/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Chats, screenshots, and interviews: some people are pirating GPT-4 and offering free access after stealing OpenAI API tokens scraped from other people's code

Joseph Cox / VICE : Tweets: @fabianstelzer , @simonw , @alex , @josephfcox , @iethics , @josephfcox , and @josephfcox Tweets: Fabian Stelzer / @fabianstelzer : “pirating API tokens” - apt scene https://twitter.com/... [image] Simon Willison / @simonw : A reminder that your OpenAI API keys are effectively tokens that allow anyone to rack up API usage charges against your credit card https://twitter.com/... @alex : the def of product market fit is when people are ripping the product out of your hands, etc https://www.techmeme.com/... Joseph Cox / @josephfcox : One person has scraped exposed OpenAI keys from Replit. Here, people can collaborate on code together, but projects are public by default. Because we alerted them, Replit will now scan for exposed OpenAI keys https://www.vice.com/... [image] @iethics : “The method by which the pirate gained access highlights a #security consideration that paying users of #OpenAI need to consider. The person says they scraped a website that allows people to collaborate on coding projects”: https://www.vice.com/... #ethics #internet #tech #AI Joseph Cox / @josephfcox : Here is a screenshot of the website that was using a stolen OpenAI API key to then offer free GPT-4 access to those who signed up https://www.vice.com/... [image] Joseph Cox / @josephfcox : New: people are pirating access to GPT-4 by scraping code online. In one case, someone gained access to an account with $150,000 usage limit, now offering access for free via a website and Discord server. Why pay for GPT-4 when you can just steal it? https://www.vice.com/...

VICE Joseph Cox

Context & Ripple Effects

This is the third front in an escalating fight over who pays for frontier-model access. In April, OpenAI demanded the GPT4Free GitHub project shut down or face a lawsuit; earlier, an unaffiliated ChatGPT iOS app sold subscriptions atop OpenAI's models without permission. Today's twist is that the gray market no longer needs a workaround at all — people scraped live OpenAI API keys from public code and are reselling the capacity for free.

First-order effects

  • The key owners whose credentials were lifted bear the immediate cost: one compromised account carried a $150,000 usage limit, and as Simon Willison notes, anyone holding your key can rack up API charges against your card.
  • Replit has begun scanning public projects for exposed OpenAI API keys after being alerted that keys were harvested from code hosted there.

Second-order effects

  • OpenAI faces pressure to make usage limits, anomaly detection, and key rotation defaults rather than opt-ins, since permissive $150k ceilings turn leaked keys into free inventory for pirates.
  • Secret scanning for AI provider keys is set to become table stakes across developer platforms the way credential scanning became standard for cloud providers — every host of public code is now a leak surface for OpenAI billing.

Third-order effects

  • If free-access projects keep getting legally squeezed — the GPT4Free takedown demand, now this token-piracy economy — enforcement shifts from policing apps to policing the API key itself as the security boundary around model access.
  • A durable two-tier market is taking shape alongside OpenAI's official pricing: a jailbreak community and pirate distributors treating paid model access as something to be liberated, which will shape how aggressively providers lock down and meter their APIs.

The trend: Frontier-model access is hardening into a contested resource where API keys, not apps, are the enforcement point between OpenAI's paid tier and a growing gray market for free use.

Discussion

  • @fabianstelzer Fabian Stelzer on x
    “pirating API tokens” - apt scene https://twitter.com/... [image]
  • @alex @alex on x
    the def of product market fit is when people are ripping the product out of your hands, etc https://www.techmeme.com/...
  • @simonw Simon Willison on x
    A reminder that your OpenAI API keys are effectively tokens that allow anyone to rack up API usage charges against your credit card https://twitter.com/...
  • @josephfcox Joseph Cox on x
    One person has scraped exposed OpenAI keys from Replit. Here, people can collaborate on code together, but projects are public by default. Because we alerted them, Replit will now scan for exposed OpenAI keys https://www.vice.com/... [image]
  • @iethics @iethics on x
    “The method by which the pirate gained access highlights a #security consideration that paying users of #OpenAI need to consider. The person says they scraped a website that allows people to collaborate on coding projects”: https://www.vice.com/... #ethics #internet #tech #AI
  • @josephfcox Joseph Cox on x
    Here is a screenshot of the website that was using a stolen OpenAI API key to then offer free GPT-4 access to those who signed up https://www.vice.com/... [image]
  • @josephfcox Joseph Cox on x
    New: people are pirating access to GPT-4 by scraping code online. In one case, someone gained access to an account with $150,000 usage limit, now offering access for free via a website and Discord server. Why pay for GPT-4 when you can just steal it? https://www.vice.com/...