Sadly, they're doing a lot better than most of the Bitcoin community. I recently found two exploitable XSS issues on Blockchain.info, a website which runs the largest number of Bitcoin based wallets in the entire network. To get a response from them, I had to use a public front-page post on reddit just to get an email address to contact.
Had either bug been used maliciously, every user visiting almost any page on the site would have lost their web wallet with no further interaction.
It was of course, "not an issue", despite at my count, three core Bitcoin developers chiming in and talking to the developers of the site, named Zootreeves and MemoryDealers.
https://pay.reddit.com/r/Bitcoin/comments/1n57uj/im_attempti...
Had either bug been used maliciously, every user visiting almost any page on the site would have lost their web wallet with no further interaction.
It was of course, "not an issue", despite at my count, three core Bitcoin developers chiming in and talking to the developers of the site, named Zootreeves and MemoryDealers.
https://pay.reddit.com/r/Bitcoin/comments/1n57uj/im_attempti...
Full disclosure: I was later paid a small bounty after it was fixed.