Let's be real here.
Even assuming this is not a completely contrived publicity stunt, think it through:
If somebody locked you in a sandbox with a proxy that you had limited knowledge of and you had to break out of using only the tools on your machine and the ability to probe the sandbox, could you get out? Maybe, but unless the person who set up the sandbox was an idiot you’d have a pretty difficult time of it. And how many proxies have zero-days that can be found with probing and no access to the source code or configuration, on any reasonably timescale? This is some magical thinking here, and I don't believe in magic.
So let's think about how these AI companies work. It's not like OpenAI had some carefully-crafted sandbox for its model to play in. They almost certainly slop-coded a slopbox with their own AI, and then their own AI found a slopvuln in their slopbox slopcode and slopped its way out. Teeeeeeeechnically this would be a zero-day. Teeeeeeeeeechnically they might not be lying through their teeth, just being extremely misleading which is evil but not necessarily illegal.
Then go over to HuggingFace. It's a great, useful platform from and end-user perspective but, again, let's be real here. How much of their code do you think is carefully-crafted vs. how much is slopcoded?
An AI model slopping its way out of slop into some other slop through a whole bunch of slop is not that impressive.
It's said in both cryptography and security in general that anybody can build a system that they can't break. AI isn't even living up to this level.