Who has an incentive to look closely at the code? At least those, who want to benefit from potential exploits, as happened in the recent Coldcard debacle.
This is also, I think, a good example of how just because it's reviewable doesn't mean it will be reviewed properly, as the bug was discovered by gmaxwell looking at code. Several people reached the same conclusion by disassembling the firmware. Either way, people were able to go and look at the code/firmware, but this doesn't mean that most people can/will. It takes a highly-skilled analyst to recognize what went wrong here. Openness alone is no panacea, since it took someone as good as gmaxwell to recognize a #define/#ifdef mixup.
This likely creates an environment which isn't quite encouraging for security researchers. I mean, those commonly preinvest their time and therefore money to find something that will or rather should pay off later.
And the real crux: assuming a researcher is able to find such a subtle vulnerability, and finding an RNG whitening bug is no cake-walk either, they may very well decide to exploit it, sell it or report it. Selling/exploitation will get them way more money than bug bounty will. And potentially millions.
So, unless you want to compete with black-market in offering bounties , your company’s bounty policy, however generous, will be irrelevant. Ethics and professional reputation are the only things keeping such researchers from exploiting vulnerabilities they discover.
Has Coinkite ever acknowledged external contributions to improve their code? Genuine question, because I don't know and never cared to pay attention to it
Aside from the RNG issue itself, I think it's important to comment on the treatment of outside researchers. It doesn't take long before it becomes common knowledge in security circles if a company is going to ignore outside researchers. The next person who finds something really serious at this company might not be jumping through hoops to report it for free. At best, they'll say nothing. At worst, they'll sell it on the black market.