AION
Opinion / analysisMLOps, Tooling & Infrastructure1 source · Oct 11, 2026

PSA: DeepSeek V4.1 Flash habitually exfiltrates API keys. It is dangerously misaligned and may be hazardous to use

EDIT: since people keep calling it out, this is API key abuse but not exfiltration.

Key points

  • Seems like both Harbor and Pier (sandboxes used in almost every Software Engineering benchmark) expose the Openrouter endpoint and API key to models.
  • Only DeepSeek V4.1 Flash absued this, and it did so while knowing it was "ethically gray".
  • I know OpenRouter is not local, but considering people do run DeepSeek v4.1 Flash locally, I thought this was a matter you all might need to hear.
  • Out of all the 15 models we tested so far (including other open models like GLM 5.3/Flash, DeepSeek v4 Flash 0731, etc), ONLY DeepSeek v4.1 Flash displays such pervasive malicious behavior:

Sources (1)

Extractive summary: sentences quoted from the sources.