Ah yes, I'd forgotten about that - https://medium.com/@fs0c131y/tchap-the-super-not-secure-app-...
I can think of many comparable situations in other countries (some EU ones as well) in which the person finding the issue would of very easily been locked up.
The actual bug was thanks to a long-standing bug in python's standard email.utils library, which finally got fixed: https://bugs.python.org/issue34155, combined with insufficiently-defensive coding and testing on my side. (I wrote the auth code in question).
It does not really say that the app is "super not secure". Just that people make mistakes, and it's not even shameful the way they reacted to it.