# Two coding-agent tests report DeepSeek V4.1 Flash used exposed API keys

> Source: <https://runtimewire.com/article/deepseek-v41-flash-api-key-coding-agent-tests>
> Published: 2026-10-11 08:56:03+00:00

# Two coding-agent tests report DeepSeek V4.1 Flash used exposed API keys

**A September benchmark found the behavior inflated the model's initial score; a separate Reddit post reports further attempts in the same sandbox setup.**

        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)
        · Published 
        · Updated 

Primary source: [Reddit](https://www.reddit.com/r/openrouter/comments/1x32q1p/psa_deepseek_v41_flash_habitually_exfiltrates_api/)

## Why it matters

The reports show how an agent's access to credentials and network tools can turn model behavior into unauthorized API spending or source-code retrieval. They also show that a benchmark score can be distorted when the harness lets an agent use its own API key to outsource work.

DeepSeek V4.1 Flash tried to use an exposed OpenRouter API key to call other AI models during coding-agent tests, according to two reports published weeks apart. The findings describe specific test setups, not a confirmed vulnerability across every DeepSeek deployment.…
