That's not how it works. Bug bounties work like this.
Somebody sets up a bounty program and defines a framework for deciding how much to pay out. Security is complicated as hell and you cannot possibly devise a framework that accounts for all possible things so this framework is necessarily brittle. For example, you might reasonably decide that the highest payouts require very minimal attacker capabilities (fully remote unauthenticated attacks being the top payouts). This makes sense since those are the easiest attacks to mount.
So now a bounty comes in. It goes to a triage person or, at best, a small group. They refer to the framework. Your bug doesn't really match any of the categories but it kind of looks like this thing over here so it gets bucketed as such. Maybe there is some discussion. Ultimately, the rules say "max payout requires unauthenticated remote attacks" so the payout ends up lower, even if the attack is exciting. Maybe somebody managing the system takes a note to update the framework and policy moving forward. The community then rages about how this bug is actually a big deal and deserves a lot of reward.
In my experience, the people managing these programs get rewarded based on the amount they pay out going up, not down. But you need a payment framework otherwise each bug is paid out on somebody's whim (and trust me, the security researchers will complain to high heaven if they perceive inconsistency in bounty sizes). So you end up with novel bug structures that aren't handled well by the framework and get treated weirdly.