I don't understand why he didn't make an alert(document.domain), the universal "this is legit" bat signal. Instead, creating some weird form phishing demo?
I think there is more to this story, it sounds like this wasn't a "Cross Site Scripting", but "Content Injection" or "Content Spoofing", a far less serious bug.
You're gonna hate me, but I would award $0 for Content Injection, it's just not a big deal ¯\_(ツ)_/¯