Chats, screenshots, and interviews: some people are pirating GPT-4 and offering free access after stealing OpenAI API tokens scraped from other people's code
Joseph Cox / VICE : Tweets: @fabianstelzer , @simonw , @alex , @josephfcox , @iethics , @josephfcox , and @josephfcox Tweets: Fabian Stelzer / @fabianstelzer : “pirating API tokens” - apt scene https://twitter.com/... [image] Simon Willison / @simonw : A reminder that your OpenAI API keys are effectively tokens that allow anyone to rack up API usage charges against your credit card https://twitter.com/... @alex : the def of product market fit is when people are ripping the product out of your hands, etc https://www.techmeme.com/... Joseph Cox / @josephfcox : One person has scraped exposed OpenAI keys from Replit. Here, people can collaborate on code together, but projects are public by default. Because we alerted them, Replit will now scan for exposed OpenAI keys https://www.vice.com/... [image] @iethics : “The method by which the pirate gained access highlights a #security consideration that paying users of #OpenAI need to consider. The person says they scraped a website that allows people to collaborate on coding projects”: https://www.vice.com/... #ethics #internet #tech #AI Joseph Cox / @josephfcox : Here is a screenshot of the website that was using a stolen OpenAI API key to then offer free GPT-4 access to those who signed up https://www.vice.com/... [image] Joseph Cox / @josephfcox : New: people are pirating access to GPT-4 by scraping code online. In one case, someone gained access to an account with $150,000 usage limit, now offering access for free via a website and Discord server. Why pay for GPT-4 when you can just steal it? https://www.vice.com/...
Context & Ripple Effects
This is the third front in an escalating fight over who pays for frontier-model access. In April, OpenAI demanded the GPT4Free GitHub project shut down or face a lawsuit; earlier, an unaffiliated ChatGPT iOS app sold subscriptions atop OpenAI's models without permission. Today's twist is that the gray market no longer needs a workaround at all — people scraped live OpenAI API keys from public code and are reselling the capacity for free.
First-order effects
- The key owners whose credentials were lifted bear the immediate cost: one compromised account carried a $150,000 usage limit, and as Simon Willison notes, anyone holding your key can rack up API charges against your card.
- Replit has begun scanning public projects for exposed OpenAI API keys after being alerted that keys were harvested from code hosted there.
Second-order effects
- OpenAI faces pressure to make usage limits, anomaly detection, and key rotation defaults rather than opt-ins, since permissive $150k ceilings turn leaked keys into free inventory for pirates.
- Secret scanning for AI provider keys is set to become table stakes across developer platforms the way credential scanning became standard for cloud providers — every host of public code is now a leak surface for OpenAI billing.
Third-order effects
- If free-access projects keep getting legally squeezed — the GPT4Free takedown demand, now this token-piracy economy — enforcement shifts from policing apps to policing the API key itself as the security boundary around model access.
- A durable two-tier market is taking shape alongside OpenAI's official pricing: a jailbreak community and pirate distributors treating paid model access as something to be liberated, which will shape how aggressively providers lock down and meter their APIs.
The trend: Frontier-model access is hardening into a contested resource where API keys, not apps, are the enforcement point between OpenAI's paid tier and a growing gray market for free use.