No, Liquid Network / Blockstream did not run a public security bug bounty program.
Elements (the software powering Liquid) and related projects only had a standard responsible disclosure policy: report privately via PGP-encrypted email to
securityblockstream.com. No rewards or formal bounty platform (Immunefi, HackerOne, etc.) were offered for vulnerabilities.
They occasionally posted development bounties for features (e.g. wallet kits), but nothing covering protocol or consensus bugs.