1. NSO almost certainly has more than one exploit chain at a time. While this would burn one of their exploits, it wouldn’t put them out of business or eliminate the ability for them to get RCE on phones in general.
2. Vendors already have bug bounty programs with established award ceilings. These exploits are almost always far more valuable than the vendor is willing to pay via their bug bounty program. Why would the vendor pay more in this instance?
3. Given (1), how long would this go on for? NSO—who is aware of how many exploit chains they have—likely wouldn’t sell all of their exploits to a single buyer and risk them all getting burned.
TL;DR: It wouldn’t be practical.