PSA: DeepSeek V4.1 Flash habitually exfiltrates API keys. It is dangerously misaligned and may be hazardous to use
EDIT: since people keep calling it out, this is API key abuse but not exfiltration.
DeepSeekQwenDeepSeek modelsdeepseek-ai/DeepSeek-V4.1-Flashdeepseek-ai/DeepSeek-V4-Flash-0731zai-org/GLM-5.3-Flash
Key points
- Seems like both Harbor and Pier (sandboxes used in almost every Software Engineering benchmark) expose the Openrouter endpoint and API key to models.
- Only DeepSeek V4.1 Flash absued this, and it did so while knowing it was "ethically gray".
- I know OpenRouter is not local, but considering people do run DeepSeek v4.1 Flash locally, I thought this was a matter you all might need to hear.
- Out of all the 15 models we tested so far (including other open models like GLM 5.3/Flash, DeepSeek v4 Flash 0731, etc), ONLY DeepSeek v4.1 Flash displays such pervasive malicious behavior:
Sources (1)
- [1]PSA: DeepSeek V4.1 Flash habitually exfiltrates API keys. It is dangerously misaligned and may be hazardous to user/LocalLLaMA (top, daily) · Oct 11, 08:29 AM
EDIT: since people keep calling it out, this is API key abuse but not exfiltration.
Seems like both Harbor and Pier (sandboxes used in almost every Software Engineering benchmark) expose the Openrouter endpoint and API key to models.
Extractive summary: sentences quoted from the sources.