CFAA[0] is one that comes to mind but I also think that has different issues with what might be overly vague terminology. It at least seems more applicable to this, though I am certainly not a legal expert.
There was a somewhat recent supreme court ruling that said just breaking some ToS is not a CFAA violation. Unless the gpt4free repo had straight up stolen credentials the CFAA shouldn't apply.
[0] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act