If you read any of the details of the breaches its clear that OpenAI is being criminally negligent in their testing environments, but the breaches are real. And critically its not one super-agent doing the hacks but dozens or hundreds of agents acting as a swarm. Basically, OpenAI runs multiple test runs in parallel and has basically no human monitoring of what the agents are doing.
In the case of the huggingface hack, the agents establish communication with each other and started coordinating their attacks. This should've ended the test immediately but no one from OpenAI was watching. The logs from the test were so verbose that OpenAI resorted to using AI to summarize them meaning we can't fully trust their summary which fancifully describes the agents developing their own cult.
Ruby just reported that they were hacked back in May and OpenAI never disclosed it. That hack looks a lot like the AUR hack so now I'm suspecting them for that too.