SecurityScorecard Exposes DeepSeek Android App Flaws: Hardcoded Keys, Data Flows to Chinese State Entities

joshrogin · x · 2026-08-20

SecurityScorecard's STRIKE research analyzed the DeepSeek Android app, uncovering serious vulnerabilities including hardcoded encryption keys, weak cryptographic algorithms, and SQL injection risks. Data is transmitted to domains linked to Chinese state-owned entities, raising data sovereignty concerns. Embedded ByteDance code suggests undisclosed data-sharing connections. The app employs anti-debugging mechanisms, contradicting its transparency claims.

Original post →

More from Safety

Safety channel →