducted a fixed analysis of DeepSeek, a Chinese LLM chatbot, utilizing version 1.8.0 from the Google Play Store. The goal was to identify potential security and privacy problems.

I've blogged about DeepSeek formerly here.

Additional security and personal privacy issues about DeepSeek have been raised.

See also this analysis by NowSecure of the iPhone version of DeepSeek

The findings detailed in this report are based purely on fixed analysis. This means that while the code exists within the app, there is no definitive evidence that all of it is carried out in practice. Nonetheless, the existence of such code warrants scrutiny, specifically given the growing issues around information personal privacy, security, the prospective abuse of AI-driven applications, and cyber-espionage characteristics in between international powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct information to external servers, raising concerns about user activity monitoring, such as to ByteDance "volce.com" endpoints. NowSecure determines these in the iPhone app yesterday too. - Bespoke encryption and data obfuscation techniques are present, systemcheck-wiki.de with signs that they could be used to exfiltrate user details.