Intel Drops Bug Bounty Rewards, Switches to Unpaid Disclosure

Intel has suspended its paid bug bounty program, ending rewards up to $100,000 for security researchers. The company now operates an unpaid vulnerability disclosure program on Intigriti.

Intel Drops Bug Bounty Rewards, Switches to Unpaid Disclosure

has suspended its paid bug bounty program, a move that removes financial incentives for security researchers who previously helped identify vulnerabilities in its products. This policy shift means independent security experts will no longer receive monetary rewards for their findings, which may reduce the volume of external reports Intel receives. Researchers who relied on these payouts for income or recognition must now adjust their expectations regarding compensation for security work.

Intel removes financial incentives for security researchers

The previous program operated through the Intigriti platform and covered a wide range of Intel assets, including hardware, software, firmware, and open-source projects. Under the old structure, Intel offered rewards of up to $100,000 for critical findings, providing a strong financial motivation for detailed security audits. The new vulnerability disclosure program also runs on Intigriti, but it explicitly excludes financial compensation, marking a significant departure from the company's previous security engagement model.

Intel continues to accept vulnerability reports through the new disclosure channel, maintaining a pathway for security researchers to submit their findings. However, the company has made it clear that researchers should not expect any monetary compensation under this updated policy framework. This change affects the entire ecosystem of third-party security testing that previously relied on the financial structure of the bounty program.

Intel has not publicly explained the specific reasons behind this transition from a paid bounty to an unpaid disclosure program. The change was observed through the status of the platform rather than through an official company statement, leaving the strategic rationale unclear. We've been tracking Bug Bounty Program closely — see our earlier coverage on Apple Limits AI Spam in Security.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion