DeepSeek v4.1 Flash: terse launch, community FP8 quant, and a perfect 11/11 on Enclave's hacking benchmark
DeepSeek announced v4.1 Flash (2026-09-10) with no technical details; a day later a third-party uncensored FP8 quantization by Hugging Face user dealignai appeared; on 2026-09-16 Enclave AI reported the model achieved 11/11 code executions on its AI hacking…
DeepSeek publicly announced v4.1 Flash in a terse post on its official X account (reported 2026-09-10) containing no benchmarks, parameter counts, or capability details. On 2026-09-11, Hugging Face user dealignai published an uncensored FP8-quantized variant; this was a third-party upload rather than an official DeepSeek release, provided no benchmark data or license details, and drew limited visibility (43 points, 11 comments on Hacker News). Real capability data arrived on 2026-09-16, when Enclave AI reported that DeepSeek v4.1 Flash gained code execution on all 11 vulnerable targets in its AI hacking benchmark — spanning Grafana, Jenkins, and Nextcloud — while all four fixed controls held. The perfect run cost $4.65 accepted ($5.14 total) using 268.3 million mostly cached input tokens, and the median successful run took 4 minutes 38 seconds over 2,349 Bash commands. A path-level audit found six runs used the planned weaknesses (such as Jenkins credential-file abuse and a Nextcloud access-control confusion), while five runs exploited alternate routes in the Grafana and Jenkins test environments that the original scoring missed. The reported exploitation categories include Grafana plugin loading, Jenkins credential exposure, an upload race, and Nextcloud access control. Enclave updated the benchmark with stricter path-level checks, underscoring that hacking agents find the fastest exploitable route.
- DeepSeek announced v4.1 Flash on its official X account (reported 2026-09-10) with no benchmarks, parameter counts, or capability details.
- On 2026-09-11, Hugging Face user dealignai published an uncensored FP8-quantized variant; it is a third-party upload, not an official release, with no benchmark data or license details in the listing (43 points, 11 comments on Hacker News).
- Enclave AI (reported 2026-09-16) scored DeepSeek v4.1 Flash 11/11 on code execution across its AI hacking benchmark targets: Grafana, Jenkins, and Nextcloud; all four fixed controls held.
- Cost: $4.65 accepted ($5.14 total), using 268.3 million mostly cached input tokens; median successful run took 4 minutes 38 seconds over 2,349 Bash commands.
- Path-level audit: six runs used the planned weaknesses (e.g., Jenkins credential-file abuse, Nextcloud access-control confusion); five runs exploited alternate routes in the Grafana and Jenkins test environments that the original scoring…
- Exploitation categories cited: Grafana plugin loading, Jenkins credential exposure, upload race, and Nextcloud access control.
- The benchmark was updated with stricter path-level checks so it validates attack paths, not just outcomes.
Coverage timelineoldest first · each row is one article
- · 6d agoDeepSeek v4.1 Flash
Hacker News · AI· 50
DeepSeek announced v4.1 Flash, a new model version, in a terse social media post without technical details.
- · 5d agoDeepSeek v4.1 Flash Uncensored
Hacker News · AI· 30
Hugging Face user dealignai published an uncensored FP8-quantized variant of DeepSeek v4.1 Flash, drawing moderate Hacker News attention.
- · 10h agoDeepSeek v4.1 Flash Is Now Our Best Hacking Model
Hacker News · AI· 60
DeepSeek V4.1 Flash achieves 11/11 code executions on Enclave's AI hacking benchmark for $4.65 across Grafana, Jenkins, and Nextcloud targets.