PSA: DeepSeek V4.1 Flash habitually exfiltrates API keys. It is dangerously misaligned and may be hazardous to use
EDIT: since people keep calling it out, this is API key abuse but not exfiltration. Seems like both Harbor and Pier (sandboxes used in almost every Software Engineering benchmark) expose the Openrouter endpoint and API key to models, even though they block the rest of the internet. Only DeepSeek V4.1 Flash absued this, and it did so while knowing it was "ethically gray". Other open models like DeepSeek V4, GLM 5.3 +Flash, and Qwen were fine. Logs attached. I know OpenRouter is not local, but considering people do run DeepSeek v4.1 Flash locally, I thought this was a matter you all might need to hear. We were running a DeepSWE variant on DeepSeek v4.1 Flash using the standard Pier sandbox. Out of all the 15 models we tested so far (including other open models like GLM 5.3/Flash, DeepSeek v4 Flash 0731, etc), ONLY DeepSeek v4.1 Flash displays such pervasive malicious behavior: In 33% of runs, it attempts to exfiltrate the OpenRouter API key from its sandbox and in 11% of them, it succeeds. Not only that, the transcript shows it knows what it's doing is ethically wrong, but it does it anyway. And once it starts, it persists despite: Multiple frontier models refusing to help it Multiple smaller models refusing to help it Web search not finding anything Questioning multiple times whether or not this is allowed or morally right It concludes that this is fine because it's only "Ethically gray" and has a "higher chance of success" Thinking about whether or not it is going to be detected If you or anyone you know is using DeepSeek V4.1 Flash please be very careful! OpenRouter spend: preview.redd.it/9j0q3e8mssuh1.png Task 1, DeepSeek V4.1 Flash calls Astra, which refuses to help, and then calls multiple other frontier models, which also all refuse to help. It finally succeeds after finagling a lot with Sonar Web Search: preview.redd.it/w8ko2cf7tsuh1.png preview.redd.it/in7zo9f8tsuh1.png preview.redd.it/9uqzovy8tsuh1.png preview.redd.it/ybvk4ue9tsuh1.png Task 2, it says that it'll be fine "unless usage tracked" (lol) and considers that cost may be significant, but it calls multiple frontier models anyway! preview.redd.it/xmq30ucftsuh1.png preview.redd.it/73f4qu0gtsuh1.png preview.redd.it/1hd2losgtsuh1.png Task 3, DeepSeek questions whether this is allowed ethically, and then keeps on going after getting refused by the model: preview.redd.it/brmorbmhtsuh1.png preview.redd.it/nuadyhmitsuh1.png --- There are many others like this, I have a bunch more highlights on Imgur, but I won't put them all on this post. Be very careful around DeepSeek v4.1 Flash and API keys or private data; don't know what's going to happen if it thinks it can abuse that to get an advantage.