It's not possible for these programs to "create" problems, only to expose them. While many companies like to take the "la la la, I'm not listening!" approach to security, it doesn't actually make you more secure.
I don't think this analogy works. With this analogy, they'd have to be adding bugs to the code and then "finding" them to get the reward. In this case, having a reward would most likely result in more people specifically looking for bugs, but they'd be looking for them so that they could report them and get money for it. It's better to have to pay out a bug bounty than have a malicious entity find and exploit the bug later.
Did you not see the Dilbert cartoon where the punch line from Wally is "I just wrote me a new car".
The people towards whom a vulnerability rewards program is targeted aren't the same people writing the code. That should be obvious.
You don't know much about human nature do you? Insiders would pass details to trusted friends and get them to make the claim.
Just like quite a few insider trading cases it's the wife/family members that get the tip and buy the shares.