Intel has suspended its long-running bug bounty program, leaving security researchers without the monetary incentives that previously drove vulnerability discovery. This shift matters because it removes a key financial incentive for independent hackers to report flaws in Intel's software and hardware. The move signals a broader industry trend where companies are reevaluating how they handle security disclosures in an era of automated testing.

Intel removes financial incentives for security researchers
The company replaced the original bounty system with a responsible disclosure program hosted on the Intigriti platform. This new framework operates without any monetary rewards, focusing solely on the responsible reporting of security issues. Intel’s own website still lists details of the previous program, noting that awards previously ranged from $500 up to $100,000 based on the quality of the report. In contrast, the Intigriti site explicitly states that it is a responsible disclosure program without bounties.
The original program launched in 2017 and became open to all researchers in 2018, establishing a long history of external security collaboration. Intel expanded the scope of the program to include web services between mid-2025 and October 2025 before the current suspension. The exact reasons for the suspension remain unconfirmed by Intel, though industry observers speculate that AI-generated bug reports may be a primary driver. This speculation aligns with similar moves by other tech giants who cite AI-assisted research floods as a cause for pausing submissions.
This suspension is not an isolated event, as AMD's Intigriti program is also currently suspended. Additionally, HackerOne's Internet Bug Bounty program paused submissions effective March 27, citing similar concerns about AI-assisted research. We've been tracking Bug Bounty Program closely — see our earlier coverage on Apple Limits AI Spam in Security. The industry appears to be in a transitional phase as companies adjust their security protocols to handle the influx of automated vulnerability reports.
Intel's next steps are worth watching to see if this suspension ends up permanent in a fast-changing landscape. For now, researchers can only submit reports through the no-reward disclosure channel. The absence of bounties may reduce the volume of high-quality reports, potentially impacting the speed at which critical flaws are identified and patched.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.