glad to know that there is a bounty bug, I wonder how much is the reward

Depends on the bug also, very serious bugs can be more than 10 bitcoin, really depends on how it could affect website. But believe me, if you found that there is something wrong on Bitsler, Baryom or any other staff will reward you, I have experienced it once myself.
Also see Baryom's trust, once he sent 40 bitcoin to NLNico for finding very critical issues on bitsler.
yes,there is a reason sites pay bug bounties as one bug like that could have ruined the business
and 40 bitcoin seems like a huge price to pay for a bug,but I am sure the audit done by NLNico was well worth the bounty
if you look at some other sites,even the top ones,they suffer from hacks and bug exploits
remember Betking? when the owner could not even understand how was he hacked and offered the hacker bounty to disclose his method
this made the site go down and the owner take a break to come back later with a new reicarnation of the site
I think the reason why they offer these bounties is because it gives the would be hackers or thieves a legit way to earn their money.
Basically lets say they discover a bug and get to exploit the site out of a few BTCs. They can either do that and wait until the admin finds out and blocks the bug or they can just report the bug and get a bug bounty sent and get to keep it legally.
In both ways everybody is happen. Hence why these bugs exist. And they usually exist for most bitcoin services and even coins themselves like Ethereum is offering bug bounties.