The article discusses the experience of security researchers who found vulnerabilities in PayPal's system and were punished for reporting them through HackerOne. The researchers claim that despite the issues being eventually patched, they received no bounty, credit, or thanks, and instead had their reputation scores negatively impacted. The details of the article are not available, but the comments suggest that the vulnerabilities involved bypassing two-factor authentication and other security measures. The researchers and commenters are critical of PayPal's handling of the situation and its bug bounty program.