That applies to most of us.
It also doesn’t change the fact that there is very little money available in the DRC.
The DRC has a lot of problems (to say the least) at the moment and has had for a while and this is pretty low priority in their scheme of things. Countries with weird residual TLDs for non-sovereign territory (e.g. .as or .ac) surely pay more attention to these trivial domains than anyone in the DRC can.
Which is all to say the amount of effort expended on any task, or the amount of knowledge brought to bear on a task, is only sometimes correlated with its value. Ever worked hard on a company that failed?
I felt I needed to put the first line in because my comment on your question could have been misinterpreted as criticism of the hacker.
s/distort/extort/I don't know if "Big Internet" (ICANN, IANA, IETF, RIRs) does not have its own security group like the Commercial companies do (Project Zero, various EH companies). RFC3013???
We have to depend on people who can take time to look for exploits in exchange for reputation.