I don't understand how it's anything beyond a minimal defense-in-depth measure.
1. Target leaks session cookie
2. Attacker uses VPN to connect from target's country with the leaked session cookie
3. Attacker's session is deemed valid
Attackers usually don't know the country of the user. Even if they do, it's not as easy as it sounds to find a VPN or an open proxy in any country.
If you're thinking of Tor, Tor is trivial to detect and block.
I've been working in fintech companies and e-commerce, handling real money or wallets that could be stolen or emptied by a successful attacker. If you don't do defense in depth, users lose. One trivial example, the days after a new breach is published on Hacker News, there will be bots on the door attempting to brute force login with all these new email and password combinations.
Any other question? I feel like I have a context to start writing a blog post on that.
Most attacks are opportunistic, trying credentials that were leaked online or brute forcing simple passwords. It's also heavily weighted from russia, china, tor, open proxy, non-reputable hosting and cheap VPS. Each of these can be detected and blocked.
Attacker do not maintain proxies, especially not proxies across tens of developers countries, and if they that would be organized crime and it's a whole new level. By the way, banking trojans evolved to operate from the browser of the victim specifically to evade these protections.
Should I cover all these in a blog post if it's something you're interested in?
I think you're deviating from the topic of protecting against the vulnerability HackerOne encountered: using a leaked session cookie.
In their case, let's say the victim analyst was based in the United States, and they have implemented your proposed session country-lock. I also happen to reside in the US, so the country-lock protection is worthless.
For other cases, you can _try_ to block proxies, VPNs, TOR, VPSs... but that in itself is perhaps a usability fail.