conv.

All stories
SecurityQuiet 3d · day 6

Intel Suspends Bug Bounty Program, Replaces It With Unpaid Disclosure

Intel ends paid rewards for security researchers, citing AI-driven flood of duplicate vulnerability reports.

What to know

  • Intel suspended its bug bounty program, which paid $250–$100,000 per vulnerability depending on tier, and replaced it with an unpaid disclosure program on Intigriti with no stated reason.
  • The move follows an industry-wide pattern of AI-driven vulnerability flooding: HackerOne paused its Internet Bug Bounty in March, Curl shut down its program, and Linux kernel maintainers report being overwhelmed by duplicate AI submissions.
  • Intel's original program recovered 105 of 231 CVEs addressed in 2020 (45%), showing the program's historic value—its suspension could reduce incentive for human security researchers to contribute.

“Intel's replacement for the Intigriti program offers no rewards, and no reason was given for the change.”

Tom's Hardware, Tech publication · Tom's Hardware ↗ · Sep 18

Intel Hardware and security firmMichael Larabel Phoronix founder and reporterLinus TorvaldsLinus Torvalds Linux kernel creator

Intel Suspends Bug Bounty Program, Replaces It With Unpaid Disclosure
Tom's Hardware

How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts

Peak 6 pieces in two hours at Sep 19, 11 AM; 12 pieces over 6 days (9 articles · 3 posts) Sep 18, 5 AM — 1 piece · 1 article — Newswires 1Sep 18, 7 AM — quietSep 18, 9 AM — quietSep 18, 11 AM — quietSep 18, 1 PM — quietSep 18, 3 PM — 1 piece · 1 post — Hacker News 1Sep 18, 5 PM — quietSep 18, 7 PM — quietSep 18, 9 PM — quietSep 18, 11 PM — quietSep 19, 1 AM — quietSep 19, 3 AM — quietSep 19, 5 AM — 2 pieces · 2 articles — Google News 1, Newswires 1Sep 19, 7 AM — quietSep 19, 9 AM — 1 piece · 1 post — Mastodon 1Sep 19, 11 AM — 6 pieces · 6 articles — Google News 6Sep 19, 1 PM — quietSep 19, 3 PM — quietSep 19, 5 PM — quietSep 19, 7 PM — quietSep 19, 9 PM — quietSep 19, 11 PM — quietSep 20, 1 AM — quietSep 20, 3 AM — quietSep 20, 5 AM — quietSep 20, 7 AM — quietSep 20, 9 AM — quietSep 20, 11 AM — quietSep 20, 1 PM — quietSep 20, 3 PM — quietSep 20, 5 PM — quietSep 20, 7 PM — quietSep 20, 9 PM — quietSep 20, 11 PM — quietSep 21, 1 AM — quietSep 21, 3 AM — quietSep 21, 5 AM — 1 piece · 1 post — Hacker News 1Sep 21, 7 AM — quietSep 21, 9 AM — quietSep 21, 11 AM — quietSep 21, 1 PM — quietSep 21, 3 PM — quietSep 21, 5 PM — quietSep 21, 7 PM — quietSep 21, 9 PM — quietSep 21, 11 PM — quietSep 22, 1 AM — quietSep 22, 3 AM — quietSep 22, 5 AM — quietSep 22, 7 AM — quietSep 22, 9 AM — quietSep 22, 11 AM — quietSep 22, 1 PM — quietSep 22, 3 PM — quietSep 22, 5 PM — quietSep 22, 7 PM — quietSep 22, 9 PM — quietSep 22, 11 PM — quietYesterday, 1 AM — quietYesterday, 3 AM — quietYesterday, 5 AM — quietYesterday, 7 AM — quietYesterday, 9 AM — quietYesterday, 11 AM — quietYesterday, 1 PM — quietYesterday, 3 PM — quietYesterday, 5 PM — quietYesterday, 7 PM — quietYesterday, 9 PM — quietYesterday, 11 PM — quietToday, 1 AM — quietToday, 3 AM — quiet 12–3
Sep 19Sep 20Sep 21Sep 22yesterdaynow · 4:44 AM ET
  1. 2

    Industry patternAI flooding forces bounty program pauses

    Coverage documents that other companies have taken similar action: HackerOne's Internet Bug Bounty program paused submissions March 27 citing AI expansion, and Curl closed its bounty program due to AI-generated report flooding. Linux kernel maintainers report being overwhelmed by duplicate AI submissions, with Linus Torvalds calling them "almost entirely unmanageable."

    “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed.”
    — HackerOne
    • lonseidman@indieweb.social

      Intel has suspended its long-standing bug bounty program which previously paid researchers up to $100,000 for finding critical hardware flaws. The new disclosure program offers no monetary rewards, likely due to the efficiency of AI assisted tools for finding bugs and vulnerabilities. - https://www. tomshardware.com/tech-industry…

      lonseidman@indieweb.socialMastodon4d agoview on Mastodon ↗
  2. 3

    Tom's Hardware details Intel bounty suspension and context

    Coverage confirms Intel's Intigriti bounty board shows as suspended with no stated reason, and reveals the program paid up to $100,000 per flaw across four tiers. The report notes that nearly half of Intel's 2020 CVE fixes (105 of 231) came through the bounty program, and speculates AI-driven flooding may have influenced the decision, citing similar moves by HackerOne and Curl.

    “Almost half of the CVEs Intel addressed in 2020, 105 out of 231, arrived through the bounty program, Intel said.”
    — Tom's Hardware
    1. first by Yahoo Tech, 4d ago · also Tom's Hardware

    2. first by TweakTown, 4d ago

      5 more headlines
  3. 1

    Phoronix reports Intel bounty program ended

    Michael Larabel reports that Intel has ended its paid bug bounty program and launched a replacement without bounties, amid a surge in AI-driven bug reporting across the software ecosystem.

    “Amid a boom of bug reporting in general due to AI/LLMs across the entire software ecosystem, Intel this week appears to have ended its paid bug bounty program.”
    — Michael Larabel
    1. first by Phoronix, 5d ago

  4. background

    Intel announces bounty program evaluation — Intel posted an update on Intigriti stating it was evaluating "enhanced bounty and bonus criteria" for its bug bounty program.