Criminal Cases of 'hacking' require specific intent. What you're asking is that the prosecution attempt to prove Open AI intended to infiltrate Huggingface maliciously, all while the victim is saying 'no harm no foul'.
No offense but prosecutors have better things to do with their time.
If intent matters when LLMs get involved, then we can't do anything even if they kill millions of people. Anything LLM-related should involve strict liability.
I don't care about intent. That it happened is unacceptable. Ignorance is not an excuse
Gross negligence can stand in for intent. I believe a rather compelling case could be developed on the basis that a system believed to be capable of this was developed and improperly secured.