TFA isn't about LLMs intelligently escaping their inference engine, it's about people crafting malicious LLMs that exploit vulnerabilities in things like the inference engines parser. This is exactly the same problem that was once a big deal, where people would craft malicious PDFs that would pwn you if you viewed it in Adobe Acrobat. This shouldn't be a surprise to anyone. You should proceed with caution when considering downloading and running random models.