Unfortunately, the worst-case scenario has come true. Security researchers have uncovered that OpenAI has established a complete cross-site tracking chain through an internal advertising platform called "bazaar." When a user opens ChatGPT, the client first generates a random identifier and takes a JWT token bound to the user's account, then writes a cross-site cookie named "__obi" in a cross-site environment. This cookie acts like an identity tag, and when the user later visits third-party websites that have implemented OpenAI ad pixels, their browsing actions on those websites will be directly linked back to their ChatGPT account.
More notably, this association does not require that you have ever entered any specific content in ChatGPT. Even if you have never mentioned related topics in the chat window, as long as you visit a site with the pixel, your web browsing behavior will be collected by OpenAI. In other words, the vast expanse of the web outside the chat interface has also been quietly incorporated into the profile. This discovery has already ranked third on HackerNews' popular list and has caused considerable discussion within the developer community.
