Maybe they have an email list of the original donors and can propose some multiple choice options:
1 - bug bounty
2 - attempt to hire someone at a steeply reduced rate for the audit
3 - use the money to seed a complete replacement or a clean room rewrite if possible (this is a can of worms but given the license issues seems like the only realistic way forward... might need the help of FSF or ASF or the like)