- The severity of the exploit, which may be nearly the maximum theoretical possibility on a site like Facebook, aside from SQL injection or remote code execution
- The multiple months worth of unpaid sleepless nights Stephen Sclafani likely spent exploring countless dead-ends before finding this
- The fact that he beat black hats to the punch by discovering it first and thus saved Facebook and its users from millions, perhaps billions, of dollars worth of damages stemming from vague and mysterious causes over an indefinite period of time
- The billions of dollars Facebook regularly uninhibitedly spends to acquire a given startup
I feel that $20,000 is a bit low.