Funny, I thought you were going to argue that the other way. That the "right" thing to do is start a dialogue with him, but the pragmatic thing is to ban his account at least until you sort things out on your end. Guess that just shows how tricky these issues are.
Given a hacker who found a vulnerability, exploited it within his account, and publicised it we can conclude that (1) he is smart (or lucky), (2) he does not pose an immediate malicious threat, and (3) he has the potential to become a serious problem.
Engaging with him carries the benefit of understanding the vulnerability while opening a dialogue that mitigates the hacker mutating into a serious problem. It carries the cost of not being able to claim, as GH did, that it pro-actively identified the vulnerability and thus looking weak. It carries the risk of giving the hacker time to rummage through more of the system.
Suspending him carries the benefit of being able to look strong while mitigating the risk of the hacker causing further damage. It carries the cost of losing a lot of emotional lee-way and thus future conversational runway with the hacker. It thus increases the risk of him turning into a serious problem in the shadows. There is also the risk that future users who happen upon vulnerabilities will think twice about publishing their finding under their real name.
Given, as many here have pointed out, that he can create a new account and be equally damaging (the risk is a property of him, not his account), the suspension offers no tangible benefit long-run benefit above that of managing perceptions. I don't know how sensitive GH's user base is to the perception of security.
The unknown here is whether GH has evidence that he acted maliciously, i.e. modified repos in accounts whose owners didn't give him permission to modify.