# Intel appears to have suspended bug bounty program that paid up to $100,000 per flaw

Digest AI · Policy & Regulation · published 2026-09-19T10:30:00Z

Canonical: https://digestai.news/story/intel-appears-to-have-suspended-bug-bounty-program-that-paid-up-to-100

## Summary

Intel appears to have suspended its bug bounty program that once paid up to $100,000 per flaw. The Intigriti site now describes the program as a “responsible disclosure program without bounties,” and the bounty board shows the program as suspended, though Intel’s own page still lists the original award ranges from $500 up to $100,000.

The program launched invite‑only in 2017, opened to all researchers in 2018, and covered software, hardware, firmware and open‑source projects. Intel said 105 of the 231 CVEs it addressed in 2020 (about half) came through the bounty program. The old board divided rewards into four tiers: Tier 1 $2,000‑$100,000; Tier 2 $1,000‑$30,000; Tier 3 $500‑$10,000; Tier 4 $250‑$5,000. Scope was expanded to web services between mid‑2025 and October 2025, and a January 6 update said Intel was evaluating “enhanced bounty and bonus criteria.” Within roughly eight months the program moved from evaluation to suspension.

Media outlets speculate that the rise of AI‑generated vulnerability reports may have contributed; Linux kernel CVEs have approached 2,000 per release, a fourfold increase from about 500, and Linus Torvalds called duplicate AI reports “almost entirely unmanageable.” HackerOne’s Internet Bug Bounty paused submissions on March 27 but continues paying queued reports with rewards from $68 to $2,257. Researchers can still submit to Intel’s new program, but receive no monetary reward.

## Key points

- Intel’s bug bounty program, which paid up to $100,000 per report, is listed as suspended on the Intigriti site.
- In 2020, 105 of Intel’s 231 addressed CVEs (about half) came through the bounty program, according to Intel.
- HackerOne’s Internet Bug Bounty paused submissions on March 27, but continues paying queued reports with rewards from $68 to $2,257.

## Why it matters

The suspension removes financial incentives for security researchers, potentially slowing vulnerability discovery for Intel’s hardware and software, while highlighting AI‑generated report overload across the industry.

## Sources

1. [Intel suspends bug bounty program that paid up to $100,000 per flaw — new Intigriti disclosure program offers no rewards](https://tomshardware.com/tech-industry/cyber-security/intel-suspends-bug-bounty-program-that-paid-up-to-usd100-000-per-flaw-new-intigriti-disclosure-program-offers-no-rewards) (Tom's Hardware, 2026-09-19)

## Cite

Digest AI, "Intel appears to have suspended bug bounty program that paid up to $100,000 per flaw", 19 September 2026, https://digestai.news/story/intel-appears-to-have-suspended-bug-bounty-program-that-paid-up-to-100

---

Written by Digest AI's editorial model from the linked sources; the sources are the record. Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse
JSON: https://digestai.news/story/intel-appears-to-have-suspended-bug-bounty-program-that-paid-up-to-100.json
