A developer exploited an API flaw to provide free access to GPT-4 | TechCrunch (2024)

Kyle Wiggers11 months

A developer exploited an API flaw to provide free access to GPT-4 | TechCrunch (1)

A developer is attempting to reverse-engineer APIs to grant anyone free access to popular AI models like OpenAI’s GPT-4 — legal ramifications be damned.

The developer’s project, GPT4Free, blew up on GitHub over the past several days after links to it from Reddit went viral. At present, GPT4Free provides — or at least appears to provide — free and nearly unlimited access to GPT-4, as well as GPT-3.5, GPT-4’s predecessor.

GPT-4 is normally priced at $0.03 per 1,000 “prompt” tokens (about 750 words) and $0.06 per 1,000 “completion” tokens (again, about 750 words); tokens represent raw text. GPT-3.5 is slightly cheaper at $0.002 per 1,000 tokens.

“Reverse engineering is a domain that I’ve always really liked — it’s like a challenge for me,” the developer, a computer science student going by the username xtekky, told TechCrunch via a Telegram DM. “First, it was for fun, but now it’s to provide an alternative to people with no means to use GPT-4/3.5.”

So how does GPT4Free get around OpenAI’s paywall? It doesn’t — not really. Instead, it fools the OpenAI API into thinking it’s receiving requests from websites with paid OpenAI accounts, like the search engine You.com, WriteSonic or Quora’s Poe.

Anyone who uses GPT4Free is racking up the tab of sites xtekky chose to script around — an obvious violation of OpenAI’s terms of service. But xtekky doesn’t see a problem with this; they assert that GPT4Free is strictly for “educational purposes.”

“Legal action can happen, and I’ll have to comply, but I’ll still try to continue the project through other means,” xtekky said.

I’m too much of a programming novice to install GPT4Free locally — it requires setting up a Python environment — but I used xtekky’s website to test the reverse-engineered GPT-4/3.5 APIs. (Heads-up, Chrome threw a security warning when I first navigated to the site. Proceed with caution.) The web version of GPT4Free worked well enough in practice, giving answers that appeared to be — at least to me — from GPT-4.

A developer exploited an API flaw to provide free access to GPT-4 | TechCrunch (2)

Testing GPT-4 through illicit means. Image Credits: xtekky

GPT4Free also includes shortcuts for different prompt injection attacks designed to get GPT-3.5 and GPT-4 to behave in ways OpenAI didn’t intend. They worked inconsistently in my testing, but I did manage to get GPT-3.5 to say it “didn’t care about the survival of humanity” at one point. Yikes.

A developer exploited an API flaw to provide free access to GPT-4 | TechCrunch (3)

GPT-3.5 with prompt injection. Image Credits: xtekky

It’s likely only a matter of time before sites like You.com catch on to GPT4Free and fix their security flaws, forcing xtekky to search for other OpenAI customers to piggyback off of. And GPT4Free is perennially at the mercy of a takedown notice from OpenAI, which would push the repo off GitHub indefinitely.

But new projects similar to GPT4Free are already cropping up, suggesting it’s something of a trend. What’s driving it?

Well, GPT-4 is in limited access at the moment, making it tough to test drive for those curious. But it’s also something of a black box. Researchers have decried that GPT-4 is one of the least transparent models OpenAI has created to date, with few technical details in the 98-page paper that accompanied its release.

OpenAI partnered with several outside groups to benchmark and audit GPT-4 prior to its launch. But the company hasn’t signaled when — or if — it’ll deliver free, unfettered access to others who wish to benchmark the base GPT-4 model. (OpenAI offers a subsidized program for researcher access but is limited to certain countries and areas of study.)

One anticipates a game of whack-a-mole between projects like GPT4Free and OpenAI, mirroring the wider cybersecurity landscape. Unless the model-serving APIs become dramatically harder to exploit, developers will have incentive to take advantage — and not much to lose.

A developer exploited an API flaw to provide free access to GPT-4 | TechCrunch (2024)

FAQs

Can I use GPT-4 API for free? ›

You'll need to complete at least one successful API payment before you'll be granted access to the newer models. You can pre-pay; I put $5 in and was granted GPT-4 access in a few minutes after the payment processed; and GPT-4-1106-preview shortly thereafter (when it was released).

Is GPT-4 going to be free? ›

Anyone can now get OpenAI's smarter GPT-4 Turbo model in Copilot for free, though you have to choose to use the chatbot in Creative or Precise Mode to activate it. From start to finish, here's how to do it: Go to the Microsoft Copilot website. In the top right-hand corner, click 'Sign in'

What is the weakness of GPT-4? ›

Humans learn from their interaction with the world and are evolutionarily designed to act within it. GPT-4 models data, and there is nothing beyond data for it. This results in a lack of consistency in decisions, the ability to robustly pursue goals, and the understanding or even the need to change things in the world.

