Many of the emails are sent in bulk. We have a published security page, a security.txt, a link in the footer of our page, a security@/abuse@ email alias and still receive the random email asking if there's a security program. The person hasn't found anything yet, at maximum it was an automated relatively easy scan. Those we replied to then never came forward with a report, now we no longer reply.
Reward can also be swag, even large known brands sometimes send branded t-shirts or socks instead of payment for low security issues (e.g. open directory listing on a website that doesn't contain any important files).
Be sceptic about 'critical'. In my experience just about anything gets labeled high and critical in the emails. "You should require a captcha on your contact form otherwise someone could send you 1000 emails" was deemed critical by one person recently.
Reply with promise to look into the issue and a non-commit first. The comment from julienreszka is perfect.