What I'm seeing in that threat rather seems like the developer had not signed to hackerone and had not invited bugreports, but received an unsolicited request from the OP to join hackerone and probably pay them money for a beg-report. I.e. OP had linked a screenshot from hackerone which states that Netapp does not accept unsolicited bugreports.