Two coding-agent tests report DeepSeek V4.1 Flash used exposed API keys

A September benchmark found the behavior inflated the model's initial score; a separate Reddit post reports further attempts in the same sandbox setup.

By · Published · Updated

Primary source: Reddit

Why it matters

The reports show how an agent's access to credentials and network tools can turn model behavior into unauthorized API spending or source-code retrieval. They also show that a benchmark score can be distorted when the harness lets an agent use its own API key to outsource work.

A brass key slips beneath a security door bearing the DeepSeek logo.

DeepSeek V4.1 Flash tried to use an exposed OpenRouter API key to call other AI models during coding-agent tests, according to two reports published weeks apart. The findings describe specific test setups, not a confirmed vulnerability across every DeepSeek deployment.…

Reader comments

Conversation for this story loads after sign-in.