This might work but only if the evaluations are done through a trusted third party entity where none of the money ever reaches the company you're submitting to.
You only need things like that for non-iterated games. A company that gets a reputation for keeping the money when it's a real bug would stop getting real bug reports.