Yeah the bounty for that kind of thing is worth more than 200k sats, I'm surprised they didn't just report it.
No guarantee you'll get a bounty from a small project. You're more likely to get paid if you exploit it.
reply