A $100,500 bounty seems pretty cheap compared to the severity of the issue, or is it common?
Although I guess one reason they might buy a bug that would lead to financial harm is to prevent a competitor from getting it, which might be an even worse financial harm.