Timeline

Security researchers flag hard-coded encryption keys and unencrypted data transmission in DeepSeek's mobile app

NowSecure found DeepSeek's iOS app used a deprecated 3DES cipher with an extractable hard-coded key and sent device and network data unencrypted.

  • Security & misuse
  • Minor

The mobile security firm NowSecure published a teardown of DeepSeek’s iOS app finding that it encrypted some data using the deprecated 3DES cipher with a key hard-coded into the app itself — meaning the key needed to decrypt intercepted traffic could be extracted from the software rather than being secret. The app also disabled iOS’s built-in App Transport Security protection and, NowSecure found, transmitted device information, including device name, type and fingerprinting data along with the user’s IP address, over the network without encryption.

Some of that traffic went to Volcengine, ByteDance’s cloud platform, though NowSecure said the full extent of what data was shared and with whom remained unclear from its analysis. NowSecure founder Andrew Hoog was quoted saying there was “virtually no priority around security or privacy” in the app’s engineering, and that the lapses put both individual users and any organisation whose staff had installed it at risk.

The report followed closely behind other security findings about DeepSeek’s infrastructure, including an exposed database discovered by researchers at Wiz, and arrived days after DeepSeek’s app had topped download charts on both the Apple and Google app stores following the release of its R1 model in late January. Several governments and companies moved to restrict DeepSeek’s apps on official devices in the weeks that followed, citing this cluster of findings alongside broader concerns about data handling under Chinese law.