>a gift card phone bot that calls gift card phone lines, bypasses captcha, and transcribes balance.
It probably doesn't but does that company have a mechanism for people to report security problems?
This is partly about what you do with what you find out or build. If you discover some loop hole or vulnerability report it to the company then publicly publish your code etc once the security problem is fixed that is very different to finding a problem and directly using it to acquire money.