Intel Suspends Bug Bounty Program, Replaces It With Unpaid Disclosure
Intel ends paid rewards for security researchers, citing AI-driven flood of duplicate vulnerability reports.
What to know
- Intel suspended its bug bounty program, which paid $250–$100,000 per vulnerability depending on tier, and replaced it with an unpaid disclosure program on Intigriti with no stated reason.
- The move follows an industry-wide pattern of AI-driven vulnerability flooding: HackerOne paused its Internet Bug Bounty in March, Curl shut down its program, and Linux kernel maintainers report being overwhelmed by duplicate AI submissions.
- Intel's original program recovered 105 of 231 CVEs addressed in 2020 (45%), showing the program's historic value—its suspension could reduce incentive for human security researchers to contribute.
“Intel's replacement for the Intigriti program offers no rewards, and no reason was given for the change.”
Tom's Hardware, Tech publication · Tom's Hardware ↗ · Sep 18
Intel Hardware and security firmMichael Larabel Phoronix founder and reporter
Linus Torvalds Linux kernel creator
How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts
-
2
Industry patternAI flooding forces bounty program pauses
Coverage documents that other companies have taken similar action: HackerOne's Internet Bug Bounty program paused submissions March 27 citing AI expansion, and Curl closed its bounty program due to AI-generated report flooding. Linux kernel maintainers report being overwhelmed by duplicate AI submissions, with Linus Torvalds calling them "almost entirely unmanageable."
“AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed.”
— HackerOne -
L
Intel has suspended its long-standing bug bounty program which previously paid researchers up to $100,000 for finding critical hardware flaws. The new disclosure program offers no monetary rewards, likely due to the efficiency of AI assisted tools for finding bugs and vulnerabilities. - https://www. tomshardware.com/tech-industry…
-
-
3
Tom's Hardware details Intel bounty suspension and context
Coverage confirms Intel's Intigriti bounty board shows as suspended with no stated reason, and reveals the program paid up to $100,000 per flaw across four tiers. The report notes that nearly half of Intel's 2020 CVE fixes (105 of 231) came through the bounty program, and speculates AI-driven flooding may have influenced the decision, citing similar moves by HackerOne and Curl.
“Almost half of the CVEs Intel addressed in 2020, 105 out of 231, arrived through the bounty program, Intel said.”
— Tom's Hardware -
first by Yahoo Tech, 4d ago · also Tom's Hardware
-
1 outlet Intel kills its bug bounty program that paid up to $100,000 for flagging security vulnerabilities
first by TweakTown, 4d ago
5 more headlines
- Intel Scraps Paid Bug Bounty Program That Offered Up to $100,000, Shifts to Reward-Free Disclosure finance.biggo.com · 4d ago
- Intel drops paid bug bounty program, offering researchers nothing but thanks Gagadget.com · 4d ago
- Intel suspends bug bounty program that paid up to $100,000 per flaw tomshardware.com · 4d ago
- Intel Ends Its $100,000 Bug Bounty Program techpowerup.com · 4d ago
- Intel reportedly ends bug bounty rewards for security researchers VideoCardz.com · 4d ago
-
-
1
Phoronix reports Intel bounty program ended
Michael Larabel reports that Intel has ended its paid bug bounty program and launched a replacement without bounties, amid a surge in AI-driven bug reporting across the software ecosystem.
“Amid a boom of bug reporting in general due to AI/LLMs across the entire software ecosystem, Intel this week appears to have ended its paid bug bounty program.”
— Michael Larabel -
first by Phoronix, 5d ago
-
-
background
Intel announces bounty program evaluation — Intel posted an update on Intigriti stating it was evaluating "enhanced bounty and bonus criteria" for its bug bounty program.