Facebook did not mention any bug bounty or any white hat having reported the vulnerabilities that led to last week's exposure of user details, and thus it was reasonable to assume that a third party had walked away with at least 50 million access tokens to as many accounts, a security professional claims.