A project called GPT4Free drew attention after links shared on Reddit helped it spread on GitHub. It appeared to offer users free, nearly unlimited access to GPT-4 and GPT-3.5. But the approach described by its developer did not remove the cost of using the models; it shifted that cost to other services.
How the project routed requests
The developer, a computer science student using the username xtekky, told TechCrunch that reverse engineering began as a personal challenge and later became an effort to offer an alternative to people unable to use the models. GPT4Free worked by making requests appear to come from websites with paid OpenAI accounts, including You.com, WriteSonic and Quora’s Poe.
That distinction matters. Users might not see a charge, but the services whose accounts were scripted around could incur the usage costs. The article described this as an obvious violation of OpenAI’s terms of service. Xtekky characterized the project as being for “educational purposes” and said legal action could require compliance, while adding that they would try to continue through other means.
At the time of the article, GPT-4’s listed prices were $0.03 per 1,000 prompt tokens and $0.06 per 1,000 completion tokens. GPT-3.5 was priced at $0.002 per 1,000 tokens. Tokens are units of raw text; the article estimated that 1,000 tokens correspond to about 750 words.
What users could access
The article’s author tested the project’s website and said it returned answers that appeared to come from GPT-4. The piece also noted that installing the project locally required setting up a Python environment, and that Chrome displayed a security warning when the author first visited the site.
GPT4Free included shortcuts for prompt injection attacks, which try to get a model to respond in ways its provider did not intend. The author reported inconsistent results when trying these shortcuts. One attempt got GPT-3.5 to say it “didn’t care about the survival of humanity.” That example illustrates both the unpredictable results and the way the project exposed users to behavior that its developers did not control.
A fragile route to free access
The method depended on continued access to the third-party services being used as intermediaries. The article expected that services such as You.com might identify and repair the security flaws, which would force GPT4Free to look for other paid OpenAI customers to use as a route. That makes the apparent access vulnerable to changes outside the project’s control.
The project also faced the possibility of a takedown notice from OpenAI that could remove its repository from GitHub indefinitely. In practical terms, neither the service’s availability nor its method was assured. Its users could lose access if a provider closed the route or the repository disappeared.
Why projects like it appeared
The article connected the project’s appeal to limited access to GPT-4 and the difficulty of trying the model out. It also raised a research concern: GPT-4 was described as a black box, with researchers criticizing the lack of technical detail in the 98-page paper that accompanied its release.
OpenAI had partnered with outside groups to benchmark and audit GPT-4 before launch, but the article said the company had not indicated when, or whether, others would get free, unrestricted access to benchmark the base model. A subsidized researcher program existed, though it was limited to certain countries and areas of study.
That gap between interest in examining a model and limited access helps explain why projects offering unofficial routes attracted attention. It does not make the underlying access authorized or stable. The article anticipated an ongoing contest between projects such as GPT4Free and OpenAI: as long as model-serving APIs could be exploited, similar efforts could continue to emerge.