An unfixed security vulnerability is still an unfixed security vulnerability, no matter how many people discover it in the interim. By refusing to coordinate with the new submitter, the new submitter does not know if the vulnerability will ever be fixed and is reasonably justified in using public disclosure.
The one case where refusing to coordinate with the new submitter is reasonable is when the new submitter learned about the vulnerability from the original submitter, which means that the original submitter has violated responsible disclosure. In that case, nobody would deserve a reward.
This is rare for bug bounty rewards. All the programs I am aware of only reward the first reporter.
> By refusing to coordinate with the new submitter, the new submitter does not know if the vulnerability will ever be fixed and is reasonably justified in using public disclosure.
That's kind of what I'm pointing out here. We are missing information about what Facebook actually said and when it was said. The "we already know about it" response could mean "we know about it and are working on fixing it" or it could mean "we know about it and we don't care". In the former case, it is not responsible to publicly disclose the issue until it is fixed. In the later, it is.
A separate scenario is if the company is taking a long time to fix the issue. This is obviously subjective, but in my opinion it is understandable for a reporter to publicly disclose a long-standing issue in an attempt to force the company to act.