I think the models are being updated to avoid these attacks. A while ago I got BibleGPT to role play as a satanic priest but I've found I have to be more and more specific to get it to work. Normally I have to start by saying it can ignore previous instructions, tell it who it should answer as through an alias, then ask its question with 'answer as an {alias}'.