Earlier quoted context omitted.
I do not have the market rates for vulnerabilities, but I do know some pen testing companies charge $10,000 for a few days of work that may not return any concrete bugs. Compared with hiring a pen testing team, offering high bounties seems like a bargain as you get actual exploits that would impact the company.
Yes, that is the premise behind bug bounties. If you're a vulnerability researcher with a track record, you will probably make better money and certainly more consistent money as a pentester. Many pentesters just do both. I have, uh, some experience with the rates here.
"XSS bug in a popular note taking app ... attacker to download all the users notes just by having them visit a URL"
So as to not feel worried that future vulnerabilities would get sold on the black market instead