My main skepticism isn't even that, it comes from working in security. In general, if Im setting up publicly accessible service infrastructure, with security in mind there are 2 things Im absolutely going to implement in a firewall setup.
First is statistical traffic detection to check if we are being hit with too many failed requests from consistent endpoints, and heavily throttles that traffic based on fingerprinting.
Second is payload inspection to see if there is anything that looks like shell code in there, and automatically ban the ip.
Both of those are basically enough to prevent any number of agents (or team of 10 engineers) from essentially brute forcing a logic exploit.
So either HF team is incompetent, which given its prominence and buyout by Nvidia, I highly doubt it. Or something fishy is going on.