If someone is hacking something for nothing but some odd satisfaction, it is sort of a people problem in addition to a technical problem. The attacker could very easily point to the problem and say, "OK, I had fun while it lasted but here is the security bug: ..."