I like the idea of not crediting the person who posted the bug but to the LLM that found it. People who find exploits using LLMs should never get a reward or credit.
I agree! We should go all the way though and credit the authors of the data the LLM was trained on. People who just run LLMs training scripts should never get a reward or credit.