The "fair" thing here is probably to split the bounty among the discoverers, but that's not going to happen either.
The core issue is not the reward division algorithm, it's the inherent lack of visibility. One solution here would be to just open all reports after a while, but this creates problems of its own. One is that it gives ammo to people engaging in dishonest or clueless PR. Another is that some researchers don't actually want visibility, because their employers have murky rules around such engagements, or because they have some far-off disclosure timeline in mind (as a part of a presentation at a conference, or whatnot).
Probably also need stiff penalties for insiders who might conspire to notify others of bugs and split the pay out.
As far as not doing it. At some point critical industries may be have to be regulated to force them to behave responsibly.
Or a mechanism for companies that use email to register the researchers submissions in HackerOne. The details will be sealed and non-public, with researchers having no way to know it exists unless the company provides a link to it as proof of work. HackerOne thus acts as a kind of notary against accusations from researchers that it wasn’t really a duplicate.
And some payouts are 10k, I’ve never even heard of $50 minimums, I thought it’s either $100 or swag.
Out of curiosity, why shouldn't they? Is it because they then end up with a lot of garbage/spam submissions to sort through from people hoping to trick the company into paying out a bounty?