Just to be 200% clear: cperciva is offering $1000 for an exploit of a bug in Tarsnap 1.0.35 that he already fixed in the current 1.0.36 version?!
I think if someone manages to exploit this bug, the details will be very interesting, and I think it's worth paying for "interesting".
Also an illustration of how unlikely it is that serious exploit developers are going to spend time writing a complicated Tarsnap exploit. :)
Fix bugs! Update your systems! If in doubt, assume that potential vulnerabilities are exploitable!