Do not overestimate what it "did" here. You can get information about basic hacking approaches all over the Internet and there will have been enough in its training data. Just add some "accidental" disabling of guardrails and some "non intended" weaknesses in the sandbox and also some suggestive prompting by some of the OpenAI fraudsters and you get the desired outcome. Oh, and pathetic-level IT Security at Hugging Face, but that is a given.
Just as an example, I have had a fresh graduate do a pen-test against a banking datacenter a while ago. Smart person, but inexperienced. After 4 hours, he was "system" on a Microsoft server in their secure server zone. No special tools, no AI, just common sense and a good CS education. A lot of IT security is incredibly bad. As long as we do not get liability and qualification requirements and minimal required standards, that is not going to change.