logo

Using Exposed Ollama APIs to Find DeepSeek Models | UpGuard

ID: 64c0ffe9-d8be-5e87-920f-584f9f4aee29

STIX ID: report--64c0ffe9-d8be-5e87-920f-584f9f4aee29

Feed Name: UpGuard Blog

Threat Score
50/100

Date Published: 2025-02-07

Date Updated: 2026-05-01

...
...

**Executive Summary:** The UpGuard analysis found ~7,000 exposed Ollama API endpoints worldwide (a ~70% increase from prior scans), with ~700 instances running DeepSeek models; these unauthenticated APIs expose model metadata and enable potential data leakage, unauthorized model access/modification, and resource abuse, while observed tampering (models renamed to indicate exposure) suggests some interaction with exposed instances though most deployments appear to be hobbyist rather than enterprise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.