I don't think this analogy works. With this analogy, they'd have to be adding bugs to the code and then "finding" them to get the reward. In this case, having a reward would most likely result in more people specifically looking for bugs, but they'd be looking for them so that they could report them and get money for it. It's better to have to pay out a bug bounty than have a malicious entity find and exploit the bug later.