I'd say the biggest impact is that it encourages a behavior that a lot of people people tend to show anyways: If we find a bug, most of us are inclined to report it, not abuse it. I'd assume that a lot of people tend not to report bugs when they have the feeling that it only costs them time for no benefit. Now, with a bug bounty you're shifting the equation towards the desired outcome: Taking an hour of your time to write a bug report can actually pay off for you, even if only one in five bugs get the minimum reward. Granted, you could sell a critical exploit for much more money, but most humans are intrinsically biased to do "the right thing" and by rewarding people for doing the right thing and making that reward public, you're reinforcing that bias.
It's still a cheap way to get bug reports, but I don't think it's about replacing QA. It's about creating a climate where bugs missed by QA have an increased likelyhood to end up on your desk since no QA could ever find all bugs.