I definitely think OpenAI (and Anthropic, and Google, and Meta) could have, and should have, done better.
But also I remember (and it wasn't even that long ago) people mocking the idea of AI ever getting competent enough to find zero-days in their sandboxes.
I'd go further: if any of these companies tries to make an excuse "oh, but ${safety measure} against ${capability} is too hard", the response needs to be "then you are forbidden from even developing ${capability}, and must be inspected continuously to ensure you never even accidentally produce ${capability}".
Precisely. But here they are using their incompetence in one domain as advertising for another.