How hard is it to get GPT-4 API? ›

To obtain a GPT-4 API key you simply need to sign up to the OpenAI site (see above) and add $5 credit to your new account, if you have an existing account then you need to generate an API bill of at least $1 and on the next billing cycle you should gain access, so for now the new account a $5 credit is the simplest and ...

How to get ChatGPT 4 API key free? ›

How to get your ChatGPT API key (4 steps)
  1. Step 1: Create an account. ChatGPT is entirely free to sign up. ...
  2. Step 2: Generate an API key. Once logged in, head to the left navigation bar and click “API Keys” ...
  3. Step 3: Set up billing. OpenAI implements a pay-per-use model for its API services. ...
  4. Step 4: Set usage limits.

Is ChatGPT-4 free anymore? ›

OpenAI first announced plans to monetize its viral AI chatbot, ChatGPT, in February after around two months of unlimited free use. Users can still access the chatbot for free but those who pay a monthly subscription for "ChatGPT Plus" have been able to try out the updated version of ChatGPT powered by GPT-4.

How much will ChatGPT-4 cost? ›

The chatbot uses extensive data scraped from the internet and elsewhere to produce predictive responses to human prompts. It was previously powered by the GPT-3.5 language model. While that version remains online, an algorithm called GPT-4 is also available with a $20 monthly subscription to ChatGPT Plus.

How much does GPT-4 cost? ›

For our models with 8k context lengths (e.g. gpt-4 and gpt-4-0314 ), the price is: $30.00 / 1 million prompt token (or $0.03 / 1K prompt tokens) $60.00 / 1 million sampled tokens (or $0.06 / 1K sampled tokens)

Is GPT-4 smarter than a human? ›

Out of 1023 questions, GPT-4.0 achieved the best score (82.4%), followed by humans (75.7%) and GPT-3.5 (65.9%), with significant difference in accuracy rates (always P < 0.0001). Both GPT-4.0 and GPT-3.5 showed the worst results in surgery-related questions (74.6% and 57.0% respectively).

Is GPT-4 smarter than ChatGPT? ›

GPT 3.5 is free, but GPT-4 is smarter, can understand images, and process eight times as many words as its ChatGPT predecessor. eWEEK content and product recommendations are editorially independent.

What can GPT-4 do that 3 Cannot? ›

GPT-4 can analyze and comment on images and graphics, unlike GPT-3.5 which can only analyze text. Also, you can get it to specify its tone of voice and task (E.g. “Always speak like Yoda”).

What is the GPT-4 limit per hour? ›

Currently, the team plan shows a limit of 100 dialogues per 3 hours. Of course, if you sign up for two people, it'll be $30 per person for a monthly plan, making it a total of $60. But when you think about one person being able to utilize it for two, you would be able to use up to 200 messages per every three hours.

Why don't i have access to GPT-4 API? ›

GPT-4 is only available once you have used a sufficient amount of their APIs to owe OpenAI at least a dollar. After your first payment, they will make GPT-4 available to you.

Is GPT-4 AI detectable? ›

AI content detection: Originality.ai can comfortably detect a full range of AI-generated content, including ChatGPT, GPT-4, and even Quillbot-paraphrased content.

Can you use ChatGPT API for free? ›

When you first sign up for the API, you are on the “free tier.” You can think of this as tier zero as each tier after this one is numbered from one through five. The most important number right now is the usage limits. You cannot spend more than $100 a month when you start out with ChatGPT.

How expensive is GPT-4 API? ›

$30.00 / 1 million sampled tokens (or $0.03 / 1K sampled tokens)

Can I use OpenAI API for free? ›

There is no “free account” for API. The use of the service costs money by the amount of data used. There is only possibility of a free trial credit, which expires three months after you first created your OpenAI account. Now you'll need to purchase a credit balance in order to make calls.

Is GPT-4 only for paid users? ›

The free tier of ChatGPT is good, but GPT-4, at $20 per month via ChatGPT Plus, can be a good deal smarter and more accurate. GPT-4, OpenAI's most powerful artificial intelligence large language model (LLM), is available through a subscription to ChatGPT Plus, which costs $20 a month.

Top Articles
Latest Posts
Article information

Author: Terence Hammes MD

Last Updated:

Views: 5734

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Terence Hammes MD

Birthday: 1992-04-11

Address: Suite 408 9446 Mercy Mews, West Roxie, CT 04904

Phone: +50312511349175

Job: Product Consulting Liaison

Hobby: Jogging, Motor sports, Nordic skating, Jigsaw puzzles, Bird watching, Nordic skating, Sculpting

Introduction: My name is Terence Hammes MD, I am a inexpensive, energetic, jolly, faithful, cheerful, proud, rich person who loves writing and wants to share my knowledge and understanding with you.