TL;DR: If you find an exploitable bug in a high-profile web site and discover that you're ineligible for a bug bounty, sell it to the bad guys instead. They won't treat you like s##t. ;-)
Out of curiosity, would it be illegal to do that? I mean ethically it's definitely wrong, and I'm sure it's illegal to sell it to someone if you know they are going to try and exploit it for profit, is there a technical loophole to hide behind?
Say, you sell it to someone and to the best of your knowledge they want to claim the reward for themselves. To justify the increased price you received by selling it to a third party instead of submitting it for the bug reward you could say that the third party intends to claim the bug as his own work and the professional cred they'll receive justifies the increased price.
Well, the US government buys exploits from people [1], which means it must be legal in the US. The government would never do anything against the law, right?