I am not sure why all this hate, as I said we fucked up the way the initial ticket has been handled and it's sorted now. :P FYI we plan to release the fix shortly and sebiw has already been rewarded via our official bug bounty program.
Sending a company proof that you've accessed a security hole (e.g. demonstrating it to them) can and has been prosecuted against has a hacking attempt and/or unauthorized access.
This is something every security researcher should know, and not necessarily pejorative against Nexmo in particular.
The parent was offering general advice for working with companies, and I was offering a general observation about that advice (namely, don't admit to technically-a-crime unless you know you're working with someone in good faith). Nothing personal, and it sounds like you guys have handled things professionally :-)
Edit: In particular and to clarify, my negative experience was not with your company.