Just my point of view:
I am highly in favor of having a big bounty program. Having the freedom to reward up to 5k without a proposal is something I think is great (I would be in favor of allocating 20k with max single transaction of 5k without a proposal)
I think that if this program was in place when the issue got noticed, it would had been rewarded.
Reading up the comments - “initially demanding money in order to return the remaining funds” this changes everything for me. Where I understand his motives and frustration (especially with the $10 offer). This is not the way, and I also don't think it should ultimately be rewarded in this manner. (I think he is crossing the line here and taking the risk of being sued himself).
Overall:
RE: Zero Day Vulnerability