I mean, for a recent example of how this works in practice: Polygon got whacked for like 650MM last August, but all the fiat and even stablecoin exchanges blacklisted the addresses and the guy got like 5MM “bug bounty” or whatever.
There might be prestige in some circles for taking down some dumbass Solidity coder, and some people seem to be getting some money out still (e.g. Wormhole).
But overall I’m short Trail of Bits consulting rate.