Newsletter IconGoogle IconFacebook IconX IconThreads IconInstagram IconYouTube Icon

Intel kills its bug bounty program that paid up to $100,000 for flagging security vulnerabilities

Intel has replaced its paid bug bounty with a no-reward disclosure program as AI floods security teams with automated vulnerability reports.

Intel kills its bug bounty program that paid up to $100,000 for flagging security vulnerabilities
Facebook IconX IconReddit Icon
Comments
Tech Reporter
Published
1 minute & 30 seconds read time
TL;DR: Intel ended its paid bug bounty-formerly awarding up to $100,000-and moved to a no-reward disclosure program, citing a flood of AI-assisted, high-volume vulnerability reports that make traditional bounty management difficult; researchers may still submit flaws via Intel's new Intigriti program but without monetary compensation.
Voice: Default
0:00 / 2:51
Use left and right arrow keys to seek audio.

AI models are getting so good at finding security vulnerabilities that companies are calling them just as capable as "elite security researchers." Just last week, we covered how security researchers used Anthropic's Claude to help break into OpenAI's systems. As a result, Intel has now suspended its bug bounty program, which once paid human researchers up to $100,000 per vulnerability.

The original program launched as an invite-only initiative before opening to all security researchers in 2018, covering hardware, firmware, software, and open-source projects. In 2020 alone, nearly half of the CVEs Intel addressed, 105 out of 231, came through the bounty program.

Popular Now: GTA 6 map recreated in GTA 5 using assets from Rockstar's 2022 breach
Intel kills its bug bounty program that paid up to $100,000 for flagging security vulnerabilities 2

The old bounty board split vulnerabilities into four tiers. Tier 1 paid between $2,000 and $100,000, Tier 2 offered $1,000 to $30,000, Tier 3 ranged from $500 to $10,000, and Tier 4 paid between $250 and $5,000. As recently as January 2026, Intel said it was evaluating enhanced bounty criteria. Eight months later, those bounties have gone from evaluation to suspension.

Intel has not provided an official explanation for why it suspended the bug bounty program, but the timing suggests AI-assisted vulnerability research as a possible factor. AI tools can now scan hardware and software protection layers, identify weaknesses, and flag them at a scale and speed that makes traditional human-researcher bounty programs difficult to manage. If Intel's internal tooling can already run that kind of analysis continuously, paying external researchers to do what machines can do faster could start to look like an unnecessary expense.

Intel kills its bug bounty program that paid up to $100,000 for flagging security vulnerabilities 1

That said, the Linux kernel has seen CVEs surge from around 500 per release to nearly 2,000, with Linus Torvalds saying that duplicate AI-generated reports have made the kernel security list "almost entirely unmanageable." Curl shut down its bug bounty program after being flooded with low-quality automated submissions. HackerOne's Internet Bug Bounty program paused new submissions earlier this year, explicitly citing AI-assisted research as expanding vulnerability discovery faster than the system can process it.

Frequently Asked Questions

Open a question for an answer from TweakTown's coverage of this news, or ask your own below.

Question #1

What kinds of Intel products are covered by the new Intigriti disclosure program?

Question #2

How does Intel’s no-reward disclosure program differ from its old paid bug bounty in practice?

Question #3

Are security researchers still allowed to report hardware, firmware, software, and open-source vulnerabilities to Intel?

Yes. Researchers can still submit hardware, firmware, software, and open-source vulnerabilities to Intel through its new Intigriti program. They should not expect to be paid for those reports.
Question #4

What happened to Intel’s bounty tiers and payout ranges after the suspension?

Have a question that isn't listed here? Ask below, and TweakBot will answer it.

Researchers can still submit vulnerabilities through Intel's new Intigriti program. They just should not expect to be paid for them.

Photo of the Intel® Core i9-14900K Desktop Processor

Best Deals: Intel® Core i9-14900K Desktop Processor

Prices last scanned 2 hours and 14 minutes ago

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commissions from Newegg and PCCG sales.

Join Our Newsletter

Join the TweakTown Newsletter for daily tech updates delivered to your inbox.

See previous giveaways.

News Source:app.intigriti.com

Comments

About the author

Tech Reporter

From helping gamers find the best gear to keeping up with the fast-moving world of tech news, writing is something Hamid fell completely in love with. Four years in, and that magic hasn't worn off. When he's not working, you'll find him replaying The Last of Us series or losing himself in movies.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Follow TweakTown on GoogleAdd TweakTown as a preferred source on Google
Newsletter Subscription