Intel appears to have suspended bug bounty program that paid up to $100,000 per flaw
Intel appears to have suspended its bug bounty program that once paid up to $100,000 per flaw. The Intigriti site now describes the program as a “responsible disclosure program without bounties,” and the bounty board shows the program as suspended, though Intel’s own page still lists the original award ranges from $500 up to $100,000.
Key points
- Intel’s bug bounty program, which paid up to $100,000 per report, is listed as suspended on the Intigriti site.
- In 2020, 105 of Intel’s 231 addressed CVEs (about half) came through the bounty program, according to Intel.
- HackerOne’s Internet Bug Bounty paused submissions on March 27, but continues paying queued reports with rewards from $68 to $2,257.
The program launched invite‑only in 2017, opened to all researchers in 2018, and covered software, hardware, firmware and open‑source projects. Intel said 105 of the 231 CVEs it addressed in 2020 (about half) came through the bounty program. The old board divided rewards into four tiers: Tier 1 $2,000‑$100,000; Tier 2 $1,000‑$30,000; Tier 3 $500‑$10,000; Tier 4 $250‑$5,000. Scope was expanded to web services between mid‑2025 and October 2025, and a January 6 update said Intel was evaluating “enhanced bounty and bonus criteria.” Within roughly eight months the program moved from evaluation to suspension.
Media outlets speculate that the rise of AI‑generated vulnerability reports may have contributed; Linux kernel CVEs have approached 2,000 per release, a fourfold increase from about 500, and Linus Torvalds called duplicate AI reports “almost entirely unmanageable.” HackerOne’s Internet Bug Bounty paused submissions on March 27 but continues paying queued reports with rewards from $68 to $2,257. Researchers can still submit to Intel’s new program, but receive no monetary reward.
Intel suspends bug bounty program that paid up to $100,000 per flaw — new Intigriti disclosure program offers no rewards
Tom's Hardware · 19 September 2026
Phoronix reported that Intel appears to have suspended its bounty program that once paid up to $100,000 per bug. Intel’s replacement for the Intigriti program offers no rewards, and no reason was given for the change. The Intigriti site states that it “is a responsible disclosure program without bounties,” confirming the report. A check of the site shows that the bounty board is still up but lists the program as suspended.
Intel’s site still lists details on the bug bounty program with awards that range “from $500 up to $100,000, based on quality of the report” and other factors. This program launched, invite-only, in 2017, and became open to all researchers in 2018, covering software, hardware, firmware, and open-source projects. Almost half of the CVEs Intel addressed in 2020, 105 out of 231, arrived through the bounty program, Intel said.
The old bounty board split vulnerabilities into four tiers, which were priced accordingly: Tier 1 from $2,000 to $100,000, Tier 2 $1,000 to $30,000, Tier 3 $500 to $10,000, and Tier 4 $250 to $5,000. Intel expanded the program’s scope to include web services between mid-2025 and October 2025, but it said in a January 6 update on Intigriti that it was evaluating “enhanced bounty and bonus criteria.” In about eight months, the bounties went from evaluation to suspension.
The outlet speculated that with the Linux kernel and other open-source projects being “bombarded” with security reports, it would not be surprising if AI bug-seeking played a role. Linux kernel CVEs have approached 2,000 per release, a fourfold increase from about 500, with maintainers “completely overwhelmed.” Linus Torvalds, the creator of the Linux kernel, has said that duplicate AI reports on the kernel security list are “almost entirely unmanageable.” Curl, for one, closed its bounty program due to AI slop floods.
As a point of reference, HackerOne’s Internet Bug Bounty (IBB) program paused submissions effective March 27. “AI-assisted research is expanding vulnerability discovery across the ecosystem, increasing both coverage and speed,” HackerOne said on the program’s page. HackerOne is still paying queued submissions, with rewards from $68 to $2,257 based on severity. This supports the idea that AI has affected software programs, but it may not be as significant for hardware and firmware.
Intel’s next steps are worth watching to see if this suspension ends up permanent in a fast-changing landscape. Researchers are still able to submit vulnerabilities through the new program; it just offers no bounties for them. Checking AMD’s Intigriti page today shows that the program there is also suspended, although Intigriti does have an auto-suspend mechanism. This follows an earlier payment dispute over scope with a bounty hunter in June.
Even if AI tools carry a stigma and may be a factor in these recent events, they have proven handy. AI company OpenAI paid Hacktron researchers a $6,500 bounty for a discovered exploit chain using rival Anthropic’s model. Torvalds, who previously dismissed AI as mostly marketing, has also called AI “clearly a useful” tool, and acceptance in the field may grow.
This text was published by Tom's Hardware and written by Shane Downing. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Policy & Regulation
All →- Trump says US leads China in AI, warns slowdown could aid Beijing · 1 src
- US military aborts operation after AI-generated false report on Chinese ship · 5 src
- Tasmania justice department reviews AI use after fake citation in parole decision · 1 src
- anthropic and accenture to invest $2 billion in AI safety evaluation · 7 src
- OpenAI introduces Australian Youth Safety Blueprint for teen AI use · 1 src
Comments
via GitHub Discussions