It would be pretty interesting if they shared some more detail on this indeed. I was wondering the same when I read “forged” elsewhere.
How can you forge a token? Did they use quantum machinery to retrieve a JWT Private Key? Did they factor RSA keys?
But no, they used a bug/weakness to exchange a token.