Intel ends paid bug bounty program, switches to reward-free disclosure

Intel has suspended its bug bounty program that paid up to $100,000 per flaw, replacing it with a disclosure program on Intigriti that offers no bounties. The change was made without explanation, and the old program had been open to researchers since 2018. Intel's site still lists the old reward tiers, but the Intigriti page now describes the program as responsible disclosure without bounties.
The suspended program accounted for roughly 45 percent of Intel's 2020 CVE disclosures, with tiered rewards from $250 to $100,000 covering hardware, firmware, software, and open-source projects. Intel expanded scope to web services in late 2025, then announced in January it was reviewing bounty criteria before the suspension.
The change coincides with industry-wide pressure from AI-generated reports. Linux kernel security submissions have neared 2,000 per release, overwhelming maintainers, while Curl closed its bounty program over AI slop. HackerOne's Internet Bug Bounty paused new submissions in March but continues paying queued reports.
The suspension could reduce incentives for independent researchers to report Intel flaws, potentially slowing discovery of hardware and firmware vulnerabilities. Users of Intel products may face longer exposure windows before critical issues surface, while researchers lose a revenue stream. However, the shift may reflect practical realities of AI-generated report volume, and the disclosure program still provides a reporting channel, though with diminished motivation for participation.