That's the only way we ensure it's economically more viable for hackers to resell their security leaks to LastPass than to pirates. An economic approach would claim that the total available bug bounty scheme must be worth the same as the potential stolen value of the contents, otherwise it's still valuable to exploit the leak rather than publish them. The only savings that LastPass can make is over the gap between insured value and their ability to not have leaks.
What security issues? This blog post isn't really new information (or surprising), and I cannot think of anything else.
The biggest problem LastPass has had is that LogMeIn purchase them who a lot of people hate/distrust (myself included).
The rest of your post is predicated on LastPass being of "low quality" because of supposed "security issues" so I invite you to point them out.