what you described is negligence. unless you can prove that openai specifically targeted huggingface and specifically instructed their model to hack huggingface, it would not be intent.
anyone pursuing this will have a much easier time pursuing negligence causing damage or something along those lines rather than confining themselves to the cfaa's requirements.
it is unclear to me why people want to use the cfaa so badly. not only would it be harder to hold openai responsible, but a shitty cfaa ruling could also bring along some undesired side effects for security researchers, which i would prefer to avoid.
Drunk individuals are not universally allowed to cry they were negligent due to impairment when charged (rarely) with first degree murder. There is a line between intent and negligence that puts acts over the line to intent if intentional acts led to a harmful incident.
I doubt it is difficult to prove intent on the part of various frontier labs to create a PR campaign to goad the government into defending their non-existent moat around their products. Squeeze one disgruntled employee or another.