I've made some money doing it, not a lot, and to be honest, most of the submissions I've sent have been to unpaid programs (but through Hackerone, Bugcrowd, and some companies own bug bounty systems). Why? It's fun to be able to poke at large orgs, find issues, report them, and not have some pissy response like I used to get before bug bounties were a thing. You'll actually see them get fixed and you're doing stuff that may prevent unsavory types from screwing people over.
My favorite response though is still the "This is a duplicate from [random date six months ago]". Oh, so you're purposefully just leaving an XSS live on your corporate SSO? Makes sense! Nobody ever tries to phish corporate logins at large organizations.