Likely cheaper just to force everyone to change their password on login.
That would be pointless since the malware could just grab the new credentials.
OpenAI is run like a YC company. That means they do everything not to distract the user from the core workflow. I think privacy and security are just very low priority to them.
wouldn't that reward the seller, and still be potentially costly for OpenAI?
Any security researcher wanting to analyze the data (or Troy Hunt wanting to add it to haveibeenpwnd.com) will imply someone rewarding the seller, that's inevitable.
The sooner, the less the seller can make on this data.