Intel Kills Cash Rewards for Security Researchers, Shifts to Unpaid Disclosure Program
Intel has suspended its bug bounty program on Intigriti that previously paid researchers up to $100,000 per vulnerability, replacing it with a disclosure program offering no financial compensation.

According to reporting from Phoronix, Intel has halted its paid vulnerability disclosure initiative, which once offered researchers compensation reaching $100,000 per identified flaw. The company's new program through Intigriti operates as what the platform describes as "a responsible disclosure program without bounties," with no explanation provided for the transition. The bounty board remains visible on the platform but now displays the program status as suspended.

Intel's official documentation continues to reference the previous bounty structure, which distributed awards "from $500 up to $100,000, based on quality of the report" and additional considerations. The initiative debuted in 2017 as an invitation-only effort before expanding to accept submissions from all researchers in 2018, encompassing software, hardware, firmware, and open-source codebases. During 2020 alone, the bounty program contributed to identifying 105 of the 231 CVEs that Intel addressed that year, the company disclosed.
The previous system organized reported vulnerabilities into four severity categories with corresponding payment bands: Tier 1 ranging from $2,000 to $100,000, Tier 2 from $1,000 to $30,000, Tier 3 from $500 to $10,000, and Tier 4 from $250 to $5,000. Intel broadened the program's coverage to include web services during the period between mid-2025 and October 2025, yet announced on January 6 via Intigriti that it was reassessing "enhanced bounty and bonus criteria." Within approximately eight months, the program transitioned from evaluation to suspension.
Industry observers have theorized that the proliferation of automated vulnerability discovery tools may have contributed to the decision. The Linux kernel has experienced a dramatic surge in reported CVEs, approaching 2,000 per release compared to roughly 500 previously, leaving maintainers "completely overwhelmed." Linus Torvalds, Linux's creator, characterized duplicate reports generated by AI systems submitted to the kernel security list as "almost entirely unmanageable." The Curl project similarly discontinued its bounty program after experiencing what it characterized as AI-generated submission floods.
HackerOne's Internet Bug Bounty program suspended new submissions beginning March 27, with the company noting that "AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed." The program continues processing previously submitted reports with payouts between $68 and $2,257 determined by severity level. This pattern suggests that automated discovery tools have created challenges for software-focused initiatives, though the impact on hardware and firmware programs may differ.
Intel's future direction regarding this suspension remains uncertain as the industry navigates rapid changes in vulnerability research. Researchers retain the ability to report security issues through the new program, though they will receive no monetary incentive. A review of AMD's Intigriti page reveals that its program also shows as suspended, though Intigriti maintains an automatic suspension mechanism. This development follows a prior disagreement with a bounty researcher in June concerning program scope and compensation.
Despite concerns about AI-generated submissions, automated tools have demonstrated legitimate security research value. OpenAI awarded Hacktron researchers a $6,500 bounty for identifying an exploit chain leveraging competitor Anthropic's model. Torvalds, who previously characterized AI primarily as marketing hype, has since acknowledged that AI represents "clearly a useful" tool, suggesting that broader acceptance of these technologies within the security community may increase.