A sponsored bug bounty might be just as useful as more money directly to the project (especially if Google is porting Chromium to it). The nice thing about sponsoring a bug bounty is that anybody can do it; it doesn't require coordination with the project.
The prize pool could use to be a damned sight larger though. Heartbleed only qualified for a $15,000 payout: a figure ten times larger would still look a bit stingy for such a serious bug.
Certain ... private enterprises, as well. It's very unlikely that bug bounty prizes can be made to match the kind of money you might be able to get elsewhere for a big bug; but they don't really have to.
Yup, we're just waiting on someone to do it. It wouldn't have to be OpenSSL (or even FB or MS, the existing IBB sponsors): it could be done by anyone with enough public credibility to be trusted not to run away with the money, and the time and skills to jump through the tax/charity/crowdfunding hoops.