Here's an example of something that got paid out by paypal - https://hackerone.com/reports/739737 (15K)
Good writeup - https://medium.com/@alex.birsan/the-bug-that-exposed-your-pa...
Interesting history with paypal - https://hackerone.com/alexbirsan
Here's how duplicate reports are dealt with - https://docs.hackerone.com/programs/duplicate-reports.html
I am curious if paypal provided the OP with original reports. They don't say. I wonder how much the OP is not saying here, versus how much they understand the platform they are working on.
This statement makes me very curious: "Other criticisms have pointed out that Security Analysts can first delay the reported vulnerability, report it themselves on a different bug bounty platform, collect the bounty (without disclosing it of course), and then closing the reported issue as Not Applicable, or perhaps Duplicate."
How can you do that if you're providing the original report?
Also, the guy is just wrong. You GAIN rep points for duplicates, unless you did something dumb and really amateur like not searching first for already publicly disclosed issues.
https://docs.hackerone.com/hackers/reputation.html#effects-o...