paid through an online hot wallet instead of their own wallet
1. How do you plan to verify that the supplied address is "an online hot wallet"? Or, even the corresponding private key is known?
2. Let's guess you have a workable answer for (1). Does that mean that you suggest putting $1.9M bughunting bounty online on a monthly basis?