1 Static Analysis of The DeepSeek Android App
Adrian Fritzsche edited this page 1 month ago


I conducted a fixed analysis of DeepSeek, a Chinese LLM chatbot, using version 1.8.0 from the Google Play Store. The objective was to recognize potential security and personal privacy issues.

I have actually blogged about DeepSeek previously here.

Additional security and privacy issues about DeepSeek have been raised.

See also this analysis by NowSecure of the iPhone variation of DeepSeek

The findings detailed in this report are based simply on fixed analysis. This implies that while the code exists within the app, there is no conclusive proof that all of it is performed in practice. Nonetheless, the existence of such code warrants scrutiny, specifically given the growing concerns around information personal privacy, monitoring, the possible misuse of AI-driven applications, and cyber-espionage characteristics between international powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct information to external servers, raising issues about user activity monitoring, such as to ByteDance "volce.com" endpoints. NowSecure identifies these in the iPhone app the other day also. - Bespoke file encryption and information obfuscation methods are present, with indications that they could be utilized to exfiltrate user details.