Earlier quoted context omitted.
The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.
I did the same thing with OP years ago, I tried to contact in every way possible the dev team of the largest telecom company in my country. All channels were ignored, so I have to resort to contacting our government agencies. Luckily, one agency replied to me and had one of the devs contacted me. For this hassle I was only paid $50. You have no idea the effort we go to report this things. So I quit bug hunting after…
If there is a next time, maybe I'll try convincing the cybersecurity bureau to take my vulnerability reports instead.