Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.
OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have asked for additional repro instructions after his initial report. Unfortunately, all he submitted was a link to the post he'd already made (on a real account whose consent he did not have - violating our ToS and responsible disclosure polic…
You seriously need to pay this guy like you promised, especially since he went to all the trouble to report it to you. This is a real low move for a company against this guy who obviously isn't a first-language English speaker.
Even if he violated a very minor and insignificant point in your terms, he only did it after you flat-out rejected his report. If you want to encourage reports, you need to be reasonable. If I was this guy, I would be absolutely furious after putting so much work in, doing it the pussy-way and reporting it to the company rather than leaking/selling it for spammers to use, only to get blindsided and literally make it all for nothing.