You're right, but so is the parent commenter; there is a popular meme that security bugs in general are worth large amounts of money, but in reality only a small subset of bugs command real money.
You could be a better ambassador of our industry by explaining the misconception instead of being condescending. And we wonder why developers think we are just arrogant jerks.
IMHO anyone who contributes to the state of the art with regards to public security tooling is doing the world a favour. Even if the majority of these applications are not well privileged, and therefore of dubious value, applying the same technical knowledge elsewhere could earn them cash. I still applaud their efforts.