OK, that's some interesting information but they used OpenAI without guard rails to pull off the attack so how did they do that? That's according to the article, so it kind of invalidates the point you're making.
The attacker (OpenAI) was using the model without guardrails.
The defender (huggingface) did not have access to the top models so had to use weaker ones to detect the threat.
Jailbroken, all LLM models can be broken. ALL.
The "malicious" agent was run by OpenAI and had access to models the public (or others outside of OpenAI as I understand it) doesn't have access to.