If this is "exploiting bugs" then by the same logic I'm hacking the government website by clicking view source.
Creating a gaudy branded library that's providing actual client implementations, then building an entire site that's built on those, is just bad taste
If you actually look at the implementation, some of the sites did everything right in terms of CSRF tokens and not exposing their OpenAI key directly. So the next step for the sites they're attacking with this is a whole mess of JS based detection, behavior detection, ie all the mess that we'd rather the internet didn't have.
If this person had just shared it anonymously and left it instead of drumming it up for personal glory, some motivated hackers would have used it. Now it's flooding websites at rates that break their ability to pay their bills.
If OpenAI intended to authenticate the API they probably should do it
OpenAI authenticates their API, and was getting paid for every query. OpenAI loses absolutely nothing from what these people were doing.
Who was losing was random customers who have APIs and products that call up OpenAI. In some cases those customers even secured their API keys, but by the very nature of their product, you put in some input, and get some output from OpenAI.
It's like if someone made a directory of apps that use Google's search API to show you results, so instead of paying for Google API access, you started slamming all of those apps with your queries. It's not cool to those apps, but Google shutting it down would be for the apps' benefit: they get paid either way.
The site has a rate limit, doesn't expose their API key, and it has a CSRF token. In terms of non-intrusive measures they could have taken, they did it all right.
So what's left on the table is intrusive stuff: HN has a lot of people constantly whining about how they're stuck in captcha hell because their hand built Lenovo running Firefox on BSD compiled on an abacus isn't recognized as a real client... but aggressive captchas are going to become even more pervasive if every GPT based product must fight off proxy attempts.