Maybe a logical "2nd step" for you would be to disclose that you've found a substantial bug that could "financially harm users" if exploited...but don't actually share the exploit. Post that you've contacted the developers as of <date> and will give them X-days to resolve the issue.
Now, as for that final step...that's up to you. Not sure the legal ramifications for sharing the exploit, or frankly, what the benefit to the community would be. I think your goal should be to put pressure on the developers, but not to actually expose the threat. If they never get around to fixing it, you've just potentially screwed the community (not to mention those that might never see the update).