Intel Ends Bug Bounty Program Offering Up to $100,000
Intel has discontinued its long-running bug bounty program, which offered researchers up to $100,000 for discovering security vulnerabilities. The company is transitioning to a new responsible disclosure mechanism without cash rewards.

Intel has ceased its established bug bounty program, a significant initiative that rewarded security researchers with substantial cash prizes for identifying vulnerabilities in its products. The company is shifting to a new reporting system hosted on the Intigriti platform, which is designated as a responsible disclosure project and no longer offers monetary compensation.
Under the previous program, launched in 2017 and opened to all researchers in 2018, individuals could receive rewards ranging from $250 for minor issues to a maximum of $100,000 for critical vulnerabilities. The program was credited with helping Intel fix numerous flaws before they could be exploited, with nearly half of the Common Vulnerabilities and Exposures (CVEs) addressed by Intel in 2020 originating from this initiative.
While Intel has not provided an official reason for the discontinuation, the move aligns with broader industry trends potentially influenced by the rise of artificial intelligence. The surge in AI-generated security reports has reportedly overwhelmed maintainers of open-source projects, leading to a significant increase in submissions. This issue has prompted other projects, such as Curl, to halt their bounty programs due to an influx of low-quality automated submissions.
Researchers can still report vulnerabilities found in Intel's hardware, firmware, software, and open-source projects through the new Intigriti portal. However, the financial incentives previously associated with such discoveries have been removed, marking a notable shift in how the company addresses external security research.