The road to hell is paved in good intentions. If I had to guess, a well meaning and experienced engineer or engineering leader proposed launching a legit bug bounty program. Maybe they pitched the idea to their boss, showing them hackerone or bugcrowd as an example. Everyone thought it was a good idea, but the further the concept shifted along in development and away from the original engineer, the less people understood what a bug bounty program actually is. By the time it gets through legal, and marketing, and the executive team, it turns into a downside protection effort rather than quality/security improvement effort. I have to imagine this is pretty common in large organizations that keep their departments siloed off from one another, reducing collaboration.