If they don't compensate security researchers enough, the incentive to find security holes goes away. People do this for a living.
It doesn't even have to be monetary - for example, GitHub maintains a list[1] of people who have responsibly disclosed vulnerabilities, and they often send them a shirt or something similar.
[1] https://help.github.com/articles/responsible-disclosure-of-s...
Maybe. But nobody asked these guys to do a thing. Ergo, no foul.