Bounties should work in principle: people who rely upon and care about having a secure crypto implementation should be willing to put up money for bug bounties.
Seems like people don't care enough to put up the cash. Why?
There are data breach insurance policies for sale. Why aren't these insurance companies putting up bug bounties for responsibly disclosed vulnerabilities? Is there a market gap here?