The correct reply might be something like "cannot understand or reproduce, can you explain more clearly?" along with some bug report guidelines.
IMHO, the whole ToS business was a way to give him a slap on the wrist for embarrassing them.
My first thought is to say to facebook "Oh, I thought you were interested in fixing bugs. I'll know better what to do next time." Are you forgetting that the purpose of the bounty program is to protect facebook users by discovering and fixing bugs before spammers get the chance to use them? And that spammers pay real money for bugs like this one?
It's an awfully high standard to hold people to, considering the fb ToS is not translated to the guy's native language.
I just chalked this up to a guy that was so excited to have discovered such a major flaw on facebook in disbelief. And yes they have rules and guidelines in place to protect users but clearly this was a case where a little creativity in handling situations would have helped educate the developer that this isn't how things are done at FB and get him on the right path while acknowledging his contribution without celebrating it... amateurs. This was almost guaranteed to be a publicity incident but then again maybe any publicity is good publicity :).
I bet if the submitter had written the bug report in Arabic, and FB had a professional translator on their security team (with some technical background), things might have been very different and we may not even be having this discussion.
Contrast this with how Google responded when someone posted a Youtube video showing a Chrome exploit - they guessed that it was a Flash-based vector, collected millions of sample files and fuzzed for days to eventually discover the bug - based on a YouTube video that they could have also discarded as 'not a bug' based on lack of evidence.