It's tough to know for sure if it would've made more, though. Given the limited time window, I think I slightly lean towards exploiting greed vs. exploiting altruism. If they could somehow keep he tweets up for over 24 hours, I think your idea would likely win, but given they may have thought they might have about an hour, I think the scam route might've been more reliable.
But the general sloppiness of the stratagem points towards not having the time / resources to do that.
As for which one would win, I don't know. I can see the argument of immediacy with the scam. The charity scam I think would draw in a lot more smaller donors but I can't see them feeling the need to immediately send.
Personally I would have gone with the bounty, then shamed Twitter for the (probably) low payout in an effort to promote my brand.
The problem is that the attack requires active social engineering to pull off, so it probably wouldn't have been eligible for a bounty. "I could trick your employees and gain access to user accounts" isn't really covered.
Even media could have fall.
Than they can come with Jeff Bezos yes I'm donating too. It would have more real.
The hackers knew their tweets would be pulled down in a few minutes or so, so they had to put out tweets saying "in the next 30 mins" for people to send money immediately.
This works well in what they tried, but asking people to donate in the next 30 mins would certainly have made it look suspicious.
It's human nature to play games like this. The whole idea of startup "IPO exit" is really just a ponzi play (if you think the company is good - why the heck would you sell it just as soon as the "dumb money" moves in?).