https://support.google.com/youtube/answer/7001996?hl=en-GB
edit: My hunch is that the channels the OP's attack was able to target are not actual channels but rather YouTube users (who have a "channel" because that's how YouTube represents users): so "YouTube User" is the correct description of this attack, which is distinct from what you're thinking of as a channel.
Talk about puny!
> If they poked around a bit more they may have found a better GAIA->Email vulnerability
They still can! Report more bugs, get more bounties. I don't see how this is related to how much they paid for this one.
> A database of emails for every major youtube channel would be worth an awful lot.
It's pretty clear from the article that you can't use this API to scrape at that kind of volume. This kind of thing was never in the offering. As the title says, you can leak "any" email, not "every" email.
Or just plain ole pwning them. Most users still tend to use the same password across different services, not use 2FA, and involved in at least 1 high profile leak (I know I’m in at least a dozen so far per haveibeenpwned).
Occasionally you get the victim that uses that same password for their e-mail service and that can allow you to bypass e-mail 2FA if enabled. Even better if the account is used for social SSO (ie, Google, Facebook, Twitter). Then you have access to a treasure trove of services; or just delete them for lulz