Snapchat names, aliases, and phone numbers can be discovered and harvested via the Snapchat Android and iOS API — even if the user's account is private.
....
Gibson Security told ZDNet via email the metadata could be used in conjunction with other APIs to "automatically build profiles about users, which could be sold for a lot of money."
....
The script takes in a list of phone numbers, which the script could be made to generate, and "obtains the Snapchat username of anyone with a number in that range."
With the now-published "Find Friends Exploit" a malicious entity can use the Snapchat API to write an automated program that generates phone numbers to exhaustively search the Snapchat database for users. This allows them to obtain a "1:1" link between a person's phone number and their Snapchat account.
....
"The mass registration exploit could be used to create thousands of accounts, which could be used for speeding up the above process, or possibly for spam."
Researchers publish Snapchat code allowing phone number matching after exploit disclosures ignored | ZDNet
Full documentation: Snapchat - GSFD
Shoulda took that $3 Billion...