Understood. But I imagine that his work isn't quite as "steady" as one might expect. He invests time by trying to find security exploits in hopes that the affected company compensates him. He doesn't set his price or even determine if he gets paid for his time.
I think that might be the rationale...or it might just be that he's found himself in a position where he can collect bounties AND donations :).