I agree. I think the problem is conflating the dark grey market[1] values of vulnerabilities with their white market values.
Reportedly there is a lot of money in the security vulnerability dark grey market at this particular moment in time, and that seems to be pushing up the perceived monetary value of these vulnerabilities.
But if you think about it, it would feel an awful lot like extortion for a researcher who's found a vulnerability to allude to the grey market value of a vulnerability in a responsible disclosure discussion. This is kind of what the community is doing by consistently bringing that point up in regards to rewards for such responsible disclosures.
At the end of the day, if the researcher is virtuous, then the black/grey market value of the vulnerability is irrelevant, and so acknowledgement of the issue, followed by rapid action to close the vulnerability, and optionally, a token of appreciation is plenty of reward for the disclosure from a moral point of view.
Now, I'm not naive. I believe that people respond to incentives and when you're talking about incentives, then the black/grey market values do come into the calculation. But that's a purely amoral and pragmatic optimization problem, and therefore not a proper object for the moralizing that we've seen regarding these programs.
I don't have any particular issues with pontificating about how a particular company could be more effective if it increased its bug bounty rates[2], but any pseudo-moral outrage is hollow because it's founded on the assumption that moral and immoral disclosure are relatively equivalent options.
[1] That is, it's not always technically illegal, but I think that the market is fairly universally regarded as antisocial if not a major threat of the day.
[2] Though it would be very difficult for a company outsider to actually accurately determine the value of responsible disclosures to a company. There are a whole lot of vulnerabilities in complex software, and really, any particular disclosure is essentially worthless. I would imagine that the real monetary value of a given disclosure is orders of magnitude less valuable to the vulnerable company than it would be to a potential attacker. For the vulnerable company, they still have a vulnerable product after fixing the particular vulnerability, but for the attacker, they have a successful attack vector by having knowledge of the particular open vulnerability. Also, I can't imagine that the value of a particular vulnerability is proportional to the company's revenue/valuation/etc. which is the metric that seems to always be trotted out when talking about how a particular company's reward program is not generous enough, especially with regards to "billion dollar companies"