I think from a PR point of view with respect to the rest of the developer community you might have lost this one. You didn't eliminate the threat posed by him as an individual because he can create a new account.
(Note: as far as your enterprise or big-corp clients, you probably did the right thing, because that is what they would have done and that is what they expected. So if they are the clients who put bread on your table, then you have acted correctly)
What I think you could have done better (and I speak as a developer not a corporate client): issue a public note saying something to the effect of "Thanks for finding this out, maybe you'd like to interview with us. But please, everyone, do not do it this way, this is against TOS and most likely illegal. Here is is the email where to report these things and we will make sure to give you full credit after we fix the problem".
A lot of the fire could have been cooled with the suspension notice being accompanied with (ideally preceded by) a personal note to Egor. The absence of that is what makes this seem more like a GoDaddy firing-from-the-hip move than a rationally thought out one.
The hacker reported the vulnerbility responsibly but was ignored. Now you've suspended his account even though he did no harm. It looks from the outside like you suspended his account because he embarrassed you and doesn't have the public clout of someone like Zed Shaw, who also demonstrated a vulnerability (and, unlike this case, caused some downtime) yet faced no similar reprisal.
He didn't delete or break anything, yet got the issue raised and fixed near-instantly. That strikes me as responsible. Stop parroting buzzwords - nobody likes a pedant.