I don't know, how much is the security bug bounty on LastPass? $1000 according to Bugcrowd [1]. But what would be the right value?
That's the only way we ensure it's economically more viable for hackers to resell their security leaks to LastPass than to pirates. An economic approach would claim that the total available bug bounty scheme must be worth the same as the potential stolen value of the contents, otherwise it's still valuable to exploit the leak rather than publish them. The only savings that LastPass can make is over the gap between insured value and their ability to not have leaks.