Notebookcheck Logo

Intel suspends its $100k bug bounty program

Intel Logo
ⓘ Intel
Intel Logo
Intel has officially suspended its long-running bug bounty program, eliminating cash payouts of up to $100,000 in favor of a zero-reward vulnerability disclosure system on the Intigriti platform. Launched in 2017, Intel’s bounty initiative was once a cornerstone of its proactive security strategy, responsible for identifying nearly half of the company's addressed vulnerabilities in 2020 alone.

Intel has suspended its long-standing bug bounty program and transitioned to a new vulnerability disclosure system on the Intigriti platform that offers no financial rewards. Previously paying researchers up to $100,000 for discovering security flaws, Intel's updated presence on Intigriti is now explicitly listed as a responsible disclosure program without bounties.

While researchers can still submit vulnerabilities found in Intel hardware, firmware, software, and open-source projects, they will not receive a payout for their discoveries. The original bounty program launched as an invite-only initiative in 2017 and opened to all security researchers in 2018. It proved highly effective at patching critical vulnerabilities before malicious actors could exploit them.

Intel has replaced the initiative with a responsible disclosure system on the Intigriti platform that accepts security flaw submissions but offers no financial rewards.

In 2020 alone, nearly half of the Common Vulnerabilities and Exposures (CVEs) Intel addressed were sourced directly through this program. Payouts were divided into four tiers, ranging from $250 for minor flaws up to $100,000 for top-tier vulnerabilities. As recently as early 2025, Intel stated it was evaluating enhanced bounty criteria, making this sudden suspension a surprise to the cybersecurity community.

While Intel has not provided an official reason for the suspension, industry trends point to the rise of AI as a likely factor. Open-source projects have recently faced a massive influx of security reports generated by AI tools. Linux kernel CVEs have surged from around 500 per release to nearly 2,000, leaving maintainers overwhelmed. Linux creator Linus Torvalds recently noted that duplicate AI-generated reports have made managing security lists almost impossible. Similarly, the open-source project Curl shut down its own bug bounty program due to a flood of low-quality automated submissions.

HackerOne's Internet Bug Bounty program also paused submissions earlier this year, explicitly noting that AI-assisted research is rapidly expanding vulnerability discovery and overwhelming the system. It is highly probable that Intel is facing a similar influx of automated vulnerability reports and chose to pause financial incentives to manage the volume. For now, cybersecurity researchers analyzing Intel technology will have to submit their findings without the expectation of a financial reward.

Google LogoAdd as a preferred source on Google
Mail Logo
static version load dynamic
Loading Comments
Antony Muchiri, 2026-09-20 (Update: 2026-09-20)