Intel suspends its $100k bug bounty program

Intel has suspended its long-standing bug bounty program and transitioned to a new vulnerability disclosure system on the Intigriti platform that offers no financial rewards. Previously paying researchers up to $100,000 for discovering security flaws, Intel's updated presence on Intigriti is now explicitly listed as a responsible disclosure program without bounties.
While researchers can still submit vulnerabilities found in Intel hardware, firmware, software, and open-source projects, they will not receive a payout for their discoveries. The original bounty program launched as an invite-only initiative in 2017 and opened to all security researchers in 2018. It proved highly effective at patching critical vulnerabilities before malicious actors could exploit them.
In 2020 alone, nearly half of the Common Vulnerabilities and Exposures (CVEs) Intel addressed were sourced directly through this program. Payouts were divided into four tiers, ranging from $250 for minor flaws up to $100,000 for top-tier vulnerabilities. As recently as early 2025, Intel stated it was evaluating enhanced bounty criteria, making this sudden suspension a surprise to the cybersecurity community.
While Intel has not provided an official reason for the suspension, industry trends point to the rise of AI as a likely factor. Open-source projects have recently faced a massive influx of security reports generated by AI tools. Linux kernel CVEs have surged from around 500 per release to nearly 2,000, leaving maintainers overwhelmed. Linux creator Linus Torvalds recently noted that duplicate AI-generated reports have made managing security lists almost impossible. Similarly, the open-source project Curl shut down its own bug bounty program due to a flood of low-quality automated submissions.
HackerOne's Internet Bug Bounty program also paused submissions earlier this year, explicitly noting that AI-assisted research is rapidly expanding vulnerability discovery and overwhelming the system. It is highly probable that Intel is facing a similar influx of automated vulnerability reports and chose to pause financial incentives to manage the volume. For now, cybersecurity researchers analyzing Intel technology will have to submit their findings without the expectation of a financial reward.














