This is why I consider bug bounty programs problematic, because they've been co-opted from a system to manage responsible disclosure to a system to contain and manage non-disclosure.
But like all things, they can also be used to keep software insecure, hide issues, and instead buy off researchers.