ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.
Remember that you can sell the same vulnerability to multiple people: it's software you can copy.
$1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?).
Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.
Negotiating with terrorists or black mailers is a bad idea.
The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)