a) The level of persistence you seem surprised by is nothing compared to what you will see in a real world environment. Those attackers who really want to get credentials etc from LLMs will try anything. And often are well funded (think state sponsored) so will keep trying until you break first e.g. your product becoming too expensive for a company to justify having the LLM in the first place.
b) 1 success out of 2000 saves is extremely poor. Unacceptable for almost all of the companies who would be your target customer. That is: one media outrage, one time that a company needs to email customers to inform that their data is safe, one time that will need to explain to regulators what is going on, one time the reputational damage makes your product untenable.