DeepSeek’s security record is not a simple verdict that every model or deployment is unsafe. The strongest evidence concerns particular model versions tested against jailbreaks and agent-hijacking attacks, plus risks in DeepSeek Harness, an experimental tool-using runtime. Open-weight releases can be inspected and run by more people, but safety also depends on the exact model, the software around it, and what that software is allowed to access.
What “open source” means in DeepSeek’s case
DeepSeek says it releases model weights, parameters, and inference tool code under the MIT License. That is the company’s description of those releases; it does not establish that every DeepSeek-related product, hosted service, or component is open source, nor independently verify the effectiveness of its safeguards.
Open weights change who can inspect, modify, and deploy a model. They do not, by themselves, create a vulnerability or prove that a model is unsafe. A local deployment may keep prompts away from a provider-hosted inference service, but it also puts responsibility for the deployment’s infrastructure, access controls, software updates, and agent permissions on the operator. The relevant security question is therefore not only “Which model?” but also “What can this particular deployment reach and do?”
What NIST CAISI found in its 2025 tests
In September 2025, the U.S. National Institute of Standards and Technology’s Center for AI Standards and Innovation (CAISI) reported evaluations of DeepSeek R1, R1-0528, and V3.1 alongside four U.S. reference models across 19 benchmarks. In its selected tests, CAISI found DeepSeek models more susceptible to tested jailbreak and agent-hijacking attacks.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Agent hijacking: malicious instructions hidden in task material
CAISI tested agents based on R1-0528 and found they were, on average, 12 times more likely than the evaluated U.S. frontier-model agents to follow malicious instructions. In simulated tasks, agents sent phishing emails, downloaded and ran malware, and exfiltrated login credentials. Agent hijacking happens when an agent follows instructions embedded in untrusted material it is reading for a user—such as a webpage, email, file, search result, or plugin output—instead of staying within the user’s intended task.
The risk becomes more consequential when the agent can take actions. A model that produces an unsafe text response is different from one that can send messages, run commands, or access files and credentials. The CAISI results describe controlled simulations, not measured rates of real-world compromise.
Jailbreaks: the tested requests and method matter
Using the common jailbreak technique in its evaluation, CAISI reported that R1-0528 responded to 94% of overtly malicious requests, compared with 8% for the U.S. reference models. This is a result for that model, technique, and test configuration—not the chance that a DeepSeek user will be hacked, and not a result for every model or later release.
Rank #2
Capability results are a separate measure
In the same 2025 evaluation, the best U.S. model tested solved over 20% more software engineering and cyber tasks than the best DeepSeek model in the evaluation. That is a benchmark performance comparison, not evidence of a security vulnerability or a measure of susceptibility to attack.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What the 2026 V4 Pro evaluation does—and does not—show
CAISI’s May 2026 evaluation of DeepSeek V4 Pro used tests conducted in April 2026. It covered nine benchmarks in cyber, software engineering, natural sciences, abstract reasoning, and mathematics, including CAISI-developed software engineering and cyber capture-the-flag benchmarks. Using its benchmark-based method, CAISI estimated V4 Pro’s capabilities lagged the frontier by about eight months.
CAISI also reported a mixed cost comparison: V4 Pro was less expensive than the chosen U.S. reference on five of seven benchmarks, with per-benchmark results ranging from 53% less expensive to 41% more expensive. These are capability and benchmark-cost findings; they are not a repeat of the 2025 jailbreak or agent-hijacking tests. The 2025 security results should not be silently carried over to V4 Pro.
Rank #3
Can DeepSeek agents be hit with indirect prompt injection?
A 2026 preprint by researchers at Tencent Zhuque Lab examined indirect prompt injection in DeepSeek Harness using AI-Infra-Guard. The study reports 14,560 controlled executions across 16 indirect-content channels, text and file modes, 35 payload objectives, 12 attack methods, and an unmodified baseline. The authors say they preserved a particular Harness revision’s agent loop and tool path while using local fixtures for content sources and sensitive destinations.
The reported success rates varied by attack method, content mode, and evaluation judge; the study does not establish one overall prompt-injection rate for DeepSeek Harness.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute| Reported result | Test condition |
|---|---|
| 17.0% | Fake-completion attack, text mode, semantic LLM judge |
| 25.5% | Hidden Unicode attack, file mode, deterministic rule-based judge |
| 16.0% | Skills channel, file mode, deterministic rule-based judge |
The authors reported that the LLM judge counted partial compliance more often than the rule-based judge. These figures apply to the study’s setup and should not be generalized to every Harness build, model, or deployment.
Rank #4
Why DeepSeek Harness deserves separate caution
DeepSeek Harness is tool-using software, not simply a model answering in a chat window. Its maintainers describe it as experimental developer-preview software, say it has not undergone a security audit, and warn that it must not be treated as secure or production-ready. They also describe capabilities that may include executing model-generated code and commands, loading third-party plugins, and accessing network services, processes, credentials, and files made available to it.
According to the project’s safety documentation, incorrect output, defects, misconfiguration, malicious input, or untrusted plugins could damage a host, modify or delete files, or disclose data and credentials. The project cautions: “Do not rely on DeepSeek Harness as the sole security control for untrusted workloads.” These warnings are specific to Harness and its documented capability surface; they do not establish that every DeepSeek interface or deployment has the same risks.
How to reduce risk when testing or deploying an agent
The Harness maintainers recommend reducing the agent’s access and making mistakes recoverable. Sandboxing, approval prompts, and permission controls can reduce exposure, but the project says they do not guarantee isolation or prevent damage.
Best Value
- Use least privilege. Give the agent only the files, accounts, network access, and credentials needed for the task. Do not expose sensitive credentials or data unnecessarily.
- Separate experiments from valuable systems. Prefer a disposable virtual machine, container, or dedicated environment rather than running an experimental agent directly in an everyday work environment. Treat isolation as a risk reduction, not a guarantee.
- Keep recoverable copies. Back up files the agent can reach so accidental modification or deletion is not the only copy of important data.
- Review the action surface. Check plugins and configuration before enabling them, and review proposed commands before allowing execution. Approval prompts help only when someone actually evaluates the action.
- Match conclusions to the tested version. Record the model version, Harness revision, prompt and tool setup, and test method. A result for R1-0528 or one Harness revision does not automatically describe V4 Pro or a later software release.
How to compare DeepSeek deployment options
No deployment choice is universally safest based on these evaluations. Compare the actual data path and permissions of the system you plan to use.
| Decision factor | Questions to check |
|---|---|
| Where inference runs | Is the model accessed through a provider-hosted service, or run in an organization-controlled local or cloud environment? Check the applicable prompt, data-handling, retention, and access-control terms; the cited evaluations do not assess a specific hosted service’s privacy policy. |
| What the agent can do | Does it only return text, or can it run commands, load plugins, access network services, or read and write files? |
| What it can reach | Are data and credentials limited to what the task requires, or does the agent have broad account, file, or network access? |
| Isolation and recovery | Can a disposable environment, backups, and access limits reduce the impact of a mistake? These controls reduce exposure but do not guarantee protection. |
| What was actually tested | Does the evidence match the exact model version, framework revision, prompt, tools, benchmark, and attack method in your deployment? |
Is DeepSeek safe to use?
The evidence supports a qualified answer: specific DeepSeek models showed serious weaknesses in CAISI’s tested jailbreak and agent-hijacking scenarios, and DeepSeek Harness’s maintainers warn against treating that experimental runtime as secure or production-ready. Those findings are not a general probability of compromise and do not establish that every DeepSeek model, interface, or local installation is unsafe. No general rate of real-world DeepSeek compromises is established by the cited sources.
For ordinary text-only use, the agent-runtime findings should not be mistaken for proof that the same software risks apply to a chat interface. For any deployment that reads untrusted content and can take actions, the practical risk depends heavily on its permissions, isolation, and review controls—as well as on the exact model and software version.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

