No one has done anything negative with this as far as I know.
As for going legit, that depends. There are people out there who like to buy up undisclosed/non-public exploits and vulnerabilities. They can fetch a pretty penny.
But that's a short term gain
.