Large programs pay up to seven figures for critical findings, which is rational: a bounty of $1m against $100m at risk is cheap insurance, and it gives a researcher who could otherwise exploit the bug a legal, profitable alternative.
A funded, long-running bounty says more about a team's security posture than a one-off smart-contract-audit, because it is continuous and it prices the risk honestly. Check that the scope covers the deployed contracts and that past payouts were actually made.
Disclosure must stay private. Broadcasting a fix or a proof-of-concept publicly invites front-running-onchain of the patch, and researchers who exploit first and negotiate afterwards have faced prosecution in several jurisdictions regardless of returning the funds.
Related: smart-contract-audit, front-running-onchain, admin-key-risk, flash-loan-attack