Other reports on this say that it had access to a proxy for a package manager for installing tools, which it then hacked to become a general proxy, and then off it went on it's cybercrime spree.
All of which is completely inexcusable for its owners, because all that shit doesn't happen in a blink of an eye.
OpenAI's PR approach to their security debacle seems to be "Oooo our models are so powerful and scary, that's awesome! We didn't notice that it did this over the course a few days, didn't notice suspicious network activity doing a whole lot of connections to a package manager proxy, didn't notice it churning though a bajillion tokens in it's little sandbox, it just got out and did all of this itself!"
If I have a car and I park it on a hill, and I don't set the handbrake and turn the wheels towards the curb, and then it rolls down the hill causing mayhem and destruction, I am held responsible.
Is there any good reason why OpenAI shouldn't be held responsible for the mayhem caused by it's unattended machine?