How did he have little credibility? And how did he lose it?
He spent his own time helping Starbucks improve their security. Starbucks insinuates or suggests he committed fraud and malicious actions for finding AND trying to alert them of the problem so that it could be fixed. Starbucks was out of line here, not him.
While not eloquently expressed, it should still be obvious to most readers of this site that he is not implying that next time he will go and steal millions when he finds a bug. He is articulating that corporations that respond this way create a culture where they will only find out about vulnerabilities when it's too late, because no one will want anything to do with them.
If anything, the more serious bug is the attitude of Starbucks as an institution here, and people not holding Starbucks accountable.