I don't think this is any different from prior prompt injection attacks. I am confused about it though, based on the API it looked like <|end_of_text|> was fed into the model as its own special token, and not simply as the ascii sequence used to encode it.
Sounds like that isn't happening though, if the GP is correct.
It's a poison attack that randomizes the output, but it does not allow the attack to manipulate the outputs.