I don't understand this sentiment at all.

Is it a claim that "breaking into Hugging Face's production infrastructure" didn't happen? That it's not actually all that severe? That it was done by hand by OpenAI employees and they fooled Hugging Face?

That the blog post exaggerates something, somehow?

What exactly do you mean?

At the moment it just reads like a thoughtless dismissal.

My thought is they might have set up the environment sloppily because they knew this could have led to something like this happening.