This was, itself, driven by AI vuln finding, ironically :-P however, I took the example of @ggwhyp's Firefox RCE - quite a long chain, rejected by the organizers but probably would have won some cash from Mozilla... Details aren't public, so we won't know. Maybe their vuln was patched with Bug 2024918? At this point it's anyone's guess...
But the fact that nobody else who made it through had an exploit and claimed $$$ on Firefox tells me that improvements were made.
And this is what blew my mind, personally; a _browser_ - huge, complicated target codebase with myriad features, many of which are 'on the internet' - didn't have any disclosures with money on the table. That's definitely a datapoint worth registering. But you're absolutely right to remain skeptical!