I like the idea of not crediting the person who posted the bug but to the LLM that found it. People who find exploits using LLMs should never get a reward or credit.

So people coding with LLMs shouldn't get paid then, right?

That is in fact the end goal of CEOs pushing LLM use yes. Not possible right now, but if it were they would absolutely take that option.

[citation needed]

Does "companies will cut unnecessary costs" need a citation?

Do you think the CEO of your company hired you and pays a lot of money for you because they like you?

Do you assume that five years from now you'll get paid for coding with LLMs?

Correct.

They should get paid by the LMM only.

It baffles me how this can be said without concern for first order consequences.

I agree! We should go all the way though and credit the authors of the data the LLM was trained on. People who just run LLMs training scripts should never get a reward or credit.

I take credit given all my infosec-related reddit posts they used for training.