The argument probably is that they assisted a sanctioned entity by providing a contribution i.e. service to it. Quoting US Treasury "These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person."
However, the major factual question is whether they did violate any sanctions since the contributions generally were made before the sanctions were in effect - it's not that Github had to do it, but that they chose to be safe rather than sorry (in order to ensure that Github themselves don't violate the sanctions) and if they aren't absolutely sure they blocked people. [edit: apparently not everyone, some contributors are not blocked, so they apparently did some review before choosing whom to block]
The key issue is that any collateral damage is considered acceptable, but any false negatives are absolutely not. If Github leaves even one actual agent of TornadoCash unblocked, Github has committed a crime, if they block a hundred unrelated accounts, that doesn't violate anything.
> Are there open source licenses that protect the contributors from such unforeseeable damage?
No, a contract or license can't absolve you from this prohibition if it applies to you.
> Or are we to watch our step from now on as open source contributors?
Yes, but not "from now on" but since before open source existed. There are entities you are not allowed to contribute to, and it's your responsibility to know and check who you are dealing with.