ZeroHour
Story · 1 source · 2 articlesfirst updated ()

DeepSeek v4.1 Flash: Uncensored Community Release and Perfect 11/11 Score on Enclave's AI Hacking Benchmark

infoAI safety & securityimportance 60
What's new: Within five days, DeepSeek v4.1 Flash went from a low-visibility community upload (uncensored FP8 quantization on Hugging Face) to a top-scoring model on Enclave's AI hacking benchmark with a perfect 11/11. Separately, the benchmark itself changed: scoring was hardened from outcome-only checks to path-level audits after the model was found to succeed via alternate attack routes the original…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Days after a third-party uncensored FP8 build of DeepSeek v4.1 Flash appeared on Hugging Face, Enclave AI reported the model achieved 11/11 code executions on its hacking benchmark (Grafana, Jenkins, Nextcloud) for $4.65 accepted, prompting a stricter…

Two reports from Hacker News cover the same model, DeepSeek v4.1 Flash, from different angles. On 2026-09-11, Hugging Face user dealignai published an uncensored FP8-quantized variant of DeepSeek v4.1 Flash as a third-party upload (not an official DeepSeek release), with no benchmark data or license details in the listing; it drew limited attention (43 points, 11 comments). On 2026-09-16, Enclave AI reported that DeepSeek V4.1 Flash gained code execution on all 11 vulnerable targets — Grafana, Jenkins, and Nextcloud — while all four fixed controls held, costing $4.65 accepted ($5.14 total) with 268.3 million mostly cached input tokens. The median successful run took 4 minutes 38 seconds over 2,349 Bash commands. Exploited techniques included Grafana plugin loading, Jenkins credential exposure, an upload race, and Nextcloud access control. A path-level audit found six runs used the benchmark's planned weaknesses (e.g., Jenkins credential-file abuse and Nextcloud access-control confusion), while five runs exploited alternate routes in the Grafana and Jenkins test environments that the original scoring missed. Enclave responded by hardening the benchmark to check attack paths, not just outcomes. Note: the benchmark report does not state whether the tested model was the uncensored quantization or an official build, so no link between the two releases is established.

  • Hugging Face user dealignai published an uncensored FP8-quantized variant of DeepSeek v4.1 Flash on 2026-09-11; it was a third-party upload, not an official DeepSeek release, with no benchmark data or license details in the listing (43…
  • On 2026-09-16, Enclave AI reported DeepSeek V4.1 Flash scored 11/11 code executions on its AI hacking benchmark across Grafana, Jenkins, and Nextcloud targets, while all four fixed controls held.
  • Benchmark run cost: $4.65 accepted ($5.14 total) using cached-token pricing, with 268.3 million mostly cached input tokens.
  • Median successful run took 4 minutes 38 seconds over 2,349 Bash commands.
  • Techniques observed: Grafana plugin loading, Jenkins credential exposure, an upload race, and Nextcloud access control abuse.
  • Path-level audit: six runs used the planned weaknesses (e.g., Jenkins credential-file abuse, Nextcloud access-control confusion); five runs exploited alternate routes in the Grafana and Jenkins test environments that original outcome-based…
  • Enclave hardened the benchmark with stricter path-level checks in response.
  • Sources consistently identify the model as DeepSeek v4.1 / V4.1 Flash; no source conflict on facts, though the reports cover independent facets of the model's adoption.

Coverage timeline

  1. · 6d ago
    Hacker News · AI· 30
    DeepSeek v4.1 Flash Uncensored

    Hugging Face user dealignai published an uncensored FP8-quantized variant of DeepSeek v4.1 Flash, drawing moderate Hacker News attention.

  2. · 23h ago
    Hacker News · AI· 60
    DeepSeek v4.1 Flash Is Now Our Best Hacking Model

    DeepSeek V4.1 Flash achieves 11/11 code executions on Enclave's AI hacking benchmark for $4.65 across Grafana, Jenkins, and Nextcloud targets.