You're thinking about this in moralistic terms of deservedness. The shock I encountered at the 40K was that it wasn't enough to incentive future security researchers to find bugs. This just seems like a bad business decision.
Aren’t the contents of NFTs public before the sale? I agree with your general point that there were buyers willing to pay more, but NFT might not be the right vehicle for it.
the NFT is just a dumbass complication and doesnt add anyhting. people have been selling exploits forever. its like saying ill paint the instructions onto a canvas and sell it