I wouldn't bash the guy. Someone already let him know about his technical faux pas in a professional manner on his twitter.
My guess is he found this vulnerability on accident, freaked out, and tweeted about it. Probably has limited infosec experience.