I’m not active in this business, but I know people who are. It’s not as easy as you think it is. You cannot just go to a government and say “hey, here’s my bug, give me a million dollars”. First off, your bug probably
isn’t worth a million dollars, at least if you’re just converting bug bounty submissions directly. They’re looking for reliable exploits, and payouts will depend on how long they can continue to field the chain (if it gets patched, you might be on the hook for another exploit!) and whether you’re selling it exclusively to them. Payouts will typically happen on a schedule.
Unless you’re a very known quantity they’re not going to talk to you directly, anyways. You’re going to go through a broker who will take a cut. My understanding (though I don’t know much about it) is that say, the NSA, has their own internal teams and they don’t need to buy anything anyways. The other federal agencies will contract out to a handful of firms that generally have salaried employees. You can work there, but now you’re seeing very little of the “profits” that come from the sale. Maybe your exploit will get some shoddy forensics glued into it and end up being sold as “data recovery” or something for a local police department, who probably doesn’t have much money to spare anyway.