Your friend should have informed Mt. Gox, and if they either said there was no problem, or decided not to do anything about it, only then should he have felt free to do what he pleased.
I once ordered something on ebay for $500, and it turned out that the seller's account had been hacked, and several people (including myself) were being ripped off. I freaked out, and opened a case with Paypal, but I also had my bank reverse the payment (from my checking account).
When all was said and done, Paypal actually refunded me $500
twice. I explained to them what they had done wrong, but they said that their records did not indicate anything was wrong, so they could not do anything to correct it. So I was up $500 after the incident. Not bad, since I was trying to buy a gift card.
