The HuggingFace incident still doesn't make sense. If OpenAI took their own claims seriously about the strength of their models as it relates to hacking, then their running of hacking benchmarks on anything other than a physically air-gapped network should be considered criminal negligence, full stop.
I take you haven't read it. I'm baffled how people can form strong opinions while refusing at the same time to read firsthand reports (in this case, from investigators).