I know many people making a very good living from bounties (>$500k/year). If you're good, you'll make bank. If not - don't quit your day job.
Anyway I find it a bit weird the topic is asked at all. Why didn’t the OP just cold contacted committers?
What I do know is that they tend to sell their exploits through exploit brokers like Zerodium.
One is getting paid to write code that fixes bugs or adds functionality to open source projects. (Pays very little and we suspect nobody makes a living from)
The other is doing security research and reporting on vulnerabilities. Here typically no fix is provided. You are paid for the discovery. Plenty of good researchers make a living on these security bounties