While you're absolutely right, unless there's something in it for you beyond curiosity / because you can, the risks much outweigh the benefits IMO.
Why would you help a for-profit company for free? Would they do the same for you? What is the best-possible scenario, a reward / job offer / gift certificate? What is the worst-possible scenario? Years in prison? Legal cases which drain all your savings? It hardly seems worth it to do this. Software vulnerabilities are EVERYWHERE, but trying to be a Good Samaritan in a hostile capitalistic environment doesn't tend to work out in your favor very often.
If you want to look at it rationally, he has pretty good chances of getting a good job in security now. It's likely he's looking at proposals by Google, Facebook, etc. Good recruiters love these kinds of things (and should, as they are a great measure of who is a passionate hacker).
As reluctant as I am to agree with this on principle.. yeah, the logic checks out. It's not like helping an elderly person across the street, you're dealing with an (a|im)moral entity who can and will nail you to the wall with on a whim if they think it'll improve their balance sheet.
I think the generally accepted practice is to go bug hunting when the organization has requested it (e.g. bug bounty programs), or report a bug if you stumble upon it without really searching.
Imagine going door to door checking your neighbors' houses to see if their doors are locked. Sure, you're "helping them out" by testing for a common vulnerability, but it's very difficult to distinguish between a good samaritan and a someone with malicious intents who had second thoughts or was concerned about being caught.
Many people find security bugs because they think it is fun and exciting and get intrinsic pleasure from finding one. Same reason why lockpicking is a hobby. Of course these people should stick to the companies who ask you to find their bugs.
I don't actually see how Starbucks could have been out millions. They'd just notice a gift card had a large balance, investigate, and zero it out. Unless the guy had managed to drink/hawk one million coffees in a few weeks.
Because someone could have exploited this en masse, sold these cards, etc. Even if that didn't go far they'd have to rewrite their software/service, hire some people, refund money to people because they had to cancel their gift cards, etc. Plus damage to the brand and future profits.
They could actually be lucky to just be out a million if this had been properly exploited.
For Starbucks, it's GOOD. It means they're out $2 and some embarrassment instead of out millions when someone sees something is way off in the books.
All that said, I would have tested this more than once to ensure it wasn't some minor built in allowance